BPF List
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Yonghong Song" <yonghong.song@linux.dev>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf-next 16/20] libbpf: Carry the exception cleanup table through the light skeleton
Date: Thu, 17 Sep 2026 06:18:38 +0000	[thread overview]
Message-ID: <20260917061838.F013C1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260917055807.3934205-1-yonghong.song@linux.dev>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] libbpf: unconditional cleanup_info emission breaks backward compatibility on older kernels
- [Medium] libbpf: integer overflow in cleanup_info size calculation leads to OOB read/write
--

commit 076a2794e54df3a939c1a2aebf4467a8a0af5e41
Author: Yonghong Song <yonghong.song@linux.dev>

libbpf: Carry the exception cleanup table through the light skeleton

This commit adds support for carrying the exception cleanup table through
the light skeleton during BPF program loads. It expands the bpf_attr union
to include cleanup_info fields and handles endianness byte-swapping for the
records.

> diff --git a/tools/lib/bpf/gen_loader.c b/tools/lib/bpf/gen_loader.c
> index af3a04f161ac1..e9bb282a557a3 100644
> --- a/tools/lib/bpf/gen_loader.c
> +++ b/tools/lib/bpf/gen_loader.c
[ ... ]
> @@ -1011,8 +1016,11 @@ void bpf_gen__prog_load(struct bpf_gen *gen,
>  			       load_attr->line_info_rec_size;
>  	int core_relo_tot_sz = gen->core_relo_cnt *
>  			       sizeof(struct bpf_core_relo);
> +	int cleanup_info_tot_sz = load_attr->cleanup_info_cnt *
> +				  load_attr->cleanup_info_rec_size;

[Severity: Medium]
Is there a risk of integer overflow here when parsing untrusted ELF files?

If load_attr->cleanup_info_cnt is large enough, the multiplication with
load_attr->cleanup_info_rec_size could overflow the 32-bit signed integer
cleanup_info_tot_sz, resulting in a truncated heap allocation.

Later in info_blob_bswap(), the loop executes load_attr->cleanup_info_cnt
times:

info_blob_bswap() {
    ...
    for (i = 0; i < load_attr->cleanup_info_cnt; i++)
        bpf_cleanup_info_bswap(ci++);
}

Could this lead to an out-of-bounds memory read and write over the
truncated buffer, potentially causing memory corruption in userspace
tooling like bpftool?

[ ... ]
> @@ -1085,6 +1101,9 @@ void bpf_gen__prog_load(struct bpf_gen *gen,
>  	/* populate union bpf_attr with a pointer to core_relos */
>  	emit_rel_store(gen, attr_field(prog_load_attr, core_relos), core_relos);
>  
> +	/* populate union bpf_attr with a pointer to cleanup_info */
> +	emit_rel_store(gen, attr_field(prog_load_attr, cleanup_info), cleanup_info);

[Severity: High]
Will this unconditional emission cause light skeletons to fail to load on
older kernels?

By unconditionally writing a non-zero pointer (the offset in the data blob)
into the tail of the BPF attribute structure, older target kernels that do
not support the cleanup_info field might reject the BPF_PROG_LOAD syscall.

Because sys_bpf verifies that all fields beyond its known sizeof(union
bpf_attr) are zero using bpf_check_uarg_tail_zero(), it seems this could
fail with -E2BIG. Does this break backward compatibility for all light
skeletons running on older kernels, even those that do not use exceptions?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260917055645.3926444-1-yonghong.song@linux.dev?part=16

  reply	other threads:[~2026-09-17  6:18 UTC|newest]

Thread overview: 40+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-17  5:56 [PATCH bpf-next 00/20] bpf: Run exception cleanup landing pads when bpf_throw() unwinds Yonghong Song
2026-09-17  5:56 ` [PATCH bpf-next 01/20] bpf: Accept the compiler's exception cleanup table at program load Yonghong Song
2026-09-17  5:56 ` [PATCH bpf-next 02/20] bpf: Add the bpf_unwind_resume() kfunc Yonghong Song
2026-09-17  5:57 ` [PATCH bpf-next 03/20] bpf: Add lookups for exception cleanup resumes and landing pads Yonghong Song
2026-09-17  5:57 ` [PATCH bpf-next 04/20] bpf: Mark the call sites an exception cleanup table covers Yonghong Song
2026-09-17  5:57 ` [PATCH bpf-next 05/20] bpf: Make exception landing pads reachable in the CFG Yonghong Song
2026-09-17  6:22   ` sashiko-bot
2026-09-18  3:36     ` Yonghong Song
2026-09-17  5:57 ` [PATCH bpf-next 06/20] bpf: Explore the landing pads no call site reaches Yonghong Song
2026-09-17  5:57 ` [PATCH bpf-next 07/20] bpf: Refuse exception cleanup shapes bpf_throw() cannot dispatch Yonghong Song
2026-09-19  4:57   ` Alexei Starovoitov
2026-09-19 17:32     ` Yonghong Song
2026-09-17  5:57 ` [PATCH bpf-next 08/20] bpf: Walk the exception unwind in the verifier Yonghong Song
2026-09-19  4:57   ` Alexei Starovoitov
2026-09-19 17:36     ` Yonghong Song
2026-09-17  5:57 ` [PATCH bpf-next 09/20] bpf: Refuse a private stack for a program with an exception cleanup table Yonghong Song
2026-09-17  5:57 ` [PATCH bpf-next 10/20] bpf: Dispatch exception cleanup pads from bpf_throw() Yonghong Song
2026-09-17  5:57 ` [PATCH bpf-next 11/20] bpf, x86: Dispatch exception cleanup pads at run time Yonghong Song
2026-09-19  5:02   ` Alexei Starovoitov
2026-09-19 19:13     ` Yonghong Song
2026-09-17  5:57 ` [PATCH bpf-next 12/20] bpf, arm64: " Yonghong Song
2026-09-17  5:57 ` [PATCH bpf-next 13/20] libbpf: Resolve the compiler's _Unwind_Resume to the kernel's kfunc Yonghong Song
2026-09-17  6:08   ` sashiko-bot
2026-09-17  7:00   ` bot+bpf-ci
2026-09-18  3:40     ` Yonghong Song
2026-09-17  5:57 ` [PATCH bpf-next 14/20] libbpf: Add cleanup_info to bpf_prog_load_opts Yonghong Song
2026-09-17  5:58 ` [PATCH bpf-next 15/20] libbpf: Collect .bpf_cleanup records and pass them to the kernel Yonghong Song
2026-09-17  6:12   ` sashiko-bot
2026-09-18  3:44     ` Yonghong Song
2026-09-17  5:58 ` [PATCH bpf-next 16/20] libbpf: Carry the exception cleanup table through the light skeleton Yonghong Song
2026-09-17  6:18   ` sashiko-bot [this message]
2026-09-18  3:52     ` Yonghong Song
2026-09-17  5:58 ` [PATCH bpf-next 17/20] libbpf: Let the static linker carry .bpf_cleanup relocations Yonghong Song
2026-09-17  6:16   ` sashiko-bot
2026-09-18  3:58     ` Yonghong Song
2026-09-17  5:58 ` [PATCH bpf-next 18/20] selftests/bpf: Add an end-to-end .bpf_cleanup exception test Yonghong Song
2026-09-17  6:12   ` sashiko-bot
2026-09-17  5:58 ` [PATCH bpf-next 19/20] selftests/bpf: Cover the exception cleanup shapes the chain does not reach Yonghong Song
2026-09-17  6:16   ` sashiko-bot
2026-09-17  5:58 ` [PATCH bpf-next 20/20] selftests/bpf: Load an exception cleanup program from a light skeleton Yonghong Song

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260917061838.F013C1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=yonghong.song@linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox