From: Amery Hung <ameryhung@gmail.com>
To: bpf@vger.kernel.org
Cc: alexei.starovoitov@gmail.com, andrii@kernel.org,
daniel@iogearbox.net, eddyz87@gmail.com, memxor@gmail.com,
ameryhung@gmail.com, kernel-team@meta.com
Subject: [PATCH bpf-next v3 09/11] bpf: Check global subprog BTF-ID arguments in the common path
Date: Mon, 28 Sep 2026 11:53:32 -0700 [thread overview]
Message-ID: <20260928185334.1004200-10-ameryhung@gmail.com> (raw)
In-Reply-To: <20260928185334.1004200-1-ameryhung@gmail.com>
Route global ARG_PTR_TO_BTF_ID arguments through check_func_arg(). Use
vmlinux BTF for their type match and retain the global-subprogram rules
instead of applying kfunc-only trusted-pointer validation or runtime type
resolution.
The common nullability check now rejects non-nullable global BTF-ID
arguments before register-type matching. Update the corresponding
verifier log expectations.
Signed-off-by: Amery Hung <ameryhung@gmail.com>
---
kernel/bpf/verifier.c | 31 +++++--------------
.../bpf/progs/verifier_global_ptr_args.c | 4 +--
2 files changed, 10 insertions(+), 25 deletions(-)
diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
index 0d554e95fdb5..8aa1336453a4 100644
--- a/kernel/bpf/verifier.c
+++ b/kernel/bpf/verifier.c
@@ -9501,7 +9501,7 @@ static int check_func_arg(struct bpf_verifier_env *env, u32 arg, u32 slot, u32 p
case ARG_PTR_TO_BTF_ID_SOCK_COMMON:
{
const u32 *arg_btf_id = fn->arg_btf_id[arg];
- const struct btf *arg_btf = meta->btf ?: btf_vmlinux;
+ const struct btf *arg_btf = is_kfunc(meta) ? meta->btf : btf_vmlinux;
if (!meta->btf) {
const struct bpf_reg_types *compatible;
@@ -9529,8 +9529,8 @@ static int check_func_arg(struct bpf_verifier_env *env, u32 arg, u32 slot, u32 p
}
}
- if (meta->btf && (!is_trusted_reg(env, reg) ||
- bpf_type_has_unsafe_modifiers(reg->type))) {
+ if (is_kfunc(meta) && (!is_trusted_reg(env, reg) ||
+ bpf_type_has_unsafe_modifiers(reg->type))) {
if (!(arg_type & MEM_RCU)) {
const char *actual_type, *arg_name, *expected_type;
@@ -10806,6 +10806,8 @@ static void gen_subprog_arg_proto(const struct bpf_subprog_info *sub, const stru
arg_type = ARG_IGNORE;
} else if (base_type(arg_type) == ARG_PTR_TO_ARENA) {
arg_type |= PTR_MAYBE_NULL;
+ } else if (base_type(arg_type) == ARG_PTR_TO_BTF_ID) {
+ proto->arg_btf_id[arg] = &sub->args[slot].btf_id;
}
proto->arg_type[arg] = arg_type;
t = btf_type_skip_modifiers(btf, args[arg].type, NULL);
@@ -10872,7 +10874,8 @@ static int btf_check_func_arg_match(struct bpf_verifier_env *env, int subprog,
if (arg_type == ARG_SCALAR || arg_type == ARG_IGNORE ||
arg_type == ARG_PTR_TO_CTX || arg_type == ARG_PTR_TO_DYNPTR ||
- base_type(arg_type) == ARG_PTR_TO_ARENA) {
+ base_type(arg_type) == ARG_PTR_TO_ARENA ||
+ base_type(arg_type) == ARG_PTR_TO_BTF_ID) {
ret = check_func_arg(env, arg, slot, 0, &meta, env->insn_idx);
if (ret)
return ret;
@@ -10900,24 +10903,6 @@ static int btf_check_func_arg_match(struct bpf_verifier_env *env, int subprog,
reg_arg_name(env, argno));
return -EINVAL;
}
- } else if (base_type(arg_type) == ARG_PTR_TO_BTF_ID) {
- int err;
-
- if (bpf_register_is_null(reg) && type_may_be_null(arg_type)) {
- err = mark_arg_precision(env, argno);
- if (err)
- return err;
- continue;
- }
-
- err = check_reg_type(env, reg, argno, arg_type, &meta);
- err = err ?: check_func_arg_reg_off(env, reg, argno, arg_type);
- if (!err && base_type(reg->type) == PTR_TO_BTF_ID)
- err = process_arg_ptr_to_btf_id(env, reg, argno, arg_type,
- btf_vmlinux, sub->args[slot].btf_id,
- &meta, env->insn_idx);
- if (err)
- return err;
} else {
verifier_bug(env, "unrecognized %s type %d",
reg_arg_name(env, argno), arg_type);
@@ -13063,7 +13048,7 @@ static int resolve_func_arg_type(struct bpf_verifier_env *env,
if (base_type(*arg_type) != ARG_PTR_TO_BTF_ID)
return 0;
- if (!meta->btf || arg_type_is_release(*arg_type) ||
+ if (!is_kfunc(meta) || arg_type_is_release(*arg_type) ||
base_type(reg->type) == PTR_TO_BTF_ID ||
reg2btf_ids[base_type(reg->type)])
return 0;
diff --git a/tools/testing/selftests/bpf/progs/verifier_global_ptr_args.c b/tools/testing/selftests/bpf/progs/verifier_global_ptr_args.c
index 10019af5eb74..f639e2767e35 100644
--- a/tools/testing/selftests/bpf/progs/verifier_global_ptr_args.c
+++ b/tools/testing/selftests/bpf/progs/verifier_global_ptr_args.c
@@ -87,7 +87,7 @@ __weak int subprog_trusted_task_nonnull(struct task_struct *task __arg_trusted)
SEC("?kprobe")
__failure __log_level(2)
-__msg("R1 type=scalar expected=ptr_, trusted_ptr_, rcu_ptr_")
+__msg("Possibly NULL pointer passed to trusted R1")
__msg("Caller passes invalid args into func#1 ('subprog_trusted_task_nonnull')")
int trusted_task_arg_nonnull_fail1(void *ctx)
{
@@ -96,7 +96,7 @@ int trusted_task_arg_nonnull_fail1(void *ctx)
SEC("?tp_btf/task_newtask")
__failure __log_level(2)
-__msg("R1 type=trusted_ptr_or_null_ expected=ptr_, trusted_ptr_, rcu_ptr_")
+__msg("Possibly NULL pointer passed to trusted R1")
__msg("Caller passes invalid args into func#1 ('subprog_trusted_task_nonnull')")
int trusted_task_arg_nonnull_fail2(void *ctx)
{
--
2.52.0
next prev parent reply other threads:[~2026-09-28 18:53 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 18:53 [PATCH bpf-next v3 00/11] Unify subprog argument checks Amery Hung
2026-09-28 18:53 ` [PATCH bpf-next v3 01/11] bpf: Fix kfunc BTF parameter lookups after wide arguments Amery Hung
2026-09-28 18:53 ` [PATCH bpf-next v3 02/11] bpf: Identify subprog calls in argument metadata Amery Hung
2026-09-28 18:53 ` [PATCH bpf-next v3 03/11] bpf: Build argument prototypes for subprog calls Amery Hung
2026-09-28 18:53 ` [PATCH bpf-next v3 04/11] bpf: Check subprog scalar arguments in the common path Amery Hung
2026-09-28 18:53 ` [PATCH bpf-next v3 05/11] bpf: Check global subprog untrusted " Amery Hung
2026-09-28 18:53 ` [PATCH bpf-next v3 06/11] bpf: Check subprog context " Amery Hung
2026-09-28 18:53 ` [PATCH bpf-next v3 07/11] bpf: Check subprog arena " Amery Hung
2026-09-28 18:53 ` [PATCH bpf-next v3 08/11] bpf: Check subprog dynptr " Amery Hung
2026-09-28 18:53 ` Amery Hung [this message]
2026-09-28 18:53 ` [PATCH bpf-next v3 10/11] bpf: Check global subprog memory " Amery Hung
2026-09-28 19:53 ` bot+bpf-ci
2026-09-28 18:53 ` [PATCH bpf-next v3 11/11] bpf: Check all subprog " Amery Hung
2026-09-29 10:40 ` [PATCH bpf-next v3 00/11] Unify subprog argument checks patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260928185334.1004200-10-ameryhung@gmail.com \
--to=ameryhung@gmail.com \
--cc=alexei.starovoitov@gmail.com \
--cc=andrii@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=eddyz87@gmail.com \
--cc=kernel-team@meta.com \
--cc=memxor@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox