BPF List
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Jay Wang" <wanjay@amazon.com>
Cc: bpf@vger.kernel.org, linux-modules@vger.kernel.org
Subject: Re: [PATCH bpf-next v2 3/9] bpf: fetch the vmlinux BTF where kernel types enter a program
Date: Fri, 25 Sep 2026 21:42:41 +0000	[thread overview]
Message-ID: <20260925214242.367201F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260925211314.5118-4-wanjay@amazon.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] bpf: NULL pointer dereference in process_arg_ptr_to_btf_id due to missing ARG_PTR_TO_BTF_ID_SOCK_COMMON
--

commit 84d2361be82e8cb989ae15ca8d3347130aa3ce1b
Author: Jay Wang <wanjay@amazon.com>

bpf: fetch the vmlinux BTF where kernel types enter a program

This commit defers fetching the vmlinux BTF in the BPF verifier until
kernel types are actually needed by a program. This optimization avoids
loading and parsing BTF data for programs that do not use kernel types,
such as simple socket filters.

> diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
> index a7c9e2d8965d5..f02ecb0dae75c 100644
> --- a/kernel/bpf/verifier.c
> +++ b/kernel/bpf/verifier.c
[ ... ]
> @@ -11568,6 +11570,24 @@ static int release_reg(struct bpf_verifier_env *env, struct bpf_reg_state *reg,
>  	return err;
>  }
>  
> +/* Does calling helper @func_id bring kernel BTF types into the program? */
> +static bool helper_uses_vmlinux_btf(enum bpf_func_id func_id,
> +				    const struct bpf_func_proto *fn)
> +{
> +	int i;
> +
> +	/* these take the kernel type id in a struct btf_ptr, not in a register */
> +	if (func_id == BPF_FUNC_snprintf_btf || func_id == BPF_FUNC_seq_printf_btf)
> +		return true;
> +	if (base_type(fn->ret_type) == RET_PTR_TO_BTF_ID)
> +		return true;
> +	for (i = 0; i < MAX_BPF_FUNC_ARGS; i++) {
> +		if (base_type(fn->arg_type[i]) == ARG_PTR_TO_BTF_ID)
> +			return true;

[Severity: High]
Does this logic also need to check for ARG_PTR_TO_BTF_ID_SOCK_COMMON?

If ARG_PTR_TO_BTF_ID_SOCK_COMMON is omitted here, helpers like
bpf_sk_release() that accept this argument type will skip loading
btf_vmlinux.

If a program synthesizes a PTR_TO_BTF_ID pointing to a module's BTF using
ldimm64, btf_vmlinux could remain NULL. Later, in check_func_args(),
arg_btf is assigned from btf_vmlinux:

check_func_args() {
    ...
    case ARG_PTR_TO_BTF_ID:
    case ARG_PTR_TO_BTF_ID_SOCK_COMMON:
    {
        const u32 *arg_btf_id = fn->arg_btf_id[arg];
        const struct btf *arg_btf = meta->btf ?: btf_vmlinux;
    ...
}

Because btf_vmlinux is NULL, arg_btf becomes NULL. Could this lead to a
NULL pointer dereference when process_arg_ptr_to_btf_id() unconditionally
dereferences it?

process_arg_ptr_to_btf_id() {
    ...
    arg_t = btf_type_skip_modifiers(arg_btf, arg_btf_id, &arg_btf_id);
    ...
}

> +	}
> +	return false;
> +}
> +

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260925211314.5118-1-wanjay@amazon.com?part=3

  reply	other threads:[~2026-09-25 21:42 UTC|newest]

Thread overview: 16+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-25 21:13 [PATCH bpf-next v2 0/9] bpf: make the vmlinux BTF an on-demand loadable module (CONFIG_DEBUG_INFO_BTF=m) to save ~5.4 MB memory Jay Wang
2026-09-25 21:13 ` [PATCH bpf-next v2 1/9] bpf: pass the vmlinux BTF to btf_parse_module() and let it adopt the data Jay Wang
2026-09-25 21:13 ` [PATCH bpf-next v2 2/9] bpf: split the kfunc, dtor kfunc and struct_ops registration bodies Jay Wang
2026-09-25 21:13 ` [PATCH bpf-next v2 3/9] bpf: fetch the vmlinux BTF where kernel types enter a program Jay Wang
2026-09-25 21:42   ` sashiko-bot [this message]
2026-09-25 23:02     ` Jay Wang
2026-09-25 21:13 ` [PATCH bpf-next v2 4/9] bpf: take the vmlinux BTF from the btf_vmlinux module Jay Wang
2026-09-25 21:13 ` [PATCH bpf-next v2 5/9] bpf: defer vmlinux kfunc and struct_ops registrations Jay Wang
2026-09-25 21:13 ` [PATCH bpf-next v2 6/9] bpf: keep module BTF until the vmlinux BTF is available Jay Wang
2026-09-25 21:29   ` sashiko-bot
2026-09-25 23:02     ` Jay Wang
2026-09-25 21:13 ` [PATCH bpf-next v2 7/9] bpf: expose deferred .BTF.base module BTF in sysfs from module load Jay Wang
2026-09-25 21:13 ` [PATCH bpf-next v2 8/9] bpf, trace, net: prepare CONFIG_DEBUG_INFO_BTF checks for a tristate Jay Wang
2026-09-25 21:13 ` [PATCH bpf-next v2 9/9] kbuild, bpf: allow building the vmlinux BTF as a module Jay Wang
2026-09-25 21:33   ` sashiko-bot
2026-09-25 23:02     ` Jay Wang

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260925214242.367201F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=linux-modules@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=wanjay@amazon.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox