BPF List
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Yonghong Song" <yonghong.song@linux.dev>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf-next v4 07/20] bpf: Refuse exception cleanup shapes bpf_throw() cannot dispatch
Date: Mon, 21 Sep 2026 21:20:57 +0000	[thread overview]
Message-ID: <20260921212057.D23021F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260921210109.1719713-1-yonghong.song@linux.dev>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] bpf: kernel stack leak via >5 arg BPF-to-BPF calls in exception pads
--

commit 961251cb485953d7f6bd99ead3712d0e8268b8eb
Author: Yonghong Song <yonghong.song@linux.dev>

bpf: Refuse exception cleanup shapes bpf_throw() cannot dispatch

This commit adds verification logic to reject specific control flow shapes 
that bpf_throw() and the exception cleanup handling cannot safely dispatch. 
It performs post-CFG checks using bpf_check_cleanup_exceptions() to inspect 
pad reachability, catch pads, and unwinding safety.

> diff --git a/kernel/bpf/exception.c b/kernel/bpf/exception.c
> index 67af78baa558d..da8fa6eb7e4b9 100644
> --- a/kernel/bpf/exception.c
> +++ b/kernel/bpf/exception.c

[ ... ]

> +static int cleanup_check_pad_insn(struct bpf_verifier_env *env, u32 i)
> +{
> +	struct bpf_insn *insn = &env->prog->insnsi[i];
> +
> +	if (bpf_helper_call(insn) && insn->imm == BPF_FUNC_tail_call) {
> +		verbose(env,
> +			"bpf_tail_call() at insn %u is in an exception cleanup landing pad\n",
> +			i);
> +		return -EINVAL;
> +	}
> +	/* A BPF_LD_[ABS|IND] can leave the frame through its epilogue. */
> +	if (BPF_CLASS(insn->code) == BPF_LD &&
> +	    (BPF_MODE(insn->code) == BPF_ABS || BPF_MODE(insn->code) == BPF_IND)) {
> +		verbose(env,
> +			"BPF_LD_[ABS|IND] at insn %u is in an exception cleanup landing pad\n",
> +			i);
> +		return -EINVAL;
> +	}
> +	if (is_stack_arg_st(insn) || is_stack_arg_stx(insn)) {
> +		verbose(env,
> +			"insn %u passes an on-stack call argument in an exception cleanup landing pad\n",
> +			i);
> +		return -EINVAL;
> +	}
> +	if (bpf_pseudo_kfunc_call(insn)) {
> +		struct bpf_call_summary cs;
> +
> +		if (bpf_get_call_summary(env, insn, &cs) &&
> +		    cs.arg_slot_cnt > MAX_BPF_FUNC_REG_ARGS) {

[Severity: High]
Does this omit checking BPF-to-BPF calls (bpf_pseudo_call) for on-stack
arguments?

The JIT executes exception cleanup landing pads on the unwinder's stack (rsp),
while rbp points to the BPF frame. This check restricts kfuncs from passing
arguments on the stack, but seems to miss BPF subprograms because
bpf_get_call_summary() returns false for them.

If a pad calls a BPF subprogram requiring more than 5 arguments, could the
callee read uninitialized kernel stack memory belonging to the unwinder's
caller?

> +			verbose(env,
> +				"insn %u passes an on-stack call argument in an exception cleanup landing pad\n",
> +				i);
> +			return -EINVAL;
> +		}
> +	}
> +	return 0;
> +}

[ ... ]

> +static int cleanup_mark_pad_bodies(struct cleanup_ctx *ctx)
> +{
> +	struct bpf_verifier_env *env = ctx->env;
> +	u32 i, sp = 0;
> +	int ret;

[ ... ]

> +	while (sp) {
> +		u32 j = ctx->stack[--sp];
> +		enum cleanup_insn_kind kind;
> +		int next, target, sub;
> +		u32 start, end;
> +
> +		ret = cleanup_check_pad_insn(env, j);
> +		if (ret)
> +			return ret;
> +
> +		sub = cleanup_subprog_of(env, j);
> +		start = env->subprog_info[sub].start;
> +		end = env->subprog_info[sub + 1].start;
> +		kind = cleanup_succ(env, j, start, end, &next, &target);
> +
> +		if (kind == CLEANUP_INSN_CALL) {
> +			/* check_subprogs() registered every call target. */
> +			int callee = cleanup_subprog_of(env, j + env->prog->insnsi[j].imm + 1);
> +
> +			if (env->subprog_info[callee].might_throw) {

[Severity: High]
Since cleanup_mark_pad_bodies() allows BPF-to-BPF calls in landing pads as
long as they don't throw, should it also verify that the callee does not
take on-stack arguments?

For example, by checking if env->subprog_info[callee].arg_slot_cnt <=
MAX_BPF_FUNC_REG_ARGS?

Without this check, a subprogram requiring more than 5 arguments could be
called, potentially leading to the kernel stack data leak mentioned above.

> +				verbose(env,
> +					"cleanup landing pad calls subprog %d at insn %u, which can throw while an exception is in flight\n",
> +					callee, j);
> +				return -EINVAL;
> +			}
> +		}

[ ... ]

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260921210033.1715000-1-yonghong.song@linux.dev?part=7

  reply	other threads:[~2026-09-21 21:20 UTC|newest]

Thread overview: 80+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-21 21:00 [PATCH bpf-next v4 00/20] bpf: Run exception cleanup landing pads when bpf_throw() unwinds Yonghong Song
2026-09-21 21:00 ` [PATCH bpf-next v4 01/20] bpf: Accept the compiler's exception cleanup table at program load Yonghong Song
2026-09-21 21:56   ` bot+bpf-ci
2026-09-22  3:27     ` Yonghong Song
2026-09-21 21:00 ` [PATCH bpf-next v4 02/20] bpf: Add the bpf_unwind_resume() kfunc Yonghong Song
2026-09-21 21:56   ` bot+bpf-ci
2026-09-22  3:31     ` Yonghong Song
2026-09-21 21:00 ` [PATCH bpf-next v4 03/20] bpf: Add lookups for exception cleanup resumes and landing pads Yonghong Song
2026-09-22  4:04   ` Alexei Starovoitov
2026-09-22  5:28     ` Yonghong Song
2026-09-21 21:00 ` [PATCH bpf-next v4 04/20] bpf: Prepare for an exception cleanup table before the CFG walk Yonghong Song
2026-09-22 18:27   ` Eduard Zingerman
2026-09-23  3:07     ` Yonghong Song
2026-09-23  3:54       ` Eduard Zingerman
2026-09-23  4:05         ` Yonghong Song
2026-09-21 21:00 ` [PATCH bpf-next v4 05/20] bpf: Make exception landing pads reachable in the CFG Yonghong Song
2026-09-21 21:01 ` [PATCH bpf-next v4 06/20] bpf: Explore the landing pads no call site reaches Yonghong Song
2026-09-21 23:58   ` Eduard Zingerman
2026-09-22  3:32     ` Yonghong Song
2026-09-22  4:10       ` Eduard Zingerman
2026-09-21 21:01 ` [PATCH bpf-next v4 07/20] bpf: Refuse exception cleanup shapes bpf_throw() cannot dispatch Yonghong Song
2026-09-21 21:20   ` sashiko-bot [this message]
2026-09-22  3:39     ` Yonghong Song
2026-09-21 21:56   ` bot+bpf-ci
2026-09-22  3:44     ` Yonghong Song
2026-09-22  0:30   ` Eduard Zingerman
2026-09-22  3:45     ` Yonghong Song
2026-09-22 21:43       ` Eduard Zingerman
2026-09-23  3:11         ` Yonghong Song
2026-09-21 21:01 ` [PATCH bpf-next v4 08/20] bpf: Walk the exception unwind in the verifier Yonghong Song
2026-09-21 21:40   ` sashiko-bot
2026-09-22  4:17     ` Yonghong Song
2026-09-21 21:56   ` bot+bpf-ci
2026-09-22  5:21     ` Yonghong Song
2026-09-22  4:08   ` Alexei Starovoitov
2026-09-22  5:25     ` Yonghong Song
2026-09-22 21:53       ` Eduard Zingerman
2026-09-23  3:18         ` Yonghong Song
2026-09-22 23:43   ` Eduard Zingerman
2026-09-23  3:21     ` Yonghong Song
2026-09-21 21:01 ` [PATCH bpf-next v4 09/20] bpf: Refuse a private stack for a program with an exception cleanup table Yonghong Song
2026-09-21 21:01 ` [PATCH bpf-next v4 10/20] bpf: Dispatch exception cleanup pads from bpf_throw() Yonghong Song
2026-09-22 21:38   ` Eduard Zingerman
2026-09-23  3:22     ` Yonghong Song
2026-09-21 21:01 ` [PATCH bpf-next v4 11/20] bpf, x86: Dispatch exception cleanup pads at run time Yonghong Song
2026-09-21 21:01 ` [PATCH bpf-next v4 12/20] bpf, arm64: " Yonghong Song
2026-09-21 21:01 ` [PATCH bpf-next v4 13/20] libbpf: Resolve the compiler's _Unwind_Resume to the kernel's kfunc Yonghong Song
2026-09-21 21:13   ` sashiko-bot
2026-09-21 21:01 ` [PATCH bpf-next v4 14/20] libbpf: Add cleanup_info to bpf_prog_load_opts Yonghong Song
2026-09-21 21:01 ` [PATCH bpf-next v4 15/20] libbpf: Collect .bpf_cleanup records and pass them to the kernel Yonghong Song
2026-09-21 21:20   ` sashiko-bot
2026-09-21 21:01 ` [PATCH bpf-next v4 16/20] libbpf: Carry the exception cleanup table through the light skeleton Yonghong Song
2026-09-21 21:02 ` [PATCH bpf-next v4 17/20] libbpf: Let the static linker carry .bpf_cleanup relocations Yonghong Song
2026-09-21 21:02 ` [PATCH bpf-next v4 18/20] selftests/bpf: Add an end-to-end .bpf_cleanup exception test Yonghong Song
2026-09-21 21:22   ` sashiko-bot
2026-09-22  5:26     ` Yonghong Song
2026-09-21 21:56   ` bot+bpf-ci
2026-09-21 21:02 ` [PATCH bpf-next v4 19/20] selftests/bpf: Cover the exception cleanup shapes the chain does not reach Yonghong Song
2026-09-21 21:19   ` sashiko-bot
2026-09-21 21:02 ` [PATCH bpf-next v4 20/20] selftests/bpf: Load an exception cleanup program from a light skeleton Yonghong Song
2026-09-22  1:08 ` [PATCH bpf-next v4 00/20] bpf: Run exception cleanup landing pads when bpf_throw() unwinds Eduard Zingerman
2026-09-22  2:16   ` Alexei Starovoitov
2026-09-22  2:31     ` Kumar Kartikeya Dwivedi
2026-09-22 21:44       ` Alexei Starovoitov
2026-09-23  4:36         ` Kumar Kartikeya Dwivedi
2026-09-23  4:54           ` Alexei Starovoitov
2026-09-23  5:20             ` Kumar Kartikeya Dwivedi
2026-09-23  6:16             ` Eduard Zingerman
2026-09-23  6:44               ` Kumar Kartikeya Dwivedi
2026-09-22  4:27     ` Eduard Zingerman
2026-09-22 21:47       ` Alexei Starovoitov
2026-09-22 23:08         ` Eduard Zingerman
2026-09-22 23:37           ` Alexei Starovoitov
2026-09-23  0:04             ` Eduard Zingerman
2026-09-23 19:04               ` Eduard Zingerman
2026-09-23 19:24                 ` Andrii Nakryiko
2026-09-23 19:34                   ` Kumar Kartikeya Dwivedi
2026-09-23 21:34                     ` Alexei Starovoitov
2026-09-23 22:00                       ` Eduard Zingerman
2026-09-23 23:22                         ` Alexei Starovoitov

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260921212057.D23021F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=yonghong.song@linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox