* [PATCH bpf-next] selftests/bpf: Guard link cleanup in fexit_bpf2bpf
@ 2026-09-17 9:39 Zhixing Chen
2026-09-17 10:34 ` bot+bpf-ci
2026-09-21 21:30 ` patchwork-bot+netdevbpf
0 siblings, 2 replies; 3+ messages in thread
From: Zhixing Chen @ 2026-09-17 9:39 UTC (permalink / raw)
To: bpf; +Cc: Andrii Nakryiko, Eduard Zingerman, Ihor Solodrai, Zhixing Chen
test_fexit_bpf2bpf_common() can jump to the common cleanup path before
the link array is allocated, for example if bpf_prog_get_info_by_fd()
fails. The cleanup loop still indexes link[i] unconditionally, which can
dereference a NULL pointer and hide the original failure.
Guard the loop so the test reports the original failure instead.
Signed-off-by: Zhixing Chen <running910@gmail.com>
---
tools/testing/selftests/bpf/prog_tests/fexit_bpf2bpf.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/tools/testing/selftests/bpf/prog_tests/fexit_bpf2bpf.c b/tools/testing/selftests/bpf/prog_tests/fexit_bpf2bpf.c
index 6262c81cdaa9..d2f2dcc0f2e1 100644
--- a/tools/testing/selftests/bpf/prog_tests/fexit_bpf2bpf.c
+++ b/tools/testing/selftests/bpf/prog_tests/fexit_bpf2bpf.c
@@ -164,8 +164,10 @@ static void test_fexit_bpf2bpf_common(const char *obj_file,
goto close_prog;
close_prog:
- for (i = 0; i < prog_cnt; i++)
- bpf_link__destroy(link[i]);
+ if (link) {
+ for (i = 0; i < prog_cnt; i++)
+ bpf_link__destroy(link[i]);
+ }
bpf_object__close(obj);
bpf_object__close(tgt_obj);
free(link);
base-commit: 71b75648d1a21c0a6379741d00f41086ec95f14a
--
2.34.1
^ permalink raw reply related [flat|nested] 3+ messages in thread* Re: [PATCH bpf-next] selftests/bpf: Guard link cleanup in fexit_bpf2bpf
2026-09-17 9:39 [PATCH bpf-next] selftests/bpf: Guard link cleanup in fexit_bpf2bpf Zhixing Chen
@ 2026-09-17 10:34 ` bot+bpf-ci
2026-09-21 21:30 ` patchwork-bot+netdevbpf
1 sibling, 0 replies; 3+ messages in thread
From: bot+bpf-ci @ 2026-09-17 10:34 UTC (permalink / raw)
To: running910, bpf
Cc: andrii, eddyz87, ihor.solodrai, running910, ast, andrii, daniel,
martin.lau, eddyz87, yonghong.song, mason, ihor.solodrai
[-- Attachment #1: Type: text/plain, Size: 1168 bytes --]
> test_fexit_bpf2bpf_common() can jump to the common cleanup path before
> the link array is allocated, for example if bpf_prog_get_info_by_fd()
> fails. The cleanup loop still indexes link[i] unconditionally, which can
> dereference a NULL pointer and hide the original failure.
>
> Guard the loop so the test reports the original failure instead.
>
> Signed-off-by: Zhixing Chen <running910@gmail.com>
This patch fixes a real NULL pointer dereference in existing test code.
The old cleanup loop unconditionally reads link[0] off a NULL base when
link == NULL, and every one of the 7 callers passes prog_cnt >= 1.
Should this include a Fixes: tag? The buggy cleanup loop (accessing
link[i] without checking if link is NULL) was introduced in cd241b77f5b7.
This is checked mechanically by CI on the bpf list, so the tag should point
at the commit that actually introduced the bug:
Fixes: cd241b77f5b7 ("adding ci files")
---
AI reviewed your patch. Please fix the bug or email reply why it's not a bug.
See: https://github.com/kernel-patches/vmtest/blob/master/ci/claude/README.md
CI run summary: https://github.com/kernel-patches/bpf/actions/runs/35207993886
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: [PATCH bpf-next] selftests/bpf: Guard link cleanup in fexit_bpf2bpf
2026-09-17 9:39 [PATCH bpf-next] selftests/bpf: Guard link cleanup in fexit_bpf2bpf Zhixing Chen
2026-09-17 10:34 ` bot+bpf-ci
@ 2026-09-21 21:30 ` patchwork-bot+netdevbpf
1 sibling, 0 replies; 3+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-09-21 21:30 UTC (permalink / raw)
To: Zhixing Chen; +Cc: bpf, andrii, eddyz87, ihor.solodrai
Hello:
This patch was applied to bpf/bpf-next.git (master)
by Andrii Nakryiko <andrii@kernel.org>:
On Thu, 17 Sep 2026 17:39:28 +0800 you wrote:
> test_fexit_bpf2bpf_common() can jump to the common cleanup path before
> the link array is allocated, for example if bpf_prog_get_info_by_fd()
> fails. The cleanup loop still indexes link[i] unconditionally, which can
> dereference a NULL pointer and hide the original failure.
>
> Guard the loop so the test reports the original failure instead.
>
> [...]
Here is the summary with links:
- [bpf-next] selftests/bpf: Guard link cleanup in fexit_bpf2bpf
https://git.kernel.org/bpf/bpf-next/c/80ed1435d97d
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-09-21 22:06 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-17 9:39 [PATCH bpf-next] selftests/bpf: Guard link cleanup in fexit_bpf2bpf Zhixing Chen
2026-09-17 10:34 ` bot+bpf-ci
2026-09-21 21:30 ` patchwork-bot+netdevbpf
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox