From: sashiko-bot@kernel.org
To: "Saket Kumar Bhaskar" <skb99@linux.ibm.com>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH v13 2/8] powerpc64/bpf: fix percpu private stack leak on JIT failure
Date: Mon, 31 Aug 2026 07:32:04 +0000 [thread overview]
Message-ID: <20260831073204.87D391F000E9@smtp.kernel.org> (raw)
In-Reply-To: <a827e3ef81cd43f2aee7e9bdfe8683f2c77065da.1788154635.git.skb99@linux.ibm.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
Pre-existing issues:
- [High] The ARM64 BPF JIT compiler leaks the percpu private stack on JIT failure.
- [High] bpf_jit_binary_pack_finalize uses uninitialized memory for size on failure, causing a system crash and leaking modmem charges.
--
commit a7adca4200815295703e0e825b2bdfcafd6b972e
Author: Abhishek Dubey <adubey@linux.ibm.com>
powerpc64/bpf: fix percpu private stack leak on JIT failure
The existing conditional statement in bpf_int_jit_compile() frees the
percpu private stack only when the image buffer was never allocated.
If bpf_jit_build_body() fails, the image buffer is already allocated,
so the percpu stack is not freed and leaks. This fix implements freeing
the private stack whenever fp->jited was not set, i.e., compilation did
not succeed.
Link: https://lore.kernel.org/bpf/20260616135426.A06B71F000E9@smtp.kernel.org
> diff --git a/arch/powerpc/net/bpf_jit_comp.c b/arch/powerpc/net/bpf_jit_comp.c
> index a875521ff904d..8f7501954d9f0 100644
> --- a/arch/powerpc/net/bpf_jit_comp.c
> +++ b/arch/powerpc/net/bpf_jit_comp.c
> @@ -357,7 +357,7 @@ struct bpf_prog *bpf_int_jit_compile(struct bpf_verifier_env *env, struct bpf_pr
> (void *)fimage + FUNCTION_DESCR_SIZE);
>
> out_addrs:
> - if (!image && priv_stack_ptr) {
> + if (!fp->jited && priv_stack_ptr) {
> fp->aux->priv_stack_ptr = NULL;
> free_percpu(priv_stack_ptr);
> }
arch/arm64/net/bpf_jit_comp.c:bpf_int_jit_compile() {
...
out_off:
if (!ro_header && priv_stack_ptr) {
free_percpu(priv_stack_ptr);
prog->aux->priv_stack_ptr = NULL;
}
...
}
[Severity: High]
This isn't a bug introduced by this patch, but while reviewing this fix I
noticed a similar issue in the ARM64 JIT compiler. Does this code leak the
percpu private stack if JIT compilation fails after header allocation?
If bpf_jit_build_body() fails, the error path frees the header but does not
nullify the ro_header pointer. The subsequent cleanup block evaluates to false,
failing to free priv_stack_ptr. Since prog->jited remains 0, bpf_jit_free()
also skips freeing it.
kernel/bpf/core.c:bpf_jit_binary_pack_finalize() {
...
ptr = bpf_arch_text_copy(ro_header, rw_header, rw_header->size);
kvfree(rw_header);
if (IS_ERR(ptr)) {
bpf_prog_pack_free(ro_header, ro_header->size);
return PTR_ERR(ptr);
}
...
}
[Severity: High]
This is a pre-existing issue, but I spotted a potential memory corruption
and resource leak in the BPF core during JIT finalize. Can this error path
cause a system crash and leak modmem charges?
If bpf_arch_text_copy() fails, the size field in ro_header remains
uninitialized (for example, filled with breakpoint instructions by
bpf_fill_ill_insns()). Calling bpf_prog_pack_free() with this wild size
could corrupt the allocator.
Also, does this error path permanently leak the module memory charge by
returning without calling bpf_jit_uncharge_modmem(size)?
--
Sashiko AI review · https://sashiko.dev/#/patchset/cover.1788154635.git.skb99@linux.ibm.com?part=2
next prev parent reply other threads:[~2026-08-31 7:32 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-31 7:15 [PATCH v13 0/8] powerpc/bpf: address missing verifier selftest coverage Saket Kumar Bhaskar
2026-08-31 7:15 ` [PATCH v13 1/8] powerpc64/bpf: fix compare instruction emitted for tailcall Saket Kumar Bhaskar
2026-08-31 7:15 ` [PATCH v13 2/8] powerpc64/bpf: fix percpu private stack leak on JIT failure Saket Kumar Bhaskar
2026-08-31 7:32 ` sashiko-bot [this message]
2026-08-31 7:16 ` [PATCH v13 3/8] powerpc/bpf: fix buffer overflow in JIT for large BPF programs Saket Kumar Bhaskar
2026-08-31 8:24 ` bot+bpf-ci
2026-08-31 7:16 ` [PATCH v13 4/8] powerpc/bpf: fix alignment of long branch trampoline address Saket Kumar Bhaskar
2026-08-31 8:12 ` bot+bpf-ci
2026-08-31 7:16 ` [PATCH v13 5/8] powerpc/bpf: Move out dummy_tramp_addr after Long branch stub Saket Kumar Bhaskar
2026-08-31 7:35 ` sashiko-bot
2026-08-31 7:16 ` [PATCH v13 6/8] selftests/bpf: Fix powerpc JIT disassembly failure Saket Kumar Bhaskar
2026-08-31 8:12 ` bot+bpf-ci
2026-08-31 7:16 ` [PATCH v13 7/8] selftests/bpf: Enable verifier selftest for powerpc64 Saket Kumar Bhaskar
2026-08-31 7:16 ` [PATCH v13 8/8] selftests/bpf: Add tailcall " Saket Kumar Bhaskar
2026-08-31 8:12 ` bot+bpf-ci
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260831073204.87D391F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=skb99@linux.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox