BPF List
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Jay Wang" <wanjay@amazon.com>
Cc: bpf@vger.kernel.org, linux-modules@vger.kernel.org
Subject: Re: [PATCH bpf-next v2 6/9] bpf: keep module BTF until the vmlinux BTF is available
Date: Fri, 25 Sep 2026 21:29:37 +0000	[thread overview]
Message-ID: <20260925212938.3B4D91F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260925211314.5118-7-wanjay@amazon.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] bpf: Use-After-Free in MODULE_STATE_LIVE notifier due to lockless module memory access
--

commit 93f5bd60bb80b8878d6319aa725f17dde3127d2c
Author: Jay Wang <wanjay@amazon.com>

bpf: keep module BTF until the vmlinux BTF is available

This commit delays the parsing and registration of module BTF until the
vmlinux BTF is available when the kernel is built with
CONFIG_DEBUG_INFO_BTF=m. It keeps a copy of the module's BTF data and
processes deferred kfunc, dtor, and struct_ops registrations once the
vmlinux BTF arrives.

> diff --git a/kernel/bpf/btf.c b/kernel/bpf/btf.c
> index aa3fdc98034bd..39d75e8890601 100644
> --- a/kernel/bpf/btf.c
> +++ b/kernel/bpf/btf.c

[ ... ]

> @@ -8918,6 +9002,26 @@ static int btf_module_notify(struct notifier_block *nb, unsigned long op,
>  				continue;
>  
>  			btf_mod->flags |= BTF_MODULE_F_LIVE;
> +			if (IS_MODULE(CONFIG_DEBUG_INFO_BTF) && btf_mod->btf &&
> +			    !list_empty(&btf_mod->deferred_regs)) {
> +				/*
> +				 * The vmlinux BTF arrived while this module was
> +				 * initializing: btf_parse_deferred_modules()
> +				 * parsed its BTF but left the registrations its
> +				 * init queued to us, now that init is done and
> +				 * the module is not going anywhere.  Applying
> +				 * them walks btf_modules, so drop the mutex.
> +				 */
> +				LIST_HEAD(regs);
> +
> +				btf = btf_mod->btf;
> +				btf_get(btf);
> +				list_splice_init(&btf_mod->deferred_regs, &regs);
> +				mutex_unlock(&btf_module_mutex);
> +				btf_apply_deferred_regs(btf, &regs);
> +				btf_put(btf);
> +				goto out;

[Severity: High]
Is it possible for a concurrent module unload to free the module memory
while btf_apply_deferred_regs() is still running here?

The MODULE_STATE_LIVE notifier drops btf_module_mutex to call
btf_apply_deferred_regs(), which processes deferred_regs that point to the
module's memory (such as reg->kfunc.kset). However, it doesn't appear to
acquire a module reference via try_module_get() before dropping the lock.

Because the initial module reference count is dropped to 0 by
do_init_module() before calling the MODULE_STATE_LIVE notifiers, could a
concurrent sys_delete_module() successfully unmap the module memory,
leading to a use-after-free when btf_apply_deferred_regs() dereferences
those pointers?

> +			}
>  			break;
>  		}
>  		mutex_unlock(&btf_module_mutex);

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260925211314.5118-1-wanjay@amazon.com?part=6

  reply	other threads:[~2026-09-25 21:29 UTC|newest]

Thread overview: 16+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-25 21:13 [PATCH bpf-next v2 0/9] bpf: make the vmlinux BTF an on-demand loadable module (CONFIG_DEBUG_INFO_BTF=m) to save ~5.4 MB memory Jay Wang
2026-09-25 21:13 ` [PATCH bpf-next v2 1/9] bpf: pass the vmlinux BTF to btf_parse_module() and let it adopt the data Jay Wang
2026-09-25 21:13 ` [PATCH bpf-next v2 2/9] bpf: split the kfunc, dtor kfunc and struct_ops registration bodies Jay Wang
2026-09-25 21:13 ` [PATCH bpf-next v2 3/9] bpf: fetch the vmlinux BTF where kernel types enter a program Jay Wang
2026-09-25 21:42   ` sashiko-bot
2026-09-25 23:02     ` Jay Wang
2026-09-25 21:13 ` [PATCH bpf-next v2 4/9] bpf: take the vmlinux BTF from the btf_vmlinux module Jay Wang
2026-09-25 21:13 ` [PATCH bpf-next v2 5/9] bpf: defer vmlinux kfunc and struct_ops registrations Jay Wang
2026-09-25 21:13 ` [PATCH bpf-next v2 6/9] bpf: keep module BTF until the vmlinux BTF is available Jay Wang
2026-09-25 21:29   ` sashiko-bot [this message]
2026-09-25 23:02     ` Jay Wang
2026-09-25 21:13 ` [PATCH bpf-next v2 7/9] bpf: expose deferred .BTF.base module BTF in sysfs from module load Jay Wang
2026-09-25 21:13 ` [PATCH bpf-next v2 8/9] bpf, trace, net: prepare CONFIG_DEBUG_INFO_BTF checks for a tristate Jay Wang
2026-09-25 21:13 ` [PATCH bpf-next v2 9/9] kbuild, bpf: allow building the vmlinux BTF as a module Jay Wang
2026-09-25 21:33   ` sashiko-bot
2026-09-25 23:02     ` Jay Wang

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260925212938.3B4D91F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=linux-modules@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=wanjay@amazon.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox