BPF List
 help / color / mirror / Atom feed
* [PATCH bpf-next v5 00/11] Fix generic __uninit kfunc output buffers
@ 2026-09-21  2:38 Kumar Kartikeya Dwivedi
  2026-09-21  2:38 ` [PATCH bpf-next v5 01/11] selftests/bpf: Allow privileged preparation for capability tests Kumar Kartikeya Dwivedi
                   ` (11 more replies)
  0 siblings, 12 replies; 17+ messages in thread
From: Kumar Kartikeya Dwivedi @ 2026-09-21  2:38 UTC (permalink / raw)
  To: bpf
  Cc: Alexei Starovoitov, Andrii Nakryiko, Daniel Borkmann,
	Eduard Zingerman, Emil Tsalapatis, Tejun Heo, Amery Hung, kkd,
	kernel-team

Generic __uninit kfunc arguments are output buffers. Stack liveness treats
them as writes, but argument checking still requires readable contents and
does not record definite initialization after the call. Check these
arguments as write-only and record privileged output initialization after
validating all inputs, including inputs that alias an output.

Following Eduard's rework, helpers and kfuncs record generic outputs in the
same argument-checking path after type resolution. Generated kfunc
prototypes now mark generic buffers with MEM_WRITE, so __uninit buffers are
checked as write-only ahead of the fix while ordinary buffers stay
read/write.

The final two patches derive memory access from MEM_WRITE and MEM_UNINIT
alone, so input/output helpers such as bpf_check_mtu() require read as
well as write permission without a new prototype field, and add the
permission tests.

Changelog:
----------
v4 -> v5
v4: https://lore.kernel.org/bpf/20260918052906.12226-1-memxor@gmail.com

 * Check __uninit kfunc outputs as write-only and mark generated kfunc
   buffers MEM_WRITE, replacing the kfunc-specific access override. (Amery)
 * Derive memory access from MEM_WRITE and MEM_UNINIT after relaxing the
   MEM_UNINIT contract, so partial-output helpers keep write-only map
   destinations while input/output helpers gain read checks. (Eduard, Amery,
   Sashiko)
 * Move the helper read-access fix and its permission tests after the
   MEM_UNINIT relaxation, and drop its Fixes tag: it only closes a
   write-only map permission gap for input/output helpers.
 * Reuse the raw-memory predicate after type resolution and clarify how
   argument ordering affects output tracking. (Eduard, BPF CI)
 * Keep prospective struct-output counting separate from raw-memory checks.
 * Clarify the __uninit buffer contract and privilege rules. (BPF CI, Eduard)
 * Add read-only FIB rejection and partial-output write-only map coverage.
   (BPF CI)
 * Carry Eduard's Acked-by on the generic __uninit fix.
 * Allow partial initialization for all generic MEM_UNINIT buffers and
   annotate partial-output helpers with MEM_UNINIT. (Eduard)
 * Preserve per-byte initialization and prior stack liveness for generic
   outputs when uninitialized stack reads are not allowed. (Eduard)
 * Retain output classification when variable sizes disable raw mode.
 * Cover stricter readback rules for full-writing helpers and kfuncs.
 * Retain helper-argument fallback coverage using map_update_elem inputs.

v3 -> v4
v3: https://lore.kernel.org/bpf/20260916192805.3991983-1-memxor@gmail.com

 * Record helper and kfunc outputs after type resolution. (Eduard, Amery)
 * Derive generic memory access from flags for helpers and kfuncs. (Eduard)
 * Fix MEM_WRITE read checks separately and add permission tests. (Eduard)
 * Remove the output-count validator in the multiple-output extension.
   (Amery)
 * Clarify argument-slot naming and move its accessor into the fix. (BPF CI)
 * Add the unaligned header and order the new test registrations. (BPF CI)
 * Shorten the kfunc fix description while retaining its rationale. (BPF CI)

v2 -> v3
v2: https://lore.kernel.org/bpf/20260916160821.3157543-1-memxor@gmail.com

 * Reuse check_raw_mode_ok() after kfunc prototype generation, including
   struct outputs resolved to generic memory later. (Amery)
 * Remove the now-redundant kfunc output-count check in the multiple-output
   extension and simplify the helper validator.
 * Leave the stack-passed output uninitialized so the reduced-capability
   test detects missing __uninit handling. (Sashiko)

v1 -> v2
v1: https://lore.kernel.org/bpf/20260915141004.1196460-1-memxor@gmail.com

 * Separate the single-output fix and tests from multiple-output support
   and its tests; reduce coverage to focused cases. (Eduard)
 * Skip inactive output slots before looking up argument register state.
   (Sashiko, Amery)
 * Separate sysctl restrictions from mitigation-related test skips.
   (BPF CI)
 * Use an int-width initialization store in the alias test for big-endian
   targets. (BPF CI)
 * Centralize conversion from argument numbers to slots. (Eduard)
 * Share clear access-mode selection between fixed-size and sized arguments.
   (Amery)
 * Clarify the opt-in prepare/load capability boundary and retain the
   reduced-capability alias rejection test. (Eduard)


Eduard Zingerman (3):
  bpf: Record raw memory arguments during argument checking
  bpf: Check read access for helper input/output buffers
  selftests/bpf: Cover helper memory access permissions

Kumar Kartikeya Dwivedi (8):
  selftests/bpf: Allow privileged preparation for capability tests
  bpf: Check __uninit kfunc output buffers as write-only
  bpf: Fix generic __uninit kfunc output buffers
  selftests/bpf: Cover generic __uninit output initialization
  bpf: Support multiple __uninit kfunc output arguments
  selftests/bpf: Cover __uninit kfunc output argument slots
  bpf: Preserve stack initialization for generic output buffers
  selftests/bpf: Cover generic output stack initialization

 Documentation/bpf/kfuncs.rst                  |  27 +-
 include/linux/bpf.h                           |   5 +-
 include/linux/bpf_verifier.h                  |  13 +-
 kernel/bpf/cgroup.c                           |   2 +-
 kernel/bpf/helpers.c                          |   2 +-
 kernel/bpf/verifier.c                         | 167 +++++----
 kernel/trace/bpf_trace.c                      |   6 +-
 .../selftests/bpf/prog_tests/verifier.c       |   4 +
 tools/testing/selftests/bpf/progs/bpf_misc.h  |   9 +-
 .../progs/verifier_helper_access_var_len.c    | 332 ++++++++++++++++++
 .../bpf/progs/verifier_kfunc_uninit.c         | 236 +++++++++++++
 .../bpf/progs/verifier_kfunc_uninit_multi.c   | 113 ++++++
 .../selftests/bpf/progs/verifier_live_stack.c |  33 +-
 .../selftests/bpf/progs/verifier_mtu.c        |  88 +++++
 .../selftests/bpf/progs/verifier_raw_stack.c  |   4 +
 .../selftests/bpf/test_kmods/bpf_testmod.c    |  52 +++
 .../bpf/test_kmods/bpf_testmod_kfunc.h        |   8 +
 tools/testing/selftests/bpf/test_loader.c     |  48 ++-
 tools/testing/selftests/bpf/unpriv_helpers.c  |  16 +-
 tools/testing/selftests/bpf/unpriv_helpers.h  |   2 +
 20 files changed, 1046 insertions(+), 121 deletions(-)
 create mode 100644 tools/testing/selftests/bpf/progs/verifier_kfunc_uninit.c
 create mode 100644 tools/testing/selftests/bpf/progs/verifier_kfunc_uninit_multi.c


base-commit: b99f71407ce529ba01a9392f477522d2e76c6613
-- 
2.53.0


^ permalink raw reply	[flat|nested] 17+ messages in thread

end of thread, other threads:[~2026-09-21 17:21 UTC | newest]

Thread overview: 17+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-21  2:38 [PATCH bpf-next v5 00/11] Fix generic __uninit kfunc output buffers Kumar Kartikeya Dwivedi
2026-09-21  2:38 ` [PATCH bpf-next v5 01/11] selftests/bpf: Allow privileged preparation for capability tests Kumar Kartikeya Dwivedi
2026-09-21  2:38 ` [PATCH bpf-next v5 02/11] bpf: Record raw memory arguments during argument checking Kumar Kartikeya Dwivedi
2026-09-21  2:38 ` [PATCH bpf-next v5 03/11] bpf: Check __uninit kfunc output buffers as write-only Kumar Kartikeya Dwivedi
2026-09-21  3:54   ` bot+bpf-ci
2026-09-21  2:38 ` [PATCH bpf-next v5 04/11] bpf: Fix generic __uninit kfunc output buffers Kumar Kartikeya Dwivedi
2026-09-21  2:38 ` [PATCH bpf-next v5 05/11] selftests/bpf: Cover generic __uninit output initialization Kumar Kartikeya Dwivedi
2026-09-21  2:38 ` [PATCH bpf-next v5 06/11] bpf: Support multiple __uninit kfunc output arguments Kumar Kartikeya Dwivedi
2026-09-21  2:38 ` [PATCH bpf-next v5 07/11] selftests/bpf: Cover __uninit kfunc output argument slots Kumar Kartikeya Dwivedi
2026-09-21  2:38 ` [PATCH bpf-next v5 08/11] bpf: Preserve stack initialization for generic output buffers Kumar Kartikeya Dwivedi
2026-09-21  3:54   ` bot+bpf-ci
2026-09-21  2:38 ` [PATCH bpf-next v5 09/11] selftests/bpf: Cover generic output stack initialization Kumar Kartikeya Dwivedi
2026-09-21  3:54   ` bot+bpf-ci
2026-09-21  2:38 ` [PATCH bpf-next v5 10/11] bpf: Check read access for helper input/output buffers Kumar Kartikeya Dwivedi
2026-09-21  2:38 ` [PATCH bpf-next v5 11/11] selftests/bpf: Cover helper memory access permissions Kumar Kartikeya Dwivedi
2026-09-21  3:54   ` bot+bpf-ci
2026-09-21 17:20 ` [PATCH bpf-next v5 00/11] Fix generic __uninit kfunc output buffers patchwork-bot+netdevbpf

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox