BPF List
 help / color / mirror / Atom feed
* [PATCH v2 bpf-next 0/3] BTF inline functionality followups
@ 2026-09-25 17:08 Alan Maguire
  2026-09-25 17:08 ` [PATCH v2 bpf-next 1/3] bpf: Verify BTF_KIND_LOC_PARAM vlen, flags Alan Maguire
                   ` (2 more replies)
  0 siblings, 3 replies; 7+ messages in thread
From: Alan Maguire @ 2026-09-25 17:08 UTC (permalink / raw)
  To: ast, andrii, eddyz87, qmo
  Cc: jolsa, daniel, ihor.solodrai, yonghong.song, song, martin.lau,
	memxor, emil, bpf, nsc, puranjay, yatsenko, Alan Maguire

Include additional vlen/flags verification for BTF_KIND_LOC_PARAM
(patch 1), and add function signatures to LOCSEC entries (patch 2),
adjusting test to cover these (patch 3).

Changes since v1 [1]

- Fixed sign to appear after const (bots, patch 2)
- Simplified loc printing to remove vsnprintf() logic, updated
  to retain name in json (Quentin, patch 2)
- For oversized signature strings, append "..." (Quentin, patch 2)

[1] https://lore.kernel.org/bpf/20260925095231.879708-1-alan.maguire@oracle.com/

Alan Maguire (3):
  bpf: Verify BTF_KIND_LOC_PARAM vlen, flags
  bpftool: Update func representation to include function signature
  selftests/bpf: Fix up bpftool btf dump test for signatures

 kernel/bpf/btf.c                              |  12 ++
 tools/bpf/bpftool/btf.c                       | 118 ++++++++++++++++--
 .../bpf/prog_tests/bpftool_btf_dump.c         |  14 ++-
 3 files changed, 129 insertions(+), 15 deletions(-)

-- 
2.43.5


^ permalink raw reply	[flat|nested] 7+ messages in thread

* [PATCH v2 bpf-next 1/3] bpf: Verify BTF_KIND_LOC_PARAM vlen, flags
  2026-09-25 17:08 [PATCH v2 bpf-next 0/3] BTF inline functionality followups Alan Maguire
@ 2026-09-25 17:08 ` Alan Maguire
  2026-09-25 20:35   ` Alexei Starovoitov
  2026-09-25 17:08 ` [PATCH v2 bpf-next 2/3] bpftool: Update func representation to include function signature Alan Maguire
  2026-09-25 17:08 ` [PATCH v2 bpf-next 3/3] selftests/bpf: Fix up bpftool btf dump test for signatures Alan Maguire
  2 siblings, 1 reply; 7+ messages in thread
From: Alan Maguire @ 2026-09-25 17:08 UTC (permalink / raw)
  To: ast, andrii, eddyz87, qmo
  Cc: jolsa, daniel, ihor.solodrai, yonghong.song, song, martin.lau,
	memxor, emil, bpf, nsc, puranjay, yatsenko, Alan Maguire

Ensure that vlen is at least 1, at most 8 for LOC_PARAMs
and ensure that flags are a combination of expected values.

Fixes: 33c5a3278bdb ("btf: Extend UAPI to support BTF location (inline site) info")
Suggested-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Alan Maguire <alan.maguire@oracle.com>
---
 kernel/bpf/btf.c | 12 ++++++++++++
 1 file changed, 12 insertions(+)

diff --git a/kernel/bpf/btf.c b/kernel/bpf/btf.c
index 9bcfefdfb734..c4a811a3a650 100644
--- a/kernel/bpf/btf.c
+++ b/kernel/bpf/btf.c
@@ -4823,6 +4823,18 @@ static s32 btf_loc_param_check_meta(struct btf_verifier_env *env,
 		btf_verifier_log_type(env, t, "Invalid btf_info kind_flag");
 		return -EINVAL;
 	}
+	/* All LOC_PARAMs have vlen of at least 1, none have vlen > 8 */
+	if (vlen < 1 || vlen > 8) {
+		btf_verifier_log_type(env, t, "Invalid vlen");
+		return -EINVAL;
+	}
+	if (p->flags & ~(BTF_LOC_PARAM_SIGNED | BTF_LOC_PARAM_CONST |
+			 BTF_LOC_PARAM_ADDR | BTF_LOC_PARAM_REG |
+			 BTF_LOC_PARAM_DEREF | BTF_LOC_PARAM_OFFSET) ||
+	    !p->flags) {
+		btf_verifier_log_type(env, t, "Invalid flags");
+		return -EINVAL;
+	}
 
 	btf_verifier_log_type(env, t, NULL);
 
-- 
2.43.5


^ permalink raw reply related	[flat|nested] 7+ messages in thread

* [PATCH v2 bpf-next 2/3] bpftool: Update func representation to include function signature
  2026-09-25 17:08 [PATCH v2 bpf-next 0/3] BTF inline functionality followups Alan Maguire
  2026-09-25 17:08 ` [PATCH v2 bpf-next 1/3] bpf: Verify BTF_KIND_LOC_PARAM vlen, flags Alan Maguire
@ 2026-09-25 17:08 ` Alan Maguire
  2026-09-25 17:17   ` sashiko-bot
  2026-09-25 17:08 ` [PATCH v2 bpf-next 3/3] selftests/bpf: Fix up bpftool btf dump test for signatures Alan Maguire
  2 siblings, 1 reply; 7+ messages in thread
From: Alan Maguire @ 2026-09-25 17:08 UTC (permalink / raw)
  To: ast, andrii, eddyz87, qmo
  Cc: jolsa, daniel, ihor.solodrai, yonghong.song, song, martin.lau,
	memxor, emil, bpf, nsc, puranjay, yatsenko, Alan Maguire

Augment func= output for LOCSEC entries to include a mapping from
function signature to where parameters are stored; for example:

[290179] LOCSEC 'inline.text' vlen=524941
        func='task_pid_nr(tsk [reg0])' func_type_id=136691 loc_proto_type_id=136693 offset=2097226
        func='get_current()' func_type_id=136694 loc_proto_type_id=136695 offset=2097247
        func='arch_static_branch(key [address 0x2e275e8], branch [const 0x0])' func_type_id=136697 loc_proto_type_id=136700 offset=2097296

Fixes: 321562c34d5b ("bpftool: Add ability to dump LOC_PARAM, LOC_PROTO and LOCSEC")
Suggested-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Alan Maguire <alan.maguire@oracle.com>
---
 tools/bpf/bpftool/btf.c | 118 +++++++++++++++++++++++++++++++++++++---
 1 file changed, 109 insertions(+), 9 deletions(-)

diff --git a/tools/bpf/bpftool/btf.c b/tools/bpf/bpftool/btf.c
index e29c8a84e224..ce4c4036c279 100644
--- a/tools/bpf/bpftool/btf.c
+++ b/tools/bpf/bpftool/btf.c
@@ -150,6 +150,7 @@ static void btf_loc_param_raw_str(const struct btf_loc_param *p, __u32 vlen,
 
 static void btf_loc_param_str(const struct btf_type *t, char *str, size_t sz)
 {
+	const char *op = "", *prefix = "";
 	const struct btf_loc_param *p;
 	__u32 i = 0, vlen;
 	__u64 value;
@@ -157,7 +158,6 @@ static void btf_loc_param_str(const struct btf_type *t, char *str, size_t sz)
 	bool negative = false;
 	char regs[32] = {};
 	char num[32] = {};
-	const char *op = "";
 
 	if (!t || !btf_is_loc_param(t)) {
 		snprintf(str, sz, "<invalid>");
@@ -234,8 +234,12 @@ static void btf_loc_param_str(const struct btf_type *t, char *str, size_t sz)
 						(1ULL << bits) - value;
 			}
 		}
-		snprintf(num, sizeof(num), "0x%llx%s", (unsigned long long)value,
-			 p->flags & BTF_LOC_PARAM_ADDR ? " (addr)" : "");
+		if (p->flags & BTF_LOC_PARAM_ADDR)
+			prefix = "address ";
+		else if (p->flags & BTF_LOC_PARAM_CONST)
+			prefix = "const ";
+		snprintf(num, sizeof(num), "0x%llx",
+			 (unsigned long long)value);
 	}
 	if (i != vlen) {
 		btf_loc_param_raw_str(p, vlen, str, sz);
@@ -244,14 +248,106 @@ static void btf_loc_param_str(const struct btf_type *t, char *str, size_t sz)
 	if (num[0])
 		op = regs[0] ? (negative ? " - " : " + ") : negative ? "-" : "";
 
-	snprintf(str, sz, "%s%s%s%s%s",
+	snprintf(str, sz, "%s%s%s%s%s%s",
 		 p->flags & BTF_LOC_PARAM_DEREF ? "*(" : "",
+		 prefix,
 		 regs,
 		 op,
 		 num,
 		 p->flags & BTF_LOC_PARAM_DEREF ? ")" : "");
 }
 
+static bool btf_locsec_append(char *str, size_t sz, size_t *off,
+			      const char *suffix)
+{
+	size_t len;
+
+	if (!sz || *off >= sz)
+		return false;
+
+	len = strlen(suffix);
+	if (len < sz - *off) {
+		memcpy(str + *off, suffix, len + 1);
+		*off += len;
+		return true;
+	}
+
+	if (sz >= 4) {
+		memcpy(str + sz - 4, "...", 4);
+	} else if (sz > 1) {
+		memset(str, '.', sz - 1);
+		str[sz - 1] = '\0';
+	}
+	*off = sz - 1;
+	return false;
+}
+
+static void btf_locsec_func_str(const struct btf *btf,
+				const struct btf_loc *loc, char *str, size_t sz)
+{
+	const struct btf_type *func, *func_proto, *loc_proto;
+	const struct btf_param *params;
+	const __u32 *loc_params;
+	const char *name;
+	__u32 i, vlen;
+	size_t off = 0;
+
+	if (!sz)
+		return;
+
+	str[0] = '\0';
+	func = btf__type_by_id(btf, loc->func);
+	if (!func || !btf_is_func(func))
+		goto invalid;
+
+	name = btf_str(btf, func->name_off);
+	func_proto = btf__type_by_id(btf, func->type);
+	loc_proto = btf__type_by_id(btf, loc->loc_proto);
+	if (!func_proto || !btf_is_func_proto(func_proto) ||
+	    !loc_proto || !btf_is_loc_proto(loc_proto) ||
+	    btf_vlen(func_proto) != btf_vlen(loc_proto))
+		goto invalid;
+
+	params = (const void *)(func_proto + 1);
+	loc_params = btf_loc_proto_params(loc_proto);
+	vlen = btf_vlen(func_proto);
+	if (!btf_locsec_append(str, sz, &off, name) ||
+	    !btf_locsec_append(str, sz, &off, "("))
+		return;
+	for (i = 0; i < vlen; i++) {
+		const struct btf_type *param_loc;
+		char param_str[256] = {};
+
+		if (!params[i].type) {
+			/* Handle varargs func proto, must be last parameter */
+			if (i != vlen - 1)
+				goto invalid;
+			if (!btf_locsec_append(str, sz, &off, i ? ", " : "") ||
+			    !btf_locsec_append(str, sz, &off, "..."))
+				return;
+			break;
+		} else if (loc_params[i]) {
+			param_loc = btf__type_by_id(btf, loc_params[i]);
+			btf_loc_param_str(param_loc, param_str, sizeof(param_str));
+		} else {
+			snprintf(param_str, sizeof(param_str), "<unavailable>");
+		}
+
+		if (!btf_locsec_append(str, sz, &off, i ? ", " : "") ||
+		    !btf_locsec_append(str, sz, &off,
+				       btf_str(btf, params[i].name_off)) ||
+		    !btf_locsec_append(str, sz, &off, " [") ||
+		    !btf_locsec_append(str, sz, &off, param_str) ||
+		    !btf_locsec_append(str, sz, &off, "]"))
+			return;
+	}
+	(void) btf_locsec_append(str, sz, &off, ")");
+	return;
+
+invalid:
+	snprintf(str, sz, "<invalid>");
+}
+
 static int dump_btf_type(const struct btf *btf, __u32 id,
 			 const struct btf_type *t)
 {
@@ -617,22 +713,26 @@ static int dump_btf_type(const struct btf *btf, __u32 id,
 		}
 
 		for (i = 0; i < vlen; i++, locs++) {
-			const struct btf_type *f = btf__type_by_id(btf, locs->func);
+			const struct btf_type *func;
 			const char *name = "<invalid>";
+			char func_str[1024] = {};
 
-			if (f && btf_is_func(f))
-				name = btf_str(btf, f->name_off);
+			func = btf__type_by_id(btf, locs->func);
+			if (func && btf_is_func(func))
+				name = btf_str(btf, func->name_off);
+			btf_locsec_func_str(btf, locs, func_str, sizeof(func_str));
 
 			if (json_output) {
 				jsonw_start_object(w);
 				jsonw_uint_field(w, "func_type_id", locs->func);
 				jsonw_string_field(w, "name", name);
+				jsonw_string_field(w, "func", func_str);
 				jsonw_uint_field(w, "loc_proto_type_id", locs->loc_proto);
 				jsonw_uint_field(w, "offset", locs->offset);
 				jsonw_end_object(w);
 			} else {
-				printf("\n\tname='%s' func_type_id=%u loc_proto_type_id=%u offset=%u",
-				       name, locs->func, locs->loc_proto, locs->offset);
+				printf("\n\tfunc='%s' func_type_id=%u loc_proto_type_id=%u offset=%u",
+				       func_str, locs->func, locs->loc_proto, locs->offset);
 			}
 		}
 		if (json_output)
-- 
2.43.5


^ permalink raw reply related	[flat|nested] 7+ messages in thread

* [PATCH v2 bpf-next 3/3] selftests/bpf: Fix up bpftool btf dump test for signatures
  2026-09-25 17:08 [PATCH v2 bpf-next 0/3] BTF inline functionality followups Alan Maguire
  2026-09-25 17:08 ` [PATCH v2 bpf-next 1/3] bpf: Verify BTF_KIND_LOC_PARAM vlen, flags Alan Maguire
  2026-09-25 17:08 ` [PATCH v2 bpf-next 2/3] bpftool: Update func representation to include function signature Alan Maguire
@ 2026-09-25 17:08 ` Alan Maguire
  2 siblings, 0 replies; 7+ messages in thread
From: Alan Maguire @ 2026-09-25 17:08 UTC (permalink / raw)
  To: ast, andrii, eddyz87, qmo
  Cc: jolsa, daniel, ihor.solodrai, yonghong.song, song, martin.lau,
	memxor, emil, bpf, nsc, puranjay, yatsenko, Alan Maguire

Now we show a function signature, fix up the test to expect it.
Also fix the fact that we did not add the right number of parameters
to the FUNC_PROTO, and ensure consts/addresses are prefixed
appropriately.

Fixes: 321562c34d5b ("bpftool: Add ability to dump LOC_PARAM, LOC_PROTO and LOCSEC")
Signed-off-by: Alan Maguire <alan.maguire@oracle.com>
---
 .../selftests/bpf/prog_tests/bpftool_btf_dump.c    | 14 ++++++++------
 1 file changed, 8 insertions(+), 6 deletions(-)

diff --git a/tools/testing/selftests/bpf/prog_tests/bpftool_btf_dump.c b/tools/testing/selftests/bpf/prog_tests/bpftool_btf_dump.c
index bed506badc75..abc62958b6ed 100644
--- a/tools/testing/selftests/bpf/prog_tests/bpftool_btf_dump.c
+++ b/tools/testing/selftests/bpf/prog_tests/bpftool_btf_dump.c
@@ -72,6 +72,7 @@ static struct btf *mk_loc_btf(void)
 	btf__add_func_param(btf, "arg3", 1);
 	btf__add_func_param(btf, "arg4", 1);
 	btf__add_func_param(btf, "arg5", 1);
+	btf__add_func_param(btf, "arg6", 1);
 	btf__add_func(btf, "foo", BTF_FUNC_STATIC, 2);
 
 	btf__add_loc_param(btf, 4, BTF_LOC_PARAM_REG);
@@ -230,28 +231,29 @@ static void test_loc_dump(const char *btf_path)
 {
 	const char expected[] =
 		"[1] INT 'int' size=4 bits_offset=0 nr_bits=32 encoding=SIGNED\n"
-		"[2] FUNC_PROTO '(anon)' ret_type_id=1 vlen=5\n"
+		"[2] FUNC_PROTO '(anon)' ret_type_id=1 vlen=6\n"
 		"\t'arg1' type_id=1\n"
 		"\t'arg2' type_id=1\n"
 		"\t'arg3' type_id=1\n"
 		"\t'arg4' type_id=1\n"
 		"\t'arg5' type_id=1\n"
+		"\t'arg6' type_id=1\n"
 		"[3] FUNC 'foo' type_id=2 linkage=static\n"
 		"[4] LOC_PARAM '(anon)' size=4 flags=0x8 vlen=1 values='reg1'\n"
 		"[5] LOC_PARAM '(anon)' size=8 flags=0x38 vlen=2 values='*(reg2 + 0x10)'\n"
 		"[6] LOC_PARAM '(anon)' size=8 flags=0x29 vlen=2 values='fbreg - 0x10'\n"
-		"[7] LOC_PARAM '(anon)' size=8 flags=0x6 vlen=2 values='0x123456789abcdef0 (addr)'\n"
-		"[8] LOC_PARAM '(anon)' size=8 flags=0x2 vlen=2 values='0xdeadbeeffeedface'\n"
+		"[7] LOC_PARAM '(anon)' size=8 flags=0x6 vlen=2 values='address 0x123456789abcdef0'\n"
+		"[8] LOC_PARAM '(anon)' size=8 flags=0x2 vlen=2 values='const 0xdeadbeeffeedface'\n"
 		"[9] LOC_PARAM '(anon)' size=8 flags=0x39 vlen=2 values='*(fbreg - 0x20)'\n"
 		"[10] LOC_PROTO '(anon)' vlen=6\n"
 		"\ttype_id=4 value='reg1'\n"
 		"\ttype_id=5 value='*(reg2 + 0x10)'\n"
 		"\ttype_id=6 value='fbreg - 0x10'\n"
-		"\ttype_id=7 value='0x123456789abcdef0 (addr)'\n"
-		"\ttype_id=8 value='0xdeadbeeffeedface'\n"
+		"\ttype_id=7 value='address 0x123456789abcdef0'\n"
+		"\ttype_id=8 value='const 0xdeadbeeffeedface'\n"
 		"\ttype_id=9 value='*(fbreg - 0x20)'\n"
 		"[11] LOCSEC 'inline.text' vlen=1\n"
-		"\tname='foo' func_type_id=3 loc_proto_type_id=10 offset=64\n";
+		"\tfunc='foo(arg1 [reg1], arg2 [*(reg2 + 0x10)], arg3 [fbreg - 0x10], arg4 [address 0x123456789abcdef0], arg5 [const 0xdeadbeeffeedface], arg6 [*(fbreg - 0x20)])' func_type_id=3 loc_proto_type_id=10 offset=64\n";
 	char *dump;
 
 	dump = dump_raw(btf_path);
-- 
2.43.5


^ permalink raw reply related	[flat|nested] 7+ messages in thread

* Re: [PATCH v2 bpf-next 2/3] bpftool: Update func representation to include function signature
  2026-09-25 17:08 ` [PATCH v2 bpf-next 2/3] bpftool: Update func representation to include function signature Alan Maguire
@ 2026-09-25 17:17   ` sashiko-bot
  2026-09-25 19:55     ` Quentin Monnet
  0 siblings, 1 reply; 7+ messages in thread
From: sashiko-bot @ 2026-09-25 17:17 UTC (permalink / raw)
  To: Alan Maguire; +Cc: bpf

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] bpf: btf_locsec_append hides truncation marker due to null byte gap
--

commit 6f503008243b4dfc886859b905f8a6fa7b657ef2
Author: Alan Maguire <alan.maguire@oracle.com>

bpftool: Update func representation to include function signature

This commit augments the func= output for LOCSEC entries to include a mapping
from function signature to where parameters are stored. It addresses a feature
suggestion to dump LOC_PARAM, LOC_PROTO and LOCSEC more verbosely.

> diff --git a/tools/bpf/bpftool/btf.c b/tools/bpf/bpftool/btf.c
> index e29c8a84e224c..ce4c4036c2796 100644
> --- a/tools/bpf/bpftool/btf.c
> +++ b/tools/bpf/bpftool/btf.c

[ ... ]

> +static bool btf_locsec_append(char *str, size_t sz, size_t *off,
> +			      const char *suffix)
> +{
> +	size_t len;
> +
> +	if (!sz || *off >= sz)
> +		return false;
> +
> +	len = strlen(suffix);
> +	if (len < sz - *off) {
> +		memcpy(str + *off, suffix, len + 1);
> +		*off += len;
> +		return true;
> +	}
> +
> +	if (sz >= 4) {
> +		memcpy(str + sz - 4, "...", 4);
> +	} else if (sz > 1) {

[Severity: Medium]
When a string exceeds the buffer size and we hit this fallback path in
btf_locsec_append(), is there a risk that the truncation marker is hidden?

The truncation marker ... is unconditionally placed at the very end of the
buffer (sz - 4). Because the function fails to copy the prefix of the string
that would fit and does not write over the existing null terminator at *off,
a gap of null bytes can separate the current end of the string from the
truncation marker.

String reading functions like printf or JSON dumpers will terminate at the
first null byte, which would completely hide the ... marker and discard the
partial data.

This would be triggered when bpftool formats a BTF location string (for 
example, a function signature with many parameters) that cumulatively exceeds
1024 characters.

> +		memset(str, '.', sz - 1);
> +		str[sz - 1] = '\0';
> +	}
> +	*off = sz - 1;
> +	return false;
> +}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260925170854.1240637-1-alan.maguire@oracle.com?part=2

^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: [PATCH v2 bpf-next 2/3] bpftool: Update func representation to include function signature
  2026-09-25 17:17   ` sashiko-bot
@ 2026-09-25 19:55     ` Quentin Monnet
  0 siblings, 0 replies; 7+ messages in thread
From: Quentin Monnet @ 2026-09-25 19:55 UTC (permalink / raw)
  To: sashiko-reviews, Alan Maguire; +Cc: bpf

2026-09-25 17:17 UTC+0000 ~ sashiko-bot@kernel.org
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [Medium] bpf: btf_locsec_append hides truncation marker due to null byte gap
> --
> 
> commit 6f503008243b4dfc886859b905f8a6fa7b657ef2
> Author: Alan Maguire <alan.maguire@oracle.com>
> 
> bpftool: Update func representation to include function signature
> 
> This commit augments the func= output for LOCSEC entries to include a mapping
> from function signature to where parameters are stored. It addresses a feature
> suggestion to dump LOC_PARAM, LOC_PROTO and LOCSEC more verbosely.
> 
>> diff --git a/tools/bpf/bpftool/btf.c b/tools/bpf/bpftool/btf.c
>> index e29c8a84e224c..ce4c4036c2796 100644
>> --- a/tools/bpf/bpftool/btf.c
>> +++ b/tools/bpf/bpftool/btf.c
> 
> [ ... ]
> 
>> +static bool btf_locsec_append(char *str, size_t sz, size_t *off,
>> +			      const char *suffix)
>> +{
>> +	size_t len;
>> +
>> +	if (!sz || *off >= sz)
>> +		return false;
>> +
>> +	len = strlen(suffix);
>> +	if (len < sz - *off) {
>> +		memcpy(str + *off, suffix, len + 1);
>> +		*off += len;
>> +		return true;
>> +	}
>> +
>> +	if (sz >= 4) {
>> +		memcpy(str + sz - 4, "...", 4);
>> +	} else if (sz > 1) {
> 
> [Severity: Medium]
> When a string exceeds the buffer size and we hit this fallback path in
> btf_locsec_append(), is there a risk that the truncation marker is hidden?
> 
> The truncation marker ... is unconditionally placed at the very end of the
> buffer (sz - 4). Because the function fails to copy the prefix of the string
> that would fit and does not write over the existing null terminator at *off,
> a gap of null bytes can separate the current end of the string from the
> truncation marker.
> 
> String reading functions like printf or JSON dumpers will terminate at the
> first null byte, which would completely hide the ... marker and discard the
> partial data.
> 
> This would be triggered when bpftool formats a BTF location string (for 
> example, a function signature with many parameters) that cumulatively exceeds
> 1024 characters.

Maybe copy whatever we can from the suffix first, overwrite the end with
the dots after? Something like:

        if (sz >= 4) {
                size_t space_left = sz - 1 - *off;

                if (space_left)
                        memcpy(str + *off, suffix, space_left);
                memcpy(str + sz - 4, "...", 4);
        }

^ permalink raw reply	[flat|nested] 7+ messages in thread

* Re: [PATCH v2 bpf-next 1/3] bpf: Verify BTF_KIND_LOC_PARAM vlen, flags
  2026-09-25 17:08 ` [PATCH v2 bpf-next 1/3] bpf: Verify BTF_KIND_LOC_PARAM vlen, flags Alan Maguire
@ 2026-09-25 20:35   ` Alexei Starovoitov
  0 siblings, 0 replies; 7+ messages in thread
From: Alexei Starovoitov @ 2026-09-25 20:35 UTC (permalink / raw)
  To: Alan Maguire, andrii, eddyz87, qmo
  Cc: jolsa, daniel, ihor.solodrai, yonghong.song, song, martin.lau,
	memxor, emil, bpf, nsc, puranjay, yatsenko

On Fri, Sep 25, 2026 at 06:08 PM Alan Maguire <alan.maguire@oracle.com> wrote:
> +	/* All LOC_PARAMs have vlen of at least 1, none have vlen > 8 */
> +	if (vlen < 1 || vlen > 8) {
> +		btf_verifier_log_type(env, t, "Invalid vlen");
> +		return -EINVAL;
> +	}

Why 8? seems arbitrary.

> +	if (p->flags & ~(BTF_LOC_PARAM_SIGNED | BTF_LOC_PARAM_CONST |
> +			 BTF_LOC_PARAM_ADDR | BTF_LOC_PARAM_REG |
> +			 BTF_LOC_PARAM_DEREF | BTF_LOC_PARAM_OFFSET) ||
> +	    !p->flags) {
> +		btf_verifier_log_type(env, t, "Invalid flags");
> +		return -EINVAL;
> +	}

CONST | REG and DEREF without REG are still accepted it seems.


^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2026-09-25 20:35 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-25 17:08 [PATCH v2 bpf-next 0/3] BTF inline functionality followups Alan Maguire
2026-09-25 17:08 ` [PATCH v2 bpf-next 1/3] bpf: Verify BTF_KIND_LOC_PARAM vlen, flags Alan Maguire
2026-09-25 20:35   ` Alexei Starovoitov
2026-09-25 17:08 ` [PATCH v2 bpf-next 2/3] bpftool: Update func representation to include function signature Alan Maguire
2026-09-25 17:17   ` sashiko-bot
2026-09-25 19:55     ` Quentin Monnet
2026-09-25 17:08 ` [PATCH v2 bpf-next 3/3] selftests/bpf: Fix up bpftool btf dump test for signatures Alan Maguire

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox