From: Kumar Kartikeya Dwivedi <memxor@gmail.com>
To: bpf@vger.kernel.org
Cc: Alexei Starovoitov <ast@kernel.org>,
Andrii Nakryiko <andrii@kernel.org>,
Daniel Borkmann <daniel@iogearbox.net>,
Eduard Zingerman <eddyz87@gmail.com>,
Emil Tsalapatis <emil@etsalapatis.com>,
kkd@meta.com, kernel-team@meta.com
Subject: [PATCH bpf-next v2 0/2] Fix fastcall rewrite with indirect stack accesses
Date: Thu, 24 Sep 2026 09:53:48 +0200 [thread overview]
Message-ID: <20260924075352.2343553-1-memxor@gmail.com> (raw)
When a bpf_fastcall call is inlined, the verifier removes the spill/fill
pairs around it and shrinks the stack frame to exclude their slots. Two
kinds of stack access skip the check that must disable this rewrite, so
the program can then access kernel stack outside its frame: stack
buffers passed to helpers and kfuncs, which BPF CI reported after commit
5da4a9f26fca ("bpf: Preserve stack initialization for generic output
buffers"), and a callee's load from its caller's stack, which checked
the callee's frame instead of the caller's.
Patch 1 moves the check into check_stack_access_within_bounds(), which
every stack access goes through with the frame that owns the slots, and
drops the calls from the stack read and write paths. Patch 2 adds tests.
Changelog:
----------
v1 -> v2
v1: https://lore.kernel.org/bpf/20260923084201.2437625-1-memxor@gmail.com
* Check the contract once in check_stack_access_within_bounds() and drop
the calls in the stack read and write paths, which also fixes the frame
check_stack_read_fixed_off() checked; fold v1 patch 2 into patch 1.
(Alexei)
* Scope the test comment to the output buffer tests and describe the
remaining tests individually. (BPF CI)
Kumar Kartikeya Dwivedi (2):
bpf: Check fastcall stack contract once for all stack accesses
selftests/bpf: Test fastcall rewrite with indirect stack accesses
kernel/bpf/verifier.c | 13 +-
.../bpf/progs/verifier_bpf_fastcall.c | 169 ++++++++++++++++++
2 files changed, 178 insertions(+), 4 deletions(-)
base-commit: 24629aac43d2884109ae47a993fd51b504e2b09b
--
2.53.0
next reply other threads:[~2026-09-24 7:53 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-24 7:53 Kumar Kartikeya Dwivedi [this message]
2026-09-24 7:53 ` [PATCH bpf-next v2 1/2] bpf: Check fastcall stack contract once for all stack accesses Kumar Kartikeya Dwivedi
2026-09-24 7:53 ` [PATCH bpf-next v2 2/2] selftests/bpf: Test fastcall rewrite with indirect " Kumar Kartikeya Dwivedi
2026-09-24 16:40 ` [PATCH bpf-next v2 0/2] Fix " patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260924075352.2343553-1-memxor@gmail.com \
--to=memxor@gmail.com \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=eddyz87@gmail.com \
--cc=emil@etsalapatis.com \
--cc=kernel-team@meta.com \
--cc=kkd@meta.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox