From: Kumar Kartikeya Dwivedi <memxor@gmail.com>
To: bpf@vger.kernel.org
Cc: Alexei Starovoitov <ast@kernel.org>,
Andrii Nakryiko <andrii@kernel.org>,
Daniel Borkmann <daniel@iogearbox.net>,
Eduard Zingerman <eddyz87@gmail.com>,
Emil Tsalapatis <emil@etsalapatis.com>, Tejun Heo <tj@kernel.org>,
Amery Hung <ameryhung@gmail.com>,
kkd@meta.com, kernel-team@meta.com
Subject: [PATCH bpf-next v3 0/5] Fix generic __uninit kfunc output buffers
Date: Wed, 16 Sep 2026 21:27:57 +0200 [thread overview]
Message-ID: <20260916192805.3991983-1-memxor@gmail.com> (raw)
Generic __uninit kfunc arguments are output buffers. Stack liveness treats
them as writes, but argument checking still requires readable contents and
does not record definite initialization after the call. Check these
arguments as write-only and record their initialization after validating all
inputs, including inputs that alias an output.
Keep the single-output fix and its immediate regression tests separate from
the extension for multiple outputs. The first three patches provide the
capability-test prerequisite, the backportable kernel fix, and its tests.
The kernel fix itself has no dependency on the test fixture. The final two
patches add per-argument output tracking and its focused tests. This
extension is optional; there is no current production consumer for multiple
outputs.
The opt-in __prepare_priv annotation uses libbpf's prepare/load boundary to
resolve module BTF before dropping CAP_SYS_ADMIN and CAP_PERFMON. Program
loading then runs with the capabilities selected by __caps_unpriv. Ordinary
unprivileged tests keep their existing preparation path, and disabled or
undetectable CPU mitigations still cause the relevant tests to be skipped.
Changelog:
----------
v2 -> v3
v2: https://lore.kernel.org/bpf/20260916160821.3157543-1-memxor@gmail.com
* Reuse check_raw_mode_ok() after kfunc prototype generation, including
struct outputs resolved to generic memory later. (Amery)
* Remove the now-redundant kfunc output-count check in the multiple-output
extension and simplify the helper validator.
* Leave the stack-passed output uninitialized so the reduced-capability
test detects missing __uninit handling. (Sashiko)
v1 -> v2
v1: https://lore.kernel.org/bpf/20260915141004.1196460-1-memxor@gmail.com
* Separate the single-output fix and tests from multiple-output support
and its tests; reduce coverage to focused cases. (Eduard)
* Skip inactive output slots before looking up argument register state.
(Sashiko, Amery)
* Separate sysctl restrictions from mitigation-related test skips.
(BPF CI)
* Use an int-width initialization store in the alias test for big-endian
targets. (BPF CI)
* Centralize conversion from argument numbers to slots. (Eduard)
* Share clear access-mode selection between fixed-size and sized arguments.
(Amery)
* Clarify the opt-in prepare/load capability boundary and retain the
reduced-capability alias rejection test. (Eduard)
Kumar Kartikeya Dwivedi (5):
selftests/bpf: Allow privileged preparation for capability tests
bpf: Fix generic __uninit kfunc output buffers
selftests/bpf: Cover generic __uninit output initialization
bpf: Support multiple __uninit kfunc output arguments
selftests/bpf: Cover __uninit kfunc output argument slots
Documentation/bpf/kfuncs.rst | 27 +++--
include/linux/bpf_verifier.h | 11 +-
kernel/bpf/verifier.c | 93 ++++++++++----
.../selftests/bpf/prog_tests/verifier.c | 4 +
tools/testing/selftests/bpf/progs/bpf_misc.h | 9 +-
.../bpf/progs/verifier_kfunc_uninit.c | 100 ++++++++++++++++
.../bpf/progs/verifier_kfunc_uninit_multi.c | 113 ++++++++++++++++++
.../selftests/bpf/test_kmods/bpf_testmod.c | 44 +++++++
.../bpf/test_kmods/bpf_testmod_kfunc.h | 7 ++
tools/testing/selftests/bpf/test_loader.c | 48 +++++---
tools/testing/selftests/bpf/unpriv_helpers.c | 16 ++-
tools/testing/selftests/bpf/unpriv_helpers.h | 2 +
12 files changed, 418 insertions(+), 56 deletions(-)
create mode 100644 tools/testing/selftests/bpf/progs/verifier_kfunc_uninit.c
create mode 100644 tools/testing/selftests/bpf/progs/verifier_kfunc_uninit_multi.c
base-commit: 5ef40d69b38a93bc9951dadb1a15c85c597e1a40
--
2.53.0
next reply other threads:[~2026-09-16 19:28 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-16 19:27 Kumar Kartikeya Dwivedi [this message]
2026-09-16 19:27 ` [PATCH bpf-next v3 1/5] selftests/bpf: Allow privileged preparation for capability tests Kumar Kartikeya Dwivedi
2026-09-16 19:27 ` [PATCH bpf-next v3 2/5] bpf: Fix generic __uninit kfunc output buffers Kumar Kartikeya Dwivedi
2026-09-16 19:52 ` Amery Hung
2026-09-16 20:27 ` Amery Hung
2026-09-16 20:27 ` bot+bpf-ci
2026-09-17 19:29 ` Eduard Zingerman
2026-09-16 19:28 ` [PATCH bpf-next v3 3/5] selftests/bpf: Cover generic __uninit output initialization Kumar Kartikeya Dwivedi
2026-09-16 20:05 ` Amery Hung
2026-09-16 20:27 ` bot+bpf-ci
2026-09-16 19:28 ` [PATCH bpf-next v3 4/5] bpf: Support multiple __uninit kfunc output arguments Kumar Kartikeya Dwivedi
2026-09-16 19:28 ` [PATCH bpf-next v3 5/5] selftests/bpf: Cover __uninit kfunc output argument slots Kumar Kartikeya Dwivedi
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260916192805.3991983-1-memxor@gmail.com \
--to=memxor@gmail.com \
--cc=ameryhung@gmail.com \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=eddyz87@gmail.com \
--cc=emil@etsalapatis.com \
--cc=kernel-team@meta.com \
--cc=kkd@meta.com \
--cc=tj@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox