BPF List
 help / color / mirror / Atom feed
* [PATCH bpf-next v3 0/5] Fix generic __uninit kfunc output buffers
@ 2026-09-16 19:27 Kumar Kartikeya Dwivedi
  2026-09-16 19:27 ` [PATCH bpf-next v3 1/5] selftests/bpf: Allow privileged preparation for capability tests Kumar Kartikeya Dwivedi
                   ` (4 more replies)
  0 siblings, 5 replies; 12+ messages in thread
From: Kumar Kartikeya Dwivedi @ 2026-09-16 19:27 UTC (permalink / raw)
  To: bpf
  Cc: Alexei Starovoitov, Andrii Nakryiko, Daniel Borkmann,
	Eduard Zingerman, Emil Tsalapatis, Tejun Heo, Amery Hung, kkd,
	kernel-team

Generic __uninit kfunc arguments are output buffers. Stack liveness treats
them as writes, but argument checking still requires readable contents and
does not record definite initialization after the call. Check these
arguments as write-only and record their initialization after validating all
inputs, including inputs that alias an output.

Keep the single-output fix and its immediate regression tests separate from
the extension for multiple outputs. The first three patches provide the
capability-test prerequisite, the backportable kernel fix, and its tests.
The kernel fix itself has no dependency on the test fixture. The final two
patches add per-argument output tracking and its focused tests. This
extension is optional; there is no current production consumer for multiple
outputs.

The opt-in __prepare_priv annotation uses libbpf's prepare/load boundary to
resolve module BTF before dropping CAP_SYS_ADMIN and CAP_PERFMON. Program
loading then runs with the capabilities selected by __caps_unpriv. Ordinary
unprivileged tests keep their existing preparation path, and disabled or
undetectable CPU mitigations still cause the relevant tests to be skipped.

Changelog:
----------
v2 -> v3
v2: https://lore.kernel.org/bpf/20260916160821.3157543-1-memxor@gmail.com

 * Reuse check_raw_mode_ok() after kfunc prototype generation, including
   struct outputs resolved to generic memory later. (Amery)
 * Remove the now-redundant kfunc output-count check in the multiple-output
   extension and simplify the helper validator.
 * Leave the stack-passed output uninitialized so the reduced-capability
   test detects missing __uninit handling. (Sashiko)

v1 -> v2
v1: https://lore.kernel.org/bpf/20260915141004.1196460-1-memxor@gmail.com

 * Separate the single-output fix and tests from multiple-output support
   and its tests; reduce coverage to focused cases. (Eduard)
 * Skip inactive output slots before looking up argument register state.
   (Sashiko, Amery)
 * Separate sysctl restrictions from mitigation-related test skips.
   (BPF CI)
 * Use an int-width initialization store in the alias test for big-endian
   targets. (BPF CI)
 * Centralize conversion from argument numbers to slots. (Eduard)
 * Share clear access-mode selection between fixed-size and sized arguments.
   (Amery)
 * Clarify the opt-in prepare/load capability boundary and retain the
   reduced-capability alias rejection test. (Eduard)

Kumar Kartikeya Dwivedi (5):
  selftests/bpf: Allow privileged preparation for capability tests
  bpf: Fix generic __uninit kfunc output buffers
  selftests/bpf: Cover generic __uninit output initialization
  bpf: Support multiple __uninit kfunc output arguments
  selftests/bpf: Cover __uninit kfunc output argument slots

 Documentation/bpf/kfuncs.rst                  |  27 +++--
 include/linux/bpf_verifier.h                  |  11 +-
 kernel/bpf/verifier.c                         |  93 ++++++++++----
 .../selftests/bpf/prog_tests/verifier.c       |   4 +
 tools/testing/selftests/bpf/progs/bpf_misc.h  |   9 +-
 .../bpf/progs/verifier_kfunc_uninit.c         | 100 ++++++++++++++++
 .../bpf/progs/verifier_kfunc_uninit_multi.c   | 113 ++++++++++++++++++
 .../selftests/bpf/test_kmods/bpf_testmod.c    |  44 +++++++
 .../bpf/test_kmods/bpf_testmod_kfunc.h        |   7 ++
 tools/testing/selftests/bpf/test_loader.c     |  48 +++++---
 tools/testing/selftests/bpf/unpriv_helpers.c  |  16 ++-
 tools/testing/selftests/bpf/unpriv_helpers.h  |   2 +
 12 files changed, 418 insertions(+), 56 deletions(-)
 create mode 100644 tools/testing/selftests/bpf/progs/verifier_kfunc_uninit.c
 create mode 100644 tools/testing/selftests/bpf/progs/verifier_kfunc_uninit_multi.c


base-commit: 5ef40d69b38a93bc9951dadb1a15c85c597e1a40
-- 
2.53.0


^ permalink raw reply	[flat|nested] 12+ messages in thread

end of thread, other threads:[~2026-09-17 19:29 UTC | newest]

Thread overview: 12+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-16 19:27 [PATCH bpf-next v3 0/5] Fix generic __uninit kfunc output buffers Kumar Kartikeya Dwivedi
2026-09-16 19:27 ` [PATCH bpf-next v3 1/5] selftests/bpf: Allow privileged preparation for capability tests Kumar Kartikeya Dwivedi
2026-09-16 19:27 ` [PATCH bpf-next v3 2/5] bpf: Fix generic __uninit kfunc output buffers Kumar Kartikeya Dwivedi
2026-09-16 19:52   ` Amery Hung
2026-09-16 20:27     ` Amery Hung
2026-09-16 20:27   ` bot+bpf-ci
2026-09-17 19:29   ` Eduard Zingerman
2026-09-16 19:28 ` [PATCH bpf-next v3 3/5] selftests/bpf: Cover generic __uninit output initialization Kumar Kartikeya Dwivedi
2026-09-16 20:05   ` Amery Hung
2026-09-16 20:27   ` bot+bpf-ci
2026-09-16 19:28 ` [PATCH bpf-next v3 4/5] bpf: Support multiple __uninit kfunc output arguments Kumar Kartikeya Dwivedi
2026-09-16 19:28 ` [PATCH bpf-next v3 5/5] selftests/bpf: Cover __uninit kfunc output argument slots Kumar Kartikeya Dwivedi

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox