BPF List
 help / color / mirror / Atom feed
From: Kumar Kartikeya Dwivedi <memxor@gmail.com>
To: bpf@vger.kernel.org
Cc: Alexei Starovoitov <ast@kernel.org>,
	Andrii Nakryiko <andrii@kernel.org>,
	Daniel Borkmann <daniel@iogearbox.net>,
	Eduard Zingerman <eddyz87@gmail.com>,
	Emil Tsalapatis <emil@etsalapatis.com>,
	kkd@meta.com, kernel-team@meta.com
Subject: [PATCH bpf-next v1 0/3] Fix fastcall rewrite with indirect stack accesses
Date: Wed, 23 Sep 2026 10:41:55 +0200	[thread overview]
Message-ID: <20260923084201.2437625-1-memxor@gmail.com> (raw)

When a bpf_fastcall call is inlined, the verifier removes the spill/fill
pairs around it and shrinks the stack frame to exclude their slots. Two
kinds of stack access skip the check that must disable this rewrite, so
the program can then access kernel stack outside its frame.

Patch 1 checks helper and kfunc stack buffers, which BPF CI reported
after commit 5da4a9f26fca ("bpf: Preserve stack initialization for
generic output buffers"). Patch 2 makes a callee's load from its
caller's stack check the caller's frame. Patch 3 adds tests.

Kumar Kartikeya Dwivedi (3):
  bpf: Check fastcall contract for helper and kfunc stack buffers
  bpf: Check fastcall contract of the frame a stack read targets
  selftests/bpf: Test fastcall rewrite with indirect stack accesses

 kernel/bpf/verifier.c                         |  10 +-
 .../bpf/progs/verifier_bpf_fastcall.c         | 161 ++++++++++++++++++
 2 files changed, 169 insertions(+), 2 deletions(-)


base-commit: 91f8613d95ad8cd99d8baf094806d1ef98bc6380
-- 
2.53.0


             reply	other threads:[~2026-09-23  8:42 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-23  8:41 Kumar Kartikeya Dwivedi [this message]
2026-09-23  8:41 ` [PATCH bpf-next v1 1/3] bpf: Check fastcall contract for helper and kfunc stack buffers Kumar Kartikeya Dwivedi
2026-09-24  5:55   ` Alexei Starovoitov
2026-09-23  8:41 ` [PATCH bpf-next v1 2/3] bpf: Check fastcall contract of the frame a stack read targets Kumar Kartikeya Dwivedi
2026-09-23  8:41 ` [PATCH bpf-next v1 3/3] selftests/bpf: Test fastcall rewrite with indirect stack accesses Kumar Kartikeya Dwivedi
2026-09-23  9:33   ` bot+bpf-ci

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260923084201.2437625-1-memxor@gmail.com \
    --to=memxor@gmail.com \
    --cc=andrii@kernel.org \
    --cc=ast@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=daniel@iogearbox.net \
    --cc=eddyz87@gmail.com \
    --cc=emil@etsalapatis.com \
    --cc=kernel-team@meta.com \
    --cc=kkd@meta.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox