From: Kumar Kartikeya Dwivedi <memxor@gmail.com>
To: bpf@vger.kernel.org
Cc: Alexei Starovoitov <ast@kernel.org>,
Andrii Nakryiko <andrii@kernel.org>,
Daniel Borkmann <daniel@iogearbox.net>,
Eduard Zingerman <eddyz87@gmail.com>,
Emil Tsalapatis <emil@etsalapatis.com>, Tejun Heo <tj@kernel.org>,
Amery Hung <ameryhung@gmail.com>,
kkd@meta.com, kernel-team@meta.com
Subject: [PATCH bpf-next v4 0/8] Fix generic __uninit kfunc output buffers
Date: Fri, 18 Sep 2026 07:28:54 +0200 [thread overview]
Message-ID: <20260918052906.12226-1-memxor@gmail.com> (raw)
Generic __uninit kfunc arguments are output buffers. Stack liveness treats
them as writes, but argument checking still requires readable contents and
does not record definite initialization after the call. Check these
arguments as write-only and record their initialization after validating all
inputs, including inputs that alias an output.
Following Eduard's rework, helpers and kfuncs now record generic outputs in
the same argument-checking path after type resolution. Their memory access
checks also use the same argument flags. This includes a separate helper
fix: MEM_WRITE without MEM_UNINIT requires read as well as write permission.
The helper fix and its permission tests remain separate from the original
kfunc fix and its immediate tests.
Changelog:
----------
v3 -> v4
v3: https://lore.kernel.org/bpf/20260916192805.3991983-1-memxor@gmail.com
* Record helper and kfunc outputs after type resolution. (Eduard, Amery)
* Derive generic memory access from flags for helpers and kfuncs. (Eduard)
* Fix MEM_WRITE read checks separately and add permission tests. (Eduard)
* Remove the output-count validator in the multiple-output extension.
(Amery)
* Clarify argument-slot naming and move its accessor into the fix. (BPF CI)
* Add the unaligned header and order the new test registrations. (BPF CI)
* Shorten the kfunc fix description while retaining its rationale. (BPF CI)
v2 -> v3
v2: https://lore.kernel.org/bpf/20260916160821.3157543-1-memxor@gmail.com
* Reuse check_raw_mode_ok() after kfunc prototype generation, including
struct outputs resolved to generic memory later. (Amery)
* Remove the now-redundant kfunc output-count check in the multiple-output
extension and simplify the helper validator.
* Leave the stack-passed output uninitialized so the reduced-capability
test detects missing __uninit handling. (Sashiko)
v1 -> v2
v1: https://lore.kernel.org/bpf/20260915141004.1196460-1-memxor@gmail.com
* Separate the single-output fix and tests from multiple-output support
and its tests; reduce coverage to focused cases. (Eduard)
* Skip inactive output slots before looking up argument register state.
(Sashiko, Amery)
* Separate sysctl restrictions from mitigation-related test skips.
(BPF CI)
* Use an int-width initialization store in the alias test for big-endian
targets. (BPF CI)
* Centralize conversion from argument numbers to slots. (Eduard)
* Share clear access-mode selection between fixed-size and sized arguments.
(Amery)
* Clarify the opt-in prepare/load capability boundary and retain the
reduced-capability alias rejection test. (Eduard)
Eduard Zingerman (3):
bpf: Record raw memory arguments during argument checking
bpf: Check read access for initialized writable memory arguments
selftests/bpf: Cover helper memory access permissions
Kumar Kartikeya Dwivedi (5):
selftests/bpf: Allow privileged preparation for capability tests
bpf: Fix generic __uninit kfunc output buffers
selftests/bpf: Cover generic __uninit output initialization
bpf: Support multiple __uninit kfunc output arguments
selftests/bpf: Cover __uninit kfunc output argument slots
Documentation/bpf/kfuncs.rst | 27 +++-
include/linux/bpf_verifier.h | 11 +-
kernel/bpf/verifier.c | 131 ++++++++++--------
.../selftests/bpf/prog_tests/verifier.c | 4 +
tools/testing/selftests/bpf/progs/bpf_misc.h | 9 +-
.../progs/verifier_helper_access_var_len.c | 41 ++++++
.../bpf/progs/verifier_kfunc_uninit.c | 100 +++++++++++++
.../bpf/progs/verifier_kfunc_uninit_multi.c | 113 +++++++++++++++
.../selftests/bpf/progs/verifier_mtu.c | 75 ++++++++++
.../selftests/bpf/test_kmods/bpf_testmod.c | 45 ++++++
.../bpf/test_kmods/bpf_testmod_kfunc.h | 7 +
tools/testing/selftests/bpf/test_loader.c | 48 +++++--
tools/testing/selftests/bpf/unpriv_helpers.c | 16 ++-
tools/testing/selftests/bpf/unpriv_helpers.h | 2 +
14 files changed, 536 insertions(+), 93 deletions(-)
create mode 100644 tools/testing/selftests/bpf/progs/verifier_kfunc_uninit.c
create mode 100644 tools/testing/selftests/bpf/progs/verifier_kfunc_uninit_multi.c
base-commit: 961b8946acb482b6d7a39c266d623e5f9c4e873f
--
2.53.0
next reply other threads:[~2026-09-18 5:29 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-18 5:28 Kumar Kartikeya Dwivedi [this message]
2026-09-18 5:28 ` [PATCH bpf-next v4 1/8] selftests/bpf: Allow privileged preparation for capability tests Kumar Kartikeya Dwivedi
2026-09-18 5:28 ` [PATCH bpf-next v4 2/8] bpf: Record raw memory arguments during argument checking Kumar Kartikeya Dwivedi
2026-09-18 6:35 ` bot+bpf-ci
2026-09-18 16:24 ` Eduard Zingerman
2026-09-18 5:28 ` [PATCH bpf-next v4 3/8] bpf: Check read access for initialized writable memory arguments Kumar Kartikeya Dwivedi
2026-09-18 5:50 ` sashiko-bot
2026-09-18 17:46 ` Eduard Zingerman
2026-09-18 18:01 ` Amery Hung
2026-09-18 5:28 ` [PATCH bpf-next v4 4/8] selftests/bpf: Cover helper memory access permissions Kumar Kartikeya Dwivedi
2026-09-18 6:17 ` bot+bpf-ci
2026-09-18 5:28 ` [PATCH bpf-next v4 5/8] bpf: Fix generic __uninit kfunc output buffers Kumar Kartikeya Dwivedi
2026-09-18 6:35 ` bot+bpf-ci
2026-09-18 17:50 ` Eduard Zingerman
2026-09-18 5:29 ` [PATCH bpf-next v4 6/8] selftests/bpf: Cover generic __uninit output initialization Kumar Kartikeya Dwivedi
2026-09-18 5:29 ` [PATCH bpf-next v4 7/8] bpf: Support multiple __uninit kfunc output arguments Kumar Kartikeya Dwivedi
2026-09-18 5:29 ` [PATCH bpf-next v4 8/8] selftests/bpf: Cover __uninit kfunc output argument slots Kumar Kartikeya Dwivedi
2026-09-18 6:35 ` bot+bpf-ci
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260918052906.12226-1-memxor@gmail.com \
--to=memxor@gmail.com \
--cc=ameryhung@gmail.com \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=eddyz87@gmail.com \
--cc=emil@etsalapatis.com \
--cc=kernel-team@meta.com \
--cc=kkd@meta.com \
--cc=tj@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox