From: Kumar Kartikeya Dwivedi <memxor@gmail.com>
To: bpf@vger.kernel.org
Cc: Alexei Starovoitov <ast@kernel.org>,
Andrii Nakryiko <andrii@kernel.org>,
Daniel Borkmann <daniel@iogearbox.net>,
Eduard Zingerman <eddyz87@gmail.com>,
Emil Tsalapatis <emil@etsalapatis.com>,
Nicholas Carlini <npc@anthropic.com>,
kkd@meta.com, kernel-team@meta.com
Subject: [PATCH bpf-next v2 0/2] Fix acyclic ownership checks
Date: Mon, 14 Sep 2026 15:24:41 +0200 [thread overview]
Message-ID: <20260914132444.2564218-1-memxor@gmail.com> (raw)
Bound and ensure acyclic ownership graphs for native data structures to
fix a bug reported by Nicholas. See commit logs and tests for details.
The existing list/rbtree rule already rejects graph-only cycles and bounds
those chains conservatively. It misses ownership through local referenced
kptrs, which can produce unbounded synchronous field destruction. Validate
all local ownership edges together, with an explicit depth bound, and allow
longer acyclic graph-only layouts within that bound.
Changelog:
----------
v1 -> v2
v1: https://lore.kernel.org/bpf/20260905090750.4064411-1-memxor@gmail.com/
* Fold the graph-walk and local-kptr changes into one complete fix. (Alexei)
* Explain why the original rule catches graph-only cycles, its three-type
chain bound, and the missing local-kptr ownership edges. (Alexei)
* Distinguish synchronous recursive field destruction from the deferred
RCU freeing of object storage.
* Add depth-boundary tests with child-first BTF ordering and a shared
suffix reached with different remaining budgets.
* Cover list and rbtree chains at the original three-type bound and at the
new eight-type bound, including rejected over-limit cases.
Kumar Kartikeya Dwivedi (2):
bpf: Bound ownership depth through local kptrs and graph roots
selftests/bpf: Check local object ownership depth
kernel/bpf/btf.c | 134 +++++---
.../selftests/bpf/prog_tests/linked_list.c | 4 +-
.../bpf/prog_tests/local_kptr_ownership.c | 296 ++++++++++++++++++
3 files changed, 384 insertions(+), 50 deletions(-)
create mode 100644 tools/testing/selftests/bpf/prog_tests/local_kptr_ownership.c
base-commit: a41c69c6ea14596cfd95978483166d4eff52435e
--
2.53.0
next reply other threads:[~2026-09-14 13:24 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-14 13:24 Kumar Kartikeya Dwivedi [this message]
2026-09-14 13:24 ` [PATCH bpf-next v2 1/2] bpf: Bound ownership depth through local kptrs and graph roots Kumar Kartikeya Dwivedi
2026-09-14 13:24 ` [PATCH bpf-next v2 2/2] selftests/bpf: Check local object ownership depth Kumar Kartikeya Dwivedi
2026-09-14 14:16 ` bot+bpf-ci
2026-09-19 5:30 ` [PATCH bpf-next v2 0/2] Fix acyclic ownership checks patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260914132444.2564218-1-memxor@gmail.com \
--to=memxor@gmail.com \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=eddyz87@gmail.com \
--cc=emil@etsalapatis.com \
--cc=kernel-team@meta.com \
--cc=kkd@meta.com \
--cc=npc@anthropic.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox