* [bpf-next v2] bpf: Roll back freplace link state when bpf_arch_text_poke() fails
@ 2026-09-28 9:11 chenyuan_fl
2026-10-03 8:40 ` patchwork-bot+netdevbpf
0 siblings, 1 reply; 2+ messages in thread
From: chenyuan_fl @ 2026-09-28 9:11 UTC (permalink / raw)
To: bpf
Cc: ast, daniel, andrii, eddyz87, memxor, jolsa, leon.hwang,
linux-kernel, Yuan Chen
From: Yuan Chen <chenyuan@kylinos.cn>
A freplace attach claims the target prog by bumping
tgt_prog->aux->freplace_link_cnt and setting tr->extension_prog.
bpf_arch_text_poke() then makes the extension take effect. If the
poke fails, the claims are never released: the attach unwinds
through bpf_link_cleanup(), which clears link->prog, so
bpf_trampoline_unlink_prog() never runs.
Drop the link count under ext_mutex on the error path, and set
tr->extension_prog only after the poke succeeded. The count is
still bumped before the poke: it blocks prog_array updates while
the entry is patched.
Fixes: d6083f040d5d ("bpf: Prevent tailcall infinite loop caused by freplace")
Fixes: be8704ff07d2 ("bpf: Introduce dynamic program extensions")
Suggested-by: Leon Hwang <leon.hwang@linux.dev>
Acked-by: Leon Hwang <leon.hwang@linux.dev>
Signed-off-by: Yuan Chen <chenyuan@kylinos.cn>
---
kernel/bpf/trampoline.c | 13 ++++++++++---
1 file changed, 10 insertions(+), 3 deletions(-)
Changes in v2:
- Add Fixes tag for tr->extension_prog, whose assignment before the
poke dates back to be8704ff07d2, as suggested by Leon Hwang.
- Collect Acked-by from Leon Hwang.
diff --git a/kernel/bpf/trampoline.c b/kernel/bpf/trampoline.c
index da85bd580ef0..bf4ab0ac264e 100644
--- a/kernel/bpf/trampoline.c
+++ b/kernel/bpf/trampoline.c
@@ -973,10 +973,17 @@ static int __bpf_trampoline_link_prog(struct bpf_tramp_node *node,
err = bpf_freplace_link_tgt_prog(tgt_prog);
if (err)
return err;
+ err = bpf_arch_text_poke(tr->func.addr, BPF_MOD_NOP,
+ BPF_MOD_JUMP, NULL,
+ node->link->prog->bpf_func);
+ if (err) {
+ /* Undo the claim from bpf_freplace_link_tgt_prog(). */
+ guard(mutex)(&tgt_prog->aux->ext_mutex);
+ tgt_prog->aux->freplace_link_cnt--;
+ return err;
+ }
tr->extension_prog = node->link->prog;
- return bpf_arch_text_poke(tr->func.addr, BPF_MOD_NOP,
- BPF_MOD_JUMP, NULL,
- node->link->prog->bpf_func);
+ return 0;
}
err = bpf_trampoline_add_prog(tr, node, cnt);
if (err)
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [bpf-next v2] bpf: Roll back freplace link state when bpf_arch_text_poke() fails
2026-09-28 9:11 [bpf-next v2] bpf: Roll back freplace link state when bpf_arch_text_poke() fails chenyuan_fl
@ 2026-10-03 8:40 ` patchwork-bot+netdevbpf
0 siblings, 0 replies; 2+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-10-03 8:40 UTC (permalink / raw)
To: chenyuan
Cc: bpf, ast, daniel, andrii, eddyz87, memxor, jolsa, leon.hwang,
linux-kernel, chenyuan
Hello:
This patch was applied to bpf/bpf-next.git (master)
by Alexei Starovoitov <ast@kernel.org>:
On Mon, 28 Sep 2026 17:11:21 +0800 you wrote:
> From: Yuan Chen <chenyuan@kylinos.cn>
>
> A freplace attach claims the target prog by bumping
> tgt_prog->aux->freplace_link_cnt and setting tr->extension_prog.
> bpf_arch_text_poke() then makes the extension take effect. If the
> poke fails, the claims are never released: the attach unwinds
> through bpf_link_cleanup(), which clears link->prog, so
> bpf_trampoline_unlink_prog() never runs.
>
> [...]
Here is the summary with links:
- [bpf-next,v2] bpf: Roll back freplace link state when bpf_arch_text_poke() fails
https://git.kernel.org/bpf/bpf-next/c/5ec398d9ec8f
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-03 8:40 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-28 9:11 [bpf-next v2] bpf: Roll back freplace link state when bpf_arch_text_poke() fails chenyuan_fl
2026-10-03 8:40 ` patchwork-bot+netdevbpf
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox