From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f44.google.com (mail-pj1-f44.google.com [209.85.216.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 271E437B00F for ; Thu, 20 Aug 2026 15:26:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.44 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787239618; cv=none; b=tnTjNkNCr6rxkvv0o8Yqd0Nd6sMiZnSqgCb++U9qTPo68p7kT4svviLF2BiZoelou2yce82sHiJypE5g06hAwN7Guz+1WEydCMh06FHGCHrLhwgKank8y11vskCdxB6WiLzJte9il1vGteJkIy2i1ReYXDFUFC0Y7ekqZQj9jf8= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787239618; c=relaxed/simple; bh=4Z1WvXEDeUzIJWnIoL1PNeHzSYoaGhcYd2vTSVbFVHo=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=u28D7iBVRpHh1p3KtEsywKAbXocG1QqluXo8jb0bHF1Es7ERbG16kEIRbf5SoUpFSCUfZUITq3Im4+hE/3BYHa1LBs3Dfc2AvASuXLP6t8DIViUpbSipBYful9VLKx+hJxGmLb+5UElL9A0gB9TIpCtB6eJap+QEtf9JNPwjNCM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=nkPaU4Im; arc=none smtp.client-ip=209.85.216.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="nkPaU4Im" Received: by mail-pj1-f44.google.com with SMTP id 98e67ed59e1d1-38d489b6b71so2389152a91.0 for ; Thu, 20 Aug 2026 08:26:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787239616; x=1787844416; darn=vger.kernel.org; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:from:to:cc:subject :date:message-id:reply-to:content-type; bh=IvV+0X/Y3gO0VxJslvx+LbEOAaQHrjOILkScrCstO+E=; b=nkPaU4ImKryPFaE6CROYwgA8FdCT3lbs8R/nOwkWpYWi6PSAE87YCuFYK/6dNneGlD /PXeN/ndWWPeSJUpjzA4uf7IOPD6LC5+ZriSZtzcz5MGdBDc658yj1+n2JYmKvnpxrox D67eOuxhf7JHGHLm5WYiUnhWw31O9eaWmsrZL7Gc70Hc+6d36EKY5H4gSJbrYjwhMShQ PzCcK3dGOsTmFjOYX+bqX1p9krSKYiz0TuYwwiVKoFvHDRP4V5NA7JxWHwzEFh+VD8VZ SJqZcVB/UyRcG3M0DWwMddrlvPNsW1gF0PChpYrXOiEH6d3mk+78WI9TTEYRJ6zZKagq Z2qQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787239616; x=1787844416; h=in-reply-to:content-disposition:content-type:mime-version :references:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=IvV+0X/Y3gO0VxJslvx+LbEOAaQHrjOILkScrCstO+E=; b=S8gDgUIpA1XCoC79EU9teGNIXcfnXJtJygzyssZQZukl6VjcoVTvnX4v1Rj5yyrbTY OLEOOwtuuknfkAmaeBjGl1Oc2BMLs+mhoSjyhJBf0QPisXTj8rGJPU+W1WKq3q+JGnH+ 8YUnkJNQOF8Yk3RljvKJG//HIhq6injSr8qHZOJD3byxBM2Y5ZKsy9Y0+A3k019sMzeh 3+XLatDxRw6TYLrwSNagpgZgU+nGqLP86V5xv22nEwTiP8yC4LmsMfW3G1lDjOZM+zfO dKP+XHuFUa6Lt4U6veE0OjsHaFk8O+R5LgxqiIpIsFECBwqOjY+BlrGQtZBQwD0PC+U2 Ktvw== X-Forwarded-Encrypted: i=1; AHgh+RoSp3I2qLaXzkjpEZ2qWP9zxtSnPsVV+tfXZYa7UB4wftfIgF3J+fPvRrzWgFXPRWkJc0MZy5H8ar64ApM=@vger.kernel.org X-Gm-Message-State: AFuF++nxTeW7fSb8uQlkNBxfSzEuha2nhcOSXVs0+6jPk/6deu61QXb6 EiqLdpR+nSY66w+tdRai2gfevjD/X1GxCd6THY1n90Xepj9nPYHnDF+l X-Gm-Gg: AR+sD10e0vOZHFX5M99g9DNtshfJmExZFRn71xfI6QjvZi2wc9UxGeQffgQ0DgyOHGp iGPrC0pa2rQ+daIa1Viu5p9UeI53slAPZ3J93SNpt/YCKycbArlRgMozavRxTLV4Z8hY60XFo2S OilzdZ4TY/CbelrWdPadF88+IKA8BOXxUPZw9WIdQGr06ooqS4vBW6lPDoVo0W2be9O0xjE7DP9 1jRvF7z5gySZ81wCgbwl4KIzOAthbvaNAxlHzApWKyHa1Zg7PKqo1vRpktB/rqNWbsjoOgoxWJX qE8DdaewjQSroahwY5ZXYnVA1Ao1rXILyTaGoO7pFcb/VgOxtscdUkYw2svzj43AgV76MZr/Bfc eix/quldj4itDJC1raepsByGLJjeDaU9szP9aL+rpDafL8v/g9GVpGq3RSDriSDO3NTLI9K4Elk 3kHT+u3henNLHB4f7FWRjtUPLH6fhYhkam2dO+R4mRK/CLIyGdyflIVes= X-Received: by 2002:a17:90b:2792:b0:395:5404:95 with SMTP id 98e67ed59e1d1-3958108bb19mr28368646a91.12.1787239616312; Thu, 20 Aug 2026 08:26:56 -0700 (PDT) Received: from omen-arch ([211.58.239.197]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-395a9e14d1dsm1201204a91.1.2026.08.20.08.26.51 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 20 Aug 2026 08:26:55 -0700 (PDT) Date: Fri, 21 Aug 2026 00:26:48 +0900 From: Junseo Lim To: "Florent Revest (Anthropic)" Cc: bpf@vger.kernel.org, Alexei Starovoitov , Daniel Borkmann , Andrii Nakryiko , Martin KaFai Lau , Eduard Zingerman , Kumar Kartikeya Dwivedi , Song Liu , Yonghong Song , Jiri Olsa , KP Singh , Emil Tsalapatis , John Fastabend , "Paul E. McKenney" , Jose Fernandez , linux-kernel@vger.kernel.org Subject: Re: [PATCH bpf] bpf: Keep progs alive until the trampoline image calling them is freed Message-ID: References: <20260819122252.1782790-1-florent.revest@linux.dev> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20260819122252.1782790-1-florent.revest@linux.dev> On Wed, Aug 19, 2026 at 12:22:50PM +0000, Florent Revest (Anthropic) wrote: > bpf_tramp_image_put() makes sure a trampoline image is not freed while > a task may still be running in it (call_rcu_tasks() + im->pcref), but > nothing similar is done for the progs called by that image. Since > commit e21aa341785c ("bpf: Fix fexit trampoline."), detach patches the > return path so that a task still in the original function skips the > fexit progs when it comes back, and counts on the prog's own RCU flavor > to cover a task that is inside a prog. On that basis the last prog > reference is dropped right away and the prog is freed after a single > RCU / RCU tasks trace grace period. > > [...] > > Fix it by having the image take a reference on every prog it calls, in > bpf_tramp_image_alloc(), and drop them in bpf_tramp_image_free(). A > detached prog now stays loaded until the old image is gone, which > reverts a deliberate choice of commit e21aa341785c ("bpf: Fix fexit > trampoline."). Detached fexit progs still stop being called right away > since the return path is patched. This appears to be the same issue addressed by my earlier patch [1]. I think the flexible-array approach here is cleaner, so I'm fine with this version going forward. Could you please carry the original Reported-by tag? Reported-by: Sechang Lim [1] https://lore.kernel.org/bpf/20260815071927.147049-1-zirajs7@gmail.com/T/