From: sashiko-bot@kernel.org
To: "Andrey Grodzovsky" <andrey.grodzovsky@crowdstrike.com>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf-next v5 2/8] libbpf: BPF programs manual loading and attaching
Date: Wed, 23 Sep 2026 23:43:44 +0000 [thread overview]
Message-ID: <20260923234344.C66761F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260923232939.1886328-3-andrey.grodzovsky@crowdstrike.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [Low] bpf: missing early validation for MANUAL programs in PROG_ARRAY maps
- [Low] bpf: commit message claims do not match the implemented API names
--
commit ffe6da53cfeec9f1860cfd6d78324b171ee2b1d5
Author: Slava Imameev <slava.imameev@crowdstrike.com>
libbpf: BPF programs manual loading and attaching
This commit introduces manual loading and attaching strategies for BPF
programs, allowing programs to be selectively loaded and unloaded multiple
times without requiring all object programs to be auto-loaded.
> A manual-strategy program is loaded via bpf_program__load_manually()
> and unloaded via bpf_program__unload_manually(), gated on
[Severity: Low]
The commit message mentions bpf_program__load_manually() and
bpf_program__unload_manually(), but the code actually implements
bpf_program__load() and bpf_program__unload(). Should the commit message
be updated to match the implemented API names to fix this regression?
> diff --git a/tools/lib/bpf/libbpf.c b/tools/lib/bpf/libbpf.c
> --- a/tools/lib/bpf/libbpf.c
> +++ b/tools/lib/bpf/libbpf.c
[ ... ]
> @@ -15375,10 +15431,69 @@ void bpf_object__destroy_skeleton(struct bpf_object_skeleton *s)
[ ... ]
> + /*
> + * struct_ops programs are incompatible with manual loading:
> + * bpf_map_prepare_vdata() bakes each member's fd into kern_vdata
> + * automatically during bpf_object__load(), before a MANUAL member
> + * could ever be loaded, and nothing re-bakes it afterwards.
> + */
> + if (prog->type == BPF_PROG_TYPE_STRUCT_OPS)
> + return libbpf_err(-EINVAL);
[Severity: Low]
A check exists here in bpf_program__set_load_strategy() to reject struct_ops,
but does this code miss validation for prog_array maps?
If a user configures a prog_array map to hold a reference to a BPF program
and sets that program's load strategy to manual, the object load will fail
later with -EBADF during the kernel map update when init_prog_array_slots()
calls:
fd = bpf_program__fd(targ_prog);
err = bpf_map_update_elem(map->fd, &i, &fd, 0);
Can this regression occur because the manual program has not been loaded yet,
meaning it will have an invalid file descriptor? Could we add an early
validation here similar to the struct_ops check to prevent this later
failure?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260923232939.1886328-1-andrey.grodzovsky@crowdstrike.com?part=2
next prev parent reply other threads:[~2026-09-23 23:43 UTC|newest]
Thread overview: 27+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-23 23:29 [PATCH bpf-next v5 0/8] libbpf: BPF program manual loading Andrey Grodzovsky
2026-09-23 23:29 ` [PATCH bpf-next v5 1/8] libbpf: BPF program load strategy enum Andrey Grodzovsky
2026-09-24 0:18 ` bot+bpf-ci
2026-09-23 23:29 ` [PATCH bpf-next v5 2/8] libbpf: BPF programs manual loading and attaching Andrey Grodzovsky
2026-09-23 23:43 ` sashiko-bot [this message]
2026-09-24 0:32 ` bot+bpf-ci
2026-09-28 1:40 ` Andrey Grodzovsky
2026-09-30 15:50 ` Andrii Nakryiko
2026-09-24 23:18 ` Andrii Nakryiko
2026-09-26 16:56 ` Andrey Grodzovsky
2026-09-23 23:29 ` [PATCH bpf-next v5 3/8] libbpf: Support declarative manual load via SEC("!...") prefix Andrey Grodzovsky
2026-09-24 23:18 ` Andrii Nakryiko
2026-09-23 23:29 ` [PATCH bpf-next v5 4/8] libbpf: Reject gen_loader for objects with already-manual programs Andrey Grodzovsky
2026-09-24 23:18 ` Andrii Nakryiko
2026-09-26 17:49 ` Andrey Grodzovsky
2026-09-23 23:29 ` [PATCH bpf-next v5 5/8] libbpf: Version bpf_program__set_autoattach() ABI change Andrey Grodzovsky
2026-09-23 23:41 ` sashiko-bot
2026-09-24 0:32 ` bot+bpf-ci
2026-09-24 23:19 ` Andrii Nakryiko
2026-09-26 18:04 ` Andrey Grodzovsky
2026-09-30 15:50 ` Andrii Nakryiko
2026-09-23 23:29 ` [PATCH bpf-next v5 6/8] selftests/bpf: Cover BPF program load strategy transitions Andrey Grodzovsky
2026-09-24 0:18 ` bot+bpf-ci
2026-09-23 23:29 ` [PATCH bpf-next v5 7/8] selftests/bpf: Cover BPF program manual loading Andrey Grodzovsky
2026-09-24 0:32 ` bot+bpf-ci
2026-09-23 23:29 ` [PATCH bpf-next v5 8/8] selftests/bpf: Convert veristat to BPF_PROG_LOAD_STRATEGY_MANUAL Andrey Grodzovsky
2026-09-24 0:32 ` bot+bpf-ci
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260923234344.C66761F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=andrey.grodzovsky@crowdstrike.com \
--cc=bpf@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox