All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH bpf-next v5 0/2] bpf: Track iterator-owned BTF pointer lifetimes
@ 2026-09-20 21:04 Xu Yunxiang
  2026-09-20 21:04 ` [PATCH bpf-next v5 1/2] " Xu Yunxiang
  2026-09-20 21:04 ` [PATCH bpf-next v5 2/2] selftests/bpf: Test iterator " Xu Yunxiang
  0 siblings, 2 replies; 7+ messages in thread
From: Xu Yunxiang @ 2026-09-20 21:04 UTC (permalink / raw)
  To: bpf
  Cc: ast, daniel, andrii, eddyz87, memxor, ameryhung, yonghong.song,
	puranjay

Some non-RCU struct iterator results borrow the current element's lifetime,
while others return objects that remain valid independently of the iterator.
Make current-element lifetime tracking explicit with KF_ITER_LIFETIME on the
next kfunc, and opt in task_vma, css_task, kmem_cache and dmabuf after checking
their native ownership and release paths.

Track the selected results and their fully trusted fields through the
iterator reference. Check child-resource cleanup and invalidate the previous
result before either next outcome. Use the common dynptr constructor's
backing lifetime while preserving clone and explicit-release ownership.
Unflagged struct iterators and RCU results retain their existing rules.

Changes in v5:
  - Add KF_ITER_LIFETIME opt-in, as requested by Alexei, instead of applying
    the current-element rule to every non-RCU struct iterator result.
  - Validate the flag on a NEXT method returning a strict struct pointer,
    without KF_ACQUIRE, and opt in the four audited native iterators.
  - Add a module iterator returning current, with positive verifier tests
    for using its independent-lifetime result after next and destroy.
  - Rebase onto bpf-next b99f71407ce5; retain the existing lifetime tests.

v4:
https://lore.kernel.org/r/20260917051948.1588826-1-xyx2021@mail.ustc.edu.cn
Review:
https://lore.kernel.org/r/DLHO7NCJVWJV.1K8VWK8LFIKGD@gmail.com

Validation on this exact candidate with a matching bpf_testmod:
  - W=1 verifier, full kernel/modules, changed BPF objects and test_progs
    builds passed.
  - iters: 1/111 passed; 0 skipped.
  - dynptr: 2/132 passed; 0 skipped.
  - file_reader: 1/8 passed; 0 skipped.
  - kmem_cache_iter: 1/3 passed; 0 skipped.
  - dmabuf_iter: 1/4 passed; 0 skipped.

No selected test failed. The VM ran with panic_on_warn and panic_on_oops;
no kernel WARN, Oops or panic was found.

Annotated verifier tests check load outcomes and diagnostics. The full
unfiltered suite, sanitizer configurations and architecture matrix were
not run.

Changes in v4:
  - Rebase onto bpf-next as requested by Amery Hung.
  - Keep update_ref_obj() and reg_is_referenced() unchanged; introduce
    reg_lifetime_id() for owned and borrowed source lifetimes.
  - Use the common constructor path instead of a FILE-only special case.
  - Capture the source lifetime before marking a BTF field destination.
  - Move next-time invalidation into process_iter_arg().
  - Share the child-reference leak check with release_reference(), while
    removing only the initially released ID from acquired references.
  - Retain the existing lifetime selftests on the new base.

v3:
https://lore.kernel.org/r/20260911084254.3481508-1-xyx2021@mail.ustc.edu.cn
Earlier review:
https://lore.kernel.org/r/CAMB2axMX07j49sZRmGFm2s==FMgKFzvKPWxc8hDvU=b3Lp=VOg@mail.gmail.com

Xu Yunxiang (2):
  bpf: Track iterator-owned BTF pointer lifetimes
  selftests/bpf: Test iterator BTF pointer lifetimes

 Documentation/bpf/bpf_iterators.rst           |   9 +
 include/linux/btf.h                           |   1 +
 kernel/bpf/btf.c                              |  12 +-
 kernel/bpf/helpers.c                          |  10 +-
 kernel/bpf/verifier.c                         |  88 ++++-
 .../selftests/bpf/progs/iters_testmod.c       | 370 ++++++++++++++++++
 .../selftests/bpf/test_kmods/bpf_testmod.c    |  24 ++
 .../selftests/bpf/test_kmods/bpf_testmod.h    |   4 +
 .../bpf/test_kmods/bpf_testmod_kfunc.h        |   5 +
 9 files changed, 503 insertions(+), 20 deletions(-)


base-commit: b99f71407ce529ba01a9392f477522d2e76c6613
-- 
2.43.0


^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2026-09-22 23:31 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-20 21:04 [PATCH bpf-next v5 0/2] bpf: Track iterator-owned BTF pointer lifetimes Xu Yunxiang
2026-09-20 21:04 ` [PATCH bpf-next v5 1/2] " Xu Yunxiang
2026-09-20 21:21   ` sashiko-bot
2026-09-22 23:13   ` Amery Hung
2026-09-22 23:30     ` Amery Hung
2026-09-22 23:31   ` Alexei Starovoitov
2026-09-20 21:04 ` [PATCH bpf-next v5 2/2] selftests/bpf: Test iterator " Xu Yunxiang

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.