BPF List
 help / color / mirror / Atom feed
* [PATCH bpf v7 00/10] Misc bug fixes - part 5
@ 2026-09-17 23:32 Kumar Kartikeya Dwivedi
  2026-09-17 23:32 ` [PATCH bpf v7 01/10] bpf: Make post-verification instruction rewrites killable Kumar Kartikeya Dwivedi
                   ` (10 more replies)
  0 siblings, 11 replies; 13+ messages in thread
From: Kumar Kartikeya Dwivedi @ 2026-09-17 23:32 UTC (permalink / raw)
  To: bpf
  Cc: Alexei Starovoitov, Andrii Nakryiko, Daniel Borkmann,
	Eduard Zingerman, Emil Tsalapatis, Nicholas Carlini, kkd,
	kernel-team

A set of miscellaneous fixes for bugs reported by Nicholas. See commit
logs for details.

Changelog:
----------
v6 -> v7
v6: https://lore.kernel.org/bpf/20260917111127.3780880-1-memxor@gmail.com

 * Correct the trailing ldimm64 rationale and exercise the early guard with
   CO-RE metadata. (BPF CI)
 * Keep the relocation-ordering regression causal after target hardening.
   (BPF CI)
 * Document the raw BTF access-string offset and PTR_TO_INSN map pointer.
   (BPF CI)

v5 -> v6
v5: https://lore.kernel.org/bpf/20260916212102.597335-1-memxor@gmail.com

 * Rebase on bpf/master.

v4 -> v5
v4: https://lore.kernel.org/bpf/20260914222514.1635018-1-memxor@gmail.com

 * Reject a terminal ldimm64 before in-kernel CO-RE relocation and add
   focused verifier coverage. (Eduard)
 * Bound truncated ldimm64 relocations in libbpf's relocation loop and
   retain resolved and unresolved regression coverage. (Eduard, BPF CI)
 * Encode the early CO-RE test BTF with the BTF_* helpers and fold the
   standalone follow-up into its owning patch. (Eduard)
 * Use one fixed instruction stream for CO-RE poison tests without a
   conditional program length. (Eduard)
 * Drop final selftest commit.
 * Trim callback lock identity selftests to the mismatched-value cases.
   (Eduard)

v3 -> v4
v3: https://lore.kernel.org/bpf/20260914131701.2529725-1-memxor@gmail.com

 * Return interrupted main-program JIT compilation through ERR_PTR()
   instead of an output parameter. (Eduard)
 * Apply in-kernel CO-RE relocations before subprogram discovery and
   validation, while keeping func_info and line_info validation after
   layout discovery. (Andrii, Alexei)
 * Keep relocation-target hardening as a separate patch and diagnose
   invalid register-source ALU targets. (Alexei, Eduard, BPF CI)
 * Extract CO-RE poisoning into a returning helper so validated
   instruction cases can propagate its status directly. (Andrii)
 * Restore the existing inner-map UID comment wording. (Eduard)
 * Add bounds checking and selftests for truncated ldimm64 CO-RE
   relocations. (Sashiko)

v2 -> v3
v2: https://lore.kernel.org/bpf/20260905083418.3723623-1-memxor@gmail.com

 * Propagate cancellation from constant blinding through both JIT fallback
   paths instead of rechecking fatal signals in bpf_check(). (Eduard)
 * Preserve packet-pointer displacement by comparing range bases, without
   extending the generic ID map. Veristat showed identical verdicts and
   successful-program instruction/state counts across 2773 loads. (Eduard,
   Alexei)
 * Reduce the packet pruning regression to 20 instructions and force state
   checkpoints. (Alexei, BPF CI)
 * Reject unsupported CO-RE poisoning targets in the shared relocation
   code instead of adding a CFG fall-through check. (Alexei)
 * Cover unsupported poison targets and supported relocations in dead code,
   including both halves of ldimm64.
 * Assign callback value IDs unconditionally and compare inner-map lookup
   IDs through check_ids(); explain the bug with a small program. (Eduard)
 * Move map_uid beside the other IDs and shrink frameno to preserve the
   register state size, keeping the existing memcmp() ranges.
 * Consolidate callback tests into the existing spinlock tests and reuse
   their map fixtures. Retain one-element and nested locking controls, and
   check nonzero IDs in timer, workqueue, and task-work callbacks. Clarify
   the inner-map lookup test description. (BPF CI)

v1 -> v2
v1: https://lore.kernel.org/bpf/20260905070003.3193366-1-memxor@gmail.com

 * Address inner map corner case for callback map value patch.
 * Drop patch 2 since the test can be flaky.

Kumar Kartikeya Dwivedi (10):
  bpf: Make post-verification instruction rewrites killable
  bpf: Preserve packet pointer class displacement in regsafe()
  selftests/bpf: Test packet pointer class displacement pruning
  bpf: Apply CO-RE relocations before subprogram validation
  selftests/bpf: Test early in-kernel CO-RE relocation
  bpf: Restrict CO-RE poisoning to relocatable instructions
  selftests/bpf: Test CO-RE instruction poisoning restrictions
  bpf: Assign lock identity to callback map values
  selftests/bpf: Check callback map value lock identity
  libbpf: Reject truncated ldimm64 CO-RE relocations

 include/linux/bpf_verifier.h                  |  27 +--
 kernel/bpf/check_btf.c                        |  12 +-
 kernel/bpf/core.c                             |  21 +-
 kernel/bpf/fixups.c                           |  24 ++-
 kernel/bpf/states.c                           |   9 +-
 kernel/bpf/verifier.c                         |  25 ++-
 tools/lib/bpf/libbpf.c                        |   7 +
 tools/lib/bpf/relo_core.c                     |  58 +++---
 .../selftests/bpf/prog_tests/cb_refs.c        |   2 +-
 .../selftests/bpf/prog_tests/core_reloc_raw.c | 192 ++++++++++++++++++
 .../selftests/bpf/prog_tests/spin_lock.c      |   2 +
 .../selftests/bpf/progs/test_spin_lock_fail.c |  67 +++++-
 .../progs/verifier_xdp_direct_packet_access.c |  35 ++++
 13 files changed, 418 insertions(+), 63 deletions(-)


base-commit: 8d9eae69170e6d780da07408fc6471f877cf65e5
-- 
2.53.0


^ permalink raw reply	[flat|nested] 13+ messages in thread

end of thread, other threads:[~2026-09-18  1:11 UTC | newest]

Thread overview: 13+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-17 23:32 [PATCH bpf v7 00/10] Misc bug fixes - part 5 Kumar Kartikeya Dwivedi
2026-09-17 23:32 ` [PATCH bpf v7 01/10] bpf: Make post-verification instruction rewrites killable Kumar Kartikeya Dwivedi
2026-09-17 23:32 ` [PATCH bpf v7 02/10] bpf: Preserve packet pointer class displacement in regsafe() Kumar Kartikeya Dwivedi
2026-09-17 23:32 ` [PATCH bpf v7 03/10] selftests/bpf: Test packet pointer class displacement pruning Kumar Kartikeya Dwivedi
2026-09-17 23:32 ` [PATCH bpf v7 04/10] bpf: Apply CO-RE relocations before subprogram validation Kumar Kartikeya Dwivedi
2026-09-17 23:32 ` [PATCH bpf v7 05/10] selftests/bpf: Test early in-kernel CO-RE relocation Kumar Kartikeya Dwivedi
2026-09-17 23:32 ` [PATCH bpf v7 06/10] bpf: Restrict CO-RE poisoning to relocatable instructions Kumar Kartikeya Dwivedi
2026-09-17 23:32 ` [PATCH bpf v7 07/10] selftests/bpf: Test CO-RE instruction poisoning restrictions Kumar Kartikeya Dwivedi
2026-09-17 23:32 ` [PATCH bpf v7 08/10] bpf: Assign lock identity to callback map values Kumar Kartikeya Dwivedi
2026-09-17 23:32 ` [PATCH bpf v7 09/10] selftests/bpf: Check callback map value lock identity Kumar Kartikeya Dwivedi
2026-09-17 23:46   ` sashiko-bot
2026-09-17 23:32 ` [PATCH bpf v7 10/10] libbpf: Reject truncated ldimm64 CO-RE relocations Kumar Kartikeya Dwivedi
2026-09-18  1:10 ` [PATCH bpf v7 00/10] Misc bug fixes - part 5 patchwork-bot+netdevbpf

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox