From: Kumar Kartikeya Dwivedi <memxor@gmail.com>
To: bpf@vger.kernel.org
Cc: Alexei Starovoitov <ast@kernel.org>,
Andrii Nakryiko <andrii@kernel.org>,
Daniel Borkmann <daniel@iogearbox.net>,
Eduard Zingerman <eddyz87@gmail.com>,
Emil Tsalapatis <emil@etsalapatis.com>,
Nicholas Carlini <npc@anthropic.com>,
kkd@meta.com, kernel-team@meta.com
Subject: [PATCH bpf v6 00/10] Misc bug fixes - part 5
Date: Thu, 17 Sep 2026 13:11:12 +0200 [thread overview]
Message-ID: <20260917111127.3780880-1-memxor@gmail.com> (raw)
A set of miscellaneous fixes for bugs reported by Nicholas. See commit
logs for details.
Changelog:
----------
v5 -> v6
v5: https://lore.kernel.org/bpf/20260916212102.597335-1-memxor@gmail.com
* Rebase on bpf/master.
v4 -> v5
v4: https://lore.kernel.org/bpf/20260914222514.1635018-1-memxor@gmail.com
* Reject a terminal ldimm64 before in-kernel CO-RE relocation and add
focused verifier coverage. (Eduard)
* Bound truncated ldimm64 relocations in libbpf's relocation loop and
retain resolved and unresolved regression coverage. (Eduard, BPF CI)
* Encode the early CO-RE test BTF with the BTF_* helpers and fold the
standalone follow-up into its owning patch. (Eduard)
* Use one fixed instruction stream for CO-RE poison tests without a
conditional program length. (Eduard)
* Drop final selftest commit.
* Trim callback lock identity selftests to the mismatched-value cases.
(Eduard)
v3 -> v4
v3: https://lore.kernel.org/bpf/20260914131701.2529725-1-memxor@gmail.com
* Return interrupted main-program JIT compilation through ERR_PTR()
instead of an output parameter. (Eduard)
* Apply in-kernel CO-RE relocations before subprogram discovery and
validation, while keeping func_info and line_info validation after
layout discovery. (Andrii, Alexei)
* Keep relocation-target hardening as a separate patch and diagnose
invalid register-source ALU targets. (Alexei, Eduard, BPF CI)
* Extract CO-RE poisoning into a returning helper so validated
instruction cases can propagate its status directly. (Andrii)
* Restore the existing inner-map UID comment wording. (Eduard)
* Add bounds checking and selftests for truncated ldimm64 CO-RE
relocations. (Sashiko)
v2 -> v3
v2: https://lore.kernel.org/bpf/20260905083418.3723623-1-memxor@gmail.com
* Propagate cancellation from constant blinding through both JIT fallback
paths instead of rechecking fatal signals in bpf_check(). (Eduard)
* Preserve packet-pointer displacement by comparing range bases, without
extending the generic ID map. Veristat showed identical verdicts and
successful-program instruction/state counts across 2773 loads. (Eduard,
Alexei)
* Reduce the packet pruning regression to 20 instructions and force state
checkpoints. (Alexei, BPF CI)
* Reject unsupported CO-RE poisoning targets in the shared relocation
code instead of adding a CFG fall-through check. (Alexei)
* Cover unsupported poison targets and supported relocations in dead code,
including both halves of ldimm64.
* Assign callback value IDs unconditionally and compare inner-map lookup
IDs through check_ids(); explain the bug with a small program. (Eduard)
* Move map_uid beside the other IDs and shrink frameno to preserve the
register state size, keeping the existing memcmp() ranges.
* Consolidate callback tests into the existing spinlock tests and reuse
their map fixtures. Retain one-element and nested locking controls, and
check nonzero IDs in timer, workqueue, and task-work callbacks. Clarify
the inner-map lookup test description. (BPF CI)
v1 -> v2
v1: https://lore.kernel.org/bpf/20260905070003.3193366-1-memxor@gmail.com
* Address inner map corner case for callback map value patch.
* Drop patch 2 since the test can be flaky.
Kumar Kartikeya Dwivedi (10):
bpf: Make post-verification instruction rewrites killable
bpf: Preserve packet pointer class displacement in regsafe()
selftests/bpf: Test packet pointer class displacement pruning
bpf: Apply CO-RE relocations before subprogram validation
selftests/bpf: Test early in-kernel CO-RE relocation
bpf: Restrict CO-RE poisoning to relocatable instructions
selftests/bpf: Test CO-RE instruction poisoning restrictions
bpf: Assign lock identity to callback map values
selftests/bpf: Check callback map value lock identity
libbpf: Reject truncated ldimm64 CO-RE relocations
include/linux/bpf_verifier.h | 26 +--
kernel/bpf/check_btf.c | 12 +-
kernel/bpf/core.c | 21 +-
kernel/bpf/fixups.c | 24 ++-
kernel/bpf/states.c | 9 +-
kernel/bpf/verifier.c | 25 ++-
tools/lib/bpf/libbpf.c | 7 +
tools/lib/bpf/relo_core.c | 58 +++---
.../selftests/bpf/prog_tests/cb_refs.c | 2 +-
.../selftests/bpf/prog_tests/core_reloc_raw.c | 183 ++++++++++++++++++
.../selftests/bpf/prog_tests/spin_lock.c | 2 +
.../selftests/bpf/progs/test_spin_lock_fail.c | 67 ++++++-
.../progs/verifier_xdp_direct_packet_access.c | 35 ++++
.../testing/selftests/bpf/verifier/ld_imm64.c | 8 +
14 files changed, 416 insertions(+), 63 deletions(-)
base-commit: 8d9eae69170e6d780da07408fc6471f877cf65e5
--
2.53.0
next reply other threads:[~2026-09-17 11:11 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-17 11:11 Kumar Kartikeya Dwivedi [this message]
2026-09-17 11:11 ` [PATCH bpf v6 01/10] bpf: Make post-verification instruction rewrites killable Kumar Kartikeya Dwivedi
2026-09-17 11:11 ` [PATCH bpf v6 02/10] bpf: Preserve packet pointer class displacement in regsafe() Kumar Kartikeya Dwivedi
2026-09-17 11:11 ` [PATCH bpf v6 03/10] selftests/bpf: Test packet pointer class displacement pruning Kumar Kartikeya Dwivedi
2026-09-17 11:11 ` [PATCH bpf v6 04/10] bpf: Apply CO-RE relocations before subprogram validation Kumar Kartikeya Dwivedi
2026-09-17 12:29 ` bot+bpf-ci
2026-09-17 11:11 ` [PATCH bpf v6 05/10] selftests/bpf: Test early in-kernel CO-RE relocation Kumar Kartikeya Dwivedi
2026-09-17 12:29 ` bot+bpf-ci
2026-09-17 11:11 ` [PATCH bpf v6 06/10] bpf: Restrict CO-RE poisoning to relocatable instructions Kumar Kartikeya Dwivedi
2026-09-17 12:29 ` bot+bpf-ci
2026-09-17 11:11 ` [PATCH bpf v6 07/10] selftests/bpf: Test CO-RE instruction poisoning restrictions Kumar Kartikeya Dwivedi
2026-09-17 11:11 ` [PATCH bpf v6 08/10] bpf: Assign lock identity to callback map values Kumar Kartikeya Dwivedi
2026-09-17 12:29 ` bot+bpf-ci
2026-09-17 11:11 ` [PATCH bpf v6 09/10] selftests/bpf: Check callback map value lock identity Kumar Kartikeya Dwivedi
2026-09-17 11:11 ` [PATCH bpf v6 10/10] libbpf: Reject truncated ldimm64 CO-RE relocations Kumar Kartikeya Dwivedi
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260917111127.3780880-1-memxor@gmail.com \
--to=memxor@gmail.com \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=eddyz87@gmail.com \
--cc=emil@etsalapatis.com \
--cc=kernel-team@meta.com \
--cc=kkd@meta.com \
--cc=npc@anthropic.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox