BPF List
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Ömer Mete Kaya" <omermetekaya0@gmail.com>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf] bpf: Zero-fill non-target CPU slots on BPF_F_CPU insert of new per-CPU element
Date: Mon, 28 Sep 2026 22:03:39 +0000	[thread overview]
Message-ID: <20260928220340.168F31F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260928214932.544124-1-omermetekaya0@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Low] bpf: unreachable dead code added in pcpu_init_value()
--

commit aa9c1147874e7681c03a2eaf750ae6f2bf2a633a
Author: Ömer Mete Kaya <omermetekaya0@gmail.com>

bpf: Zero-fill non-target CPU slots on BPF_F_CPU insert of new per-CPU element

pcpu_copy_value() with BPF_F_CPU copies the value only to the target
CPU's slot and returns immediately, leaving all other CPUs untouched.
When inserting a *new* element, the backing per-CPU area may be reused
from bpf_mem_cache or a prealloc freelist without being zero-initialized,
so non-target CPUs retain stale contents of a previously-deleted
element in the same map — a same-map information disclosure.

> diff --git a/kernel/bpf/hashtab.c b/kernel/bpf/hashtab.c
> index 548eb1cc7c45c..f426d4c00bdc8 100644
> --- a/kernel/bpf/hashtab.c
> +++ b/kernel/bpf/hashtab.c
> @@ -1086,6 +1086,16 @@ static void pcpu_init_value(struct bpf_htab *htab, void __percpu *pptr,
>  		}
>  	} else {
>  		pcpu_copy_value(htab, pptr, value, onallcpus, map_flags);
> +		if (map_flags & BPF_F_CPU) {

[Severity: Low]
Is this block reachable?

Since the preceding if statement in pcpu_init_value() evaluates
"if (!onallcpus || (map_flags & BPF_F_CPU))", the else branch will only
execute if "(map_flags & BPF_F_CPU)" evaluates to false.

This makes the newly added code here unreachable. Furthermore, the new
element initialization issue mentioned in the commit message appears to
already be handled correctly in the first branch, which already zeroes out
non-target CPUs via zero_map_value().

> +			int target = map_flags >> 32;
> +			int cpu;
> +
> +			for_each_possible_cpu(cpu) {
> +				if (cpu != target)
> +					zero_map_value(&htab->map,
> +						       per_cpu_ptr(pptr, cpu));
> +			}
> +		}
>  	}
>  }

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260928214932.544124-1-omermetekaya0@gmail.com?part=1

  reply	other threads:[~2026-09-28 22:03 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-28 21:47 [PATCH bpf] bpf: Zero-fill non-target CPU slots on BPF_F_CPU insert of new per-CPU element Ömer Mete Kaya
2026-09-28 22:03 ` sashiko-bot [this message]
2026-09-29  5:04 ` Leon Hwang
2026-09-29  7:58   ` Ömer Mete Kaya

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260928220340.168F31F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=omermetekaya0@gmail.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox