BPF List
 help / color / mirror / Atom feed
* [PATCH bpf v2 0/2] bpf: Reject non-negative stack object offsets
@ 2026-09-20 21:04 Xu Yunxiang
  2026-09-20 21:04 ` [PATCH bpf v2 1/2] bpf: Reject non-negative offsets in stack_slot_obj_get_spi() Xu Yunxiang
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Xu Yunxiang @ 2026-09-20 21:04 UTC (permalink / raw)
  To: bpf; +Cc: ast, daniel, andrii, eddyz87, memxor, sun.jian.kdev

Reject non-negative offsets before converting a stack object address to a
stack slot index. Add a regression test for iterator destruction through
fp+0.

Changes in v2:
- Split the kernel change and selftest as requested by Andrii.
- Rebase onto bpf/master at a11212910cf09b2fe8db9afa41ef60c4f81879c5.
- Keep the original code and test changes unchanged and retain Sun Jian's
  Reviewed-by on both parts.

v1: https://lore.kernel.org/bpf/20260911084314.3481637-1-xyx2021@mail.ustc.edu.cn/
Split request: https://lore.kernel.org/bpf/CAEf4BzbYzt-Riekpc-A=MfQft9ZELwSDSE8kkQO1ZOyR3O_FAg@mail.gmail.com/

Validation on this exact candidate with a matching bpf_testmod:
  - W=1 verifier, full kernel/modules, changed BPF objects and test_progs
    builds passed.
  - iters: 1/97 passed; 0 skipped.
  - dynptr: 2/132 passed; 0 skipped.
  - irq: 1/33 passed; 0 skipped.
  - res_spin_lock: 3/14 passed; 1 skipped.
  - file_reader: 1/8 passed; 0 skipped.
  - kmem_cache_iter: 1/3 passed; 0 skipped.
  - dmabuf_iter: 1/4 passed; 0 skipped.

No selected test failed. The VM ran with panic_on_warn and panic_on_oops;
no kernel WARN, Oops or panic was found.

res_spin_lock_stress skips because the VM has no hardware PMU.

Annotated verifier tests check load outcomes and diagnostics. The full
unfiltered suite, sanitizer configurations and architecture matrix were
not run.

Please queue this fix for stable after it reaches the BPF tree.

Xu Yunxiang (2):
  bpf: Reject non-negative offsets in stack_slot_obj_get_spi()
  selftests/bpf: Reject iterator destruction through fp+0

 kernel/bpf/verifier.c                         |  2 +-
 .../selftests/bpf/progs/iters_state_safety.c  | 22 +++++++++++++++++++
 2 files changed, 23 insertions(+), 1 deletion(-)


base-commit: a11212910cf09b2fe8db9afa41ef60c4f81879c5
-- 
2.43.0


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-09-21 22:11 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-20 21:04 [PATCH bpf v2 0/2] bpf: Reject non-negative stack object offsets Xu Yunxiang
2026-09-20 21:04 ` [PATCH bpf v2 1/2] bpf: Reject non-negative offsets in stack_slot_obj_get_spi() Xu Yunxiang
2026-09-20 21:04 ` [PATCH bpf v2 2/2] selftests/bpf: Reject iterator destruction through fp+0 Xu Yunxiang
2026-09-21 22:10 ` [PATCH bpf v2 0/2] bpf: Reject non-negative stack object offsets patchwork-bot+netdevbpf

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox