BPF List
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Pu Lehui" <pulehui@huaweicloud.com>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf-next v3 2/3] bpf: Reject callback subprogs invoke tailcall
Date: Thu, 16 Jul 2026 12:11:15 +0000	[thread overview]
Message-ID: <20260716121115.53BBB1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260716120157.835937-3-pulehui@huaweicloud.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Direct tail calls inside async and exception callbacks are no longer rejected, bypassing the Tail Call Counter (TCC) limit and potentially causing infinite tail calls or crashes.
--

--- Patch [2]: [PATCH bpf-next v3 2/3] bpf: Reject callback subprogs invoke tailcall ---
commit 99ae0587c85d574b41c654707864af3b7ff51fa8
Author: Pu Lehui <pulehui@huawei.com>

    bpf: Reject callback subprogs invoke tailcall

This commit aims to fix infinite tailcalls by rejecting tailcalls inside
all subprograms of synchronous callbacks. It also consolidates the existing
async and exception callback checks into a single unified check.

> diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
> index 782d939c38cdc..62d46b4c9962f 100644
> --- a/kernel/bpf/verifier.c
> +++ b/kernel/bpf/verifier.c
> @@ -5237,10 +5237,6 @@ static int check_max_stack_depth_subprog(struct bpf_verifier_env *env, int idx,
>  		if (verifier_bug_if(sidx < 0, env, "callee not found at insn %d", next_insn))
>  			return -EFAULT;
>  		if (subprog[sidx].is_async_cb) {
> -			if (subprog[sidx].has_tail_call) {
> -				verifier_bug(env, "subprog has tail_call and async cb");
> -				return -EFAULT;
> -			}

[Severity: High]
Does removing this explicit check allow direct tailcalls inside async and
exception callbacks to bypass validation?

If an async or exception callback does not make any subprogram calls (acting
as a root subprogram), the local variable tail_call_reachable will remain
false, as it is only set to true when traversing into or returning from a
callee subprogram.

>  			/* async callbacks don't increase bpf prog stack size unless called directly */
>  			if (!bpf_pseudo_call(insn + i))
>  				continue;
> @@ -5281,8 +5277,8 @@ static int check_max_stack_depth_subprog(struct bpf_verifier_env *env, int idx,
>  	 */
>  	if (tail_call_reachable) {
>  		for (tmp = idx; tmp >= 0; tmp = dinfo[tmp].caller) {
> -			if (subprog[tmp].is_exception_cb) {
> -				verbose(env, "cannot tail call within exception cb\n");
> +			if (subprog[tmp].is_cb) {

Because tail_call_reachable evaluates to false for callbacks without
subprogram calls, will this unified check be completely bypassed?

Since these callbacks are invoked directly by the kernel rather than via a
BPF-to-BPF call, the Tail Call Counter register might be uninitialized. Could
this bypass the TCC limit and lead to infinite tailcalls?

> +				verbose(env, "cannot tail call within callback\n");
>  				return -EINVAL;
>  			}
>  			if (subprog[tmp].stack_arg_cnt) {

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260716120157.835937-1-pulehui@huaweicloud.com?part=2

  reply	other threads:[~2026-07-16 12:11 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-16 12:01 [PATCH bpf-next v3 0/3] Fixes for tailcall with subprog and callback Pu Lehui
2026-07-16 12:01 ` [PATCH bpf-next v3 1/3] bpf: Sync tail_call_reachable with callee state on entry Pu Lehui
2026-07-16 12:01 ` [PATCH bpf-next v3 2/3] bpf: Reject callback subprogs invoke tailcall Pu Lehui
2026-07-16 12:11   ` sashiko-bot [this message]
2026-07-16 12:20     ` Pu Lehui
2026-07-16 12:01 ` [PATCH bpf-next v3 3/3] selftests/bpf: Add testcases for callback with tailcall Pu Lehui
2026-07-17  0:50 ` [PATCH bpf-next v3 0/3] Fixes for tailcall with subprog and callback patchwork-bot+netdevbpf

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260716121115.53BBB1F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=pulehui@huaweicloud.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox