BPF List
 help / color / mirror / Atom feed
* [PATCH bpf-next v2 0/2] Fix acyclic ownership checks
@ 2026-09-14 13:24 Kumar Kartikeya Dwivedi
  2026-09-14 13:24 ` [PATCH bpf-next v2 1/2] bpf: Bound ownership depth through local kptrs and graph roots Kumar Kartikeya Dwivedi
                   ` (2 more replies)
  0 siblings, 3 replies; 5+ messages in thread
From: Kumar Kartikeya Dwivedi @ 2026-09-14 13:24 UTC (permalink / raw)
  To: bpf
  Cc: Alexei Starovoitov, Andrii Nakryiko, Daniel Borkmann,
	Eduard Zingerman, Emil Tsalapatis, Nicholas Carlini, kkd,
	kernel-team

Bound and ensure acyclic ownership graphs for native data structures to
fix a bug reported by Nicholas. See commit logs and tests for details.

The existing list/rbtree rule already rejects graph-only cycles and bounds
those chains conservatively. It misses ownership through local referenced
kptrs, which can produce unbounded synchronous field destruction. Validate
all local ownership edges together, with an explicit depth bound, and allow
longer acyclic graph-only layouts within that bound.

Changelog:
----------
v1 -> v2
v1: https://lore.kernel.org/bpf/20260905090750.4064411-1-memxor@gmail.com/

 * Fold the graph-walk and local-kptr changes into one complete fix. (Alexei)
 * Explain why the original rule catches graph-only cycles, its three-type
   chain bound, and the missing local-kptr ownership edges. (Alexei)
 * Distinguish synchronous recursive field destruction from the deferred
   RCU freeing of object storage.
 * Add depth-boundary tests with child-first BTF ordering and a shared
   suffix reached with different remaining budgets.
 * Cover list and rbtree chains at the original three-type bound and at the
   new eight-type bound, including rejected over-limit cases.

Kumar Kartikeya Dwivedi (2):
  bpf: Bound ownership depth through local kptrs and graph roots
  selftests/bpf: Check local object ownership depth

 kernel/bpf/btf.c                              | 134 +++++---
 .../selftests/bpf/prog_tests/linked_list.c    |   4 +-
 .../bpf/prog_tests/local_kptr_ownership.c     | 296 ++++++++++++++++++
 3 files changed, 384 insertions(+), 50 deletions(-)
 create mode 100644 tools/testing/selftests/bpf/prog_tests/local_kptr_ownership.c


base-commit: a41c69c6ea14596cfd95978483166d4eff52435e
-- 
2.53.0


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-09-19  5:31 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-14 13:24 [PATCH bpf-next v2 0/2] Fix acyclic ownership checks Kumar Kartikeya Dwivedi
2026-09-14 13:24 ` [PATCH bpf-next v2 1/2] bpf: Bound ownership depth through local kptrs and graph roots Kumar Kartikeya Dwivedi
2026-09-14 13:24 ` [PATCH bpf-next v2 2/2] selftests/bpf: Check local object ownership depth Kumar Kartikeya Dwivedi
2026-09-14 14:16   ` bot+bpf-ci
2026-09-19  5:30 ` [PATCH bpf-next v2 0/2] Fix acyclic ownership checks patchwork-bot+netdevbpf

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox