BPF List
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Kumar Kartikeya Dwivedi" <memxor@gmail.com>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf-next v4 3/8] bpf: Check read access for initialized writable memory arguments
Date: Fri, 18 Sep 2026 05:50:37 +0000	[thread overview]
Message-ID: <20260918055038.1D4AE1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260918052906.12226-4-memxor@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Critical] bpf: MEM_WRITE without MEM_UNINIT enforces BPF_READ breaking output helpers
--

commit aebadfb01a3b32540321fe2b60bcb6fb1c8673be
Author: Eduard Zingerman <eddyz87@gmail.com>

bpf: Check read access for initialized writable memory arguments

This commit updates the BPF verifier to derive memory access types based on
argument flags, correctly enforcing read access for writable memory arguments
that are already initialized. The change addresses an issue where helper
argument checking previously omitted read permission checks on map values. It
adds a generic func_arg_access_type() helper to replace the kfunc-specific
access overrides.

> diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
> index 1d5e4ee64fc00..21eb806b1351c 100644
> --- a/kernel/bpf/verifier.c
> +++ b/kernel/bpf/verifier.c
> @@ -8886,6 +8886,15 @@ static int process_map_ptr_arg(struct bpf_verifier_env *env, struct bpf_reg_stat
>  	return 0;
>  }
>  
> +static enum bpf_access_type func_arg_access_type(enum bpf_arg_type arg_type)
> +{
> +	if (!(arg_type & MEM_WRITE))
> +		return BPF_READ;
> +	if (arg_type & MEM_UNINIT)
> +		return BPF_WRITE;
> +	return BPF_READ | BPF_WRITE;
> +}

[Severity: Critical]
Does this regression break pure output helpers that lack the MEM_UNINIT flag?

For example, bpf_snprintf() is defined as an output helper:

kernel/bpf/helpers.c:
const struct bpf_func_proto bpf_snprintf_proto = {
    ...
    .arg1_type  = ARG_PTR_TO_MEM_OR_NULL | MEM_WRITE,
    ...
};

Because bpf_snprintf() does not guarantee full buffer initialization, it
cannot be safely marked with MEM_UNINIT. However, with this change, the lack
of MEM_UNINIT means func_arg_access_type() will return BPF_READ | BPF_WRITE
instead of just BPF_WRITE.

Will this inadvertently force check_helper_mem_access() to reject valid
write-only maps (BPF_F_WRONLY_PROG) when passed to such output helpers, causing
valid BPF programs to fail verification?

Additionally, for unprivileged programs lacking CAP_PERFMON, won't this
erroneously enforce stack buffer pre-initialization by enforcing a read check
requiring stack initialization in check_stack_range_initialized()?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260918052906.12226-1-memxor@gmail.com?part=3

  reply	other threads:[~2026-09-18  5:50 UTC|newest]

Thread overview: 18+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-18  5:28 [PATCH bpf-next v4 0/8] Fix generic __uninit kfunc output buffers Kumar Kartikeya Dwivedi
2026-09-18  5:28 ` [PATCH bpf-next v4 1/8] selftests/bpf: Allow privileged preparation for capability tests Kumar Kartikeya Dwivedi
2026-09-18  5:28 ` [PATCH bpf-next v4 2/8] bpf: Record raw memory arguments during argument checking Kumar Kartikeya Dwivedi
2026-09-18  6:35   ` bot+bpf-ci
2026-09-18 16:24     ` Eduard Zingerman
2026-09-18  5:28 ` [PATCH bpf-next v4 3/8] bpf: Check read access for initialized writable memory arguments Kumar Kartikeya Dwivedi
2026-09-18  5:50   ` sashiko-bot [this message]
2026-09-18 17:46     ` Eduard Zingerman
2026-09-18 18:01     ` Amery Hung
2026-09-18  5:28 ` [PATCH bpf-next v4 4/8] selftests/bpf: Cover helper memory access permissions Kumar Kartikeya Dwivedi
2026-09-18  6:17   ` bot+bpf-ci
2026-09-18  5:28 ` [PATCH bpf-next v4 5/8] bpf: Fix generic __uninit kfunc output buffers Kumar Kartikeya Dwivedi
2026-09-18  6:35   ` bot+bpf-ci
2026-09-18 17:50   ` Eduard Zingerman
2026-09-18  5:29 ` [PATCH bpf-next v4 6/8] selftests/bpf: Cover generic __uninit output initialization Kumar Kartikeya Dwivedi
2026-09-18  5:29 ` [PATCH bpf-next v4 7/8] bpf: Support multiple __uninit kfunc output arguments Kumar Kartikeya Dwivedi
2026-09-18  5:29 ` [PATCH bpf-next v4 8/8] selftests/bpf: Cover __uninit kfunc output argument slots Kumar Kartikeya Dwivedi
2026-09-18  6:35   ` bot+bpf-ci

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260918055038.1D4AE1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=memxor@gmail.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox