From: sashiko-bot@kernel.org
To: "Jay Wang" <wanjay@amazon.com>
Cc: ojeda@kernel.org, linux-modules@vger.kernel.org,
gary@garyguo.net, bpf@vger.kernel.org
Subject: Re: [PATCH bpf-next v3 6/9] bpf: keep module BTF until the vmlinux BTF is available
Date: Fri, 25 Sep 2026 22:59:15 +0000 [thread overview]
Message-ID: <20260925225915.76BCC1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260925224229.1850-7-wanjay@amazon.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Low] bpf: memory leak of module BTF data on parse failure for .BTF.base modules
--
commit 10719f6f8154699a27d9151dc131b89e1ea34139
Author: Jay Wang <wanjay@amazon.com>
bpf: keep module BTF until the vmlinux BTF is available
Module BTF is split BTF against the vmlinux BTF and is parsed in the
module notifier. With CONFIG_DEBUG_INFO_BTF=m the vmlinux BTF may not be
loaded yet when a module loads, and the notifier cannot load btf_vmlinux
(that would nest a module load in a module load).
> diff --git a/kernel/bpf/btf.c b/kernel/bpf/btf.c
> index 207954b5754a7..1dae1c9b53fed 100644
> --- a/kernel/bpf/btf.c
> +++ b/kernel/bpf/btf.c
[ ... ]
> @@ -9309,6 +9414,101 @@ static int __init btf_module_init(void)
> }
>
> fs_initcall(btf_module_init);
> +
> +#if IS_MODULE(CONFIG_DEBUG_INFO_BTF)
> +/*
> + * A kept module whose BTF cannot be used after all. The module is loaded
> + * and stays, so there is no way to reject it: the entry stays on the list,
> + * dead, until the module goes. A sysfs file it has keeps serving the raw
> + * data, which is kept for that.
> + */
> +static void btf_module_dead(struct btf_module *btf_mod, const char *what, int err)
> +{
> + pr_warn("failed to %s module [%s] BTF: %d\n", what, btf_mod->module->name, err);
> + kvfree(btf_mod->base_data);
> + btf_mod->base_data = NULL;
> + btf_free_deferred_regs(&btf_mod->deferred_regs);
> + btf_mod->gone = true;
> +}
[Severity: Low]
Does this code leak btf_mod->data when parsing fails for modules with a
.BTF.base section?
If a module with a .BTF.base section is loaded before the vmlinux BTF, and its
deferred BTF parsing subsequently fails when the vmlinux BTF is loaded, the
memory btf_mod->data is retained because btf_module_dead() assumes the sysfs
file will continue to serve the raw data.
However, for .BTF.base modules, the sysfs file uses
btf_module_sysfs_read_deferred(), which returns -ENODEV when the module is
marked as gone. As a result, the memory is inaccessible and uselessly retained
until the module is unloaded.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260925224229.1850-1-wanjay@amazon.com?part=6
next prev parent reply other threads:[~2026-09-25 22:59 UTC|newest]
Thread overview: 29+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-25 22:42 [PATCH bpf-next v3 0/9] bpf: make the vmlinux BTF an on-demand loadable module (CONFIG_DEBUG_INFO_BTF=m) to save ~5.4 MB memory Jay Wang
2026-09-25 22:42 ` [PATCH bpf-next v3 1/9] bpf: pass the vmlinux BTF to btf_parse_module() and let it adopt the data Jay Wang
2026-09-25 22:42 ` [PATCH bpf-next v3 2/9] bpf: split the kfunc, dtor kfunc and struct_ops registration bodies Jay Wang
2026-09-25 22:42 ` [PATCH bpf-next v3 3/9] bpf: fetch the vmlinux BTF where kernel types enter a program Jay Wang
2026-09-25 23:10 ` sashiko-bot
2026-10-01 23:51 ` Jay Wang
2026-09-25 22:42 ` [PATCH bpf-next v3 4/9] bpf: take the vmlinux BTF from the btf_vmlinux module Jay Wang
2026-09-25 23:23 ` bot+bpf-ci
2026-10-01 23:51 ` Jay Wang
2026-09-26 8:29 ` Alexei Starovoitov
2026-10-01 23:51 ` Jay Wang
2026-09-25 22:42 ` [PATCH bpf-next v3 5/9] bpf: defer vmlinux kfunc and struct_ops registrations Jay Wang
2026-09-25 23:34 ` bot+bpf-ci
2026-10-01 23:52 ` Jay Wang
2026-09-25 22:42 ` [PATCH bpf-next v3 6/9] bpf: keep module BTF until the vmlinux BTF is available Jay Wang
2026-09-25 22:59 ` sashiko-bot [this message]
2026-10-01 23:52 ` Jay Wang
2026-09-25 22:42 ` [PATCH bpf-next v3 7/9] bpf: expose deferred .BTF.base module BTF in sysfs from module load Jay Wang
2026-09-25 23:23 ` bot+bpf-ci
2026-10-01 23:52 ` Jay Wang
2026-09-25 22:42 ` [PATCH bpf-next v3 8/9] bpf, trace, net: prepare CONFIG_DEBUG_INFO_BTF checks for a tristate Jay Wang
2026-09-25 23:23 ` bot+bpf-ci
2026-10-01 23:53 ` Jay Wang
2026-09-25 22:42 ` [PATCH bpf-next v3 9/9] kbuild, bpf: allow building the vmlinux BTF as a module Jay Wang
2026-09-25 23:34 ` bot+bpf-ci
2026-10-01 23:53 ` Jay Wang
2026-09-28 10:00 ` Alan Maguire
[not found] ` <DM6PR18MB2666F6B235D5B356AA157A7DA98D2@DM6PR18MB2666.namprd18.prod.outlook.com>
2026-09-29 18:25 ` Alan Maguire
2026-10-01 23:53 ` Jay Wang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260925225915.76BCC1F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=gary@garyguo.net \
--cc=linux-modules@vger.kernel.org \
--cc=ojeda@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=wanjay@amazon.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox