BPF List
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Jakub Kicinski" <kuba@kernel.org>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH net-next 4/5] selftests/bpf: check XDP attach on a nested bond slave
Date: Tue, 29 Sep 2026 22:37:00 +0000	[thread overview]
Message-ID: <20260929223701.197371F00893@smtp.kernel.org> (raw)
In-Reply-To: <20260928223648.2739371-5-kuba@kernel.org>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] selftests/bpf: false-positive test success due to ASSERT_GE(nest2, 0)
--

commit 342ea5a121a99c07f3e0bd7119d434dddb04cb6e
Author: Jakub Kicinski <kuba@kernel.org>

selftests/bpf: check XDP attach on a nested bond slave

This commit adds testing to verify that attaching a BPF program to a nested
slave device correctly fails when the master device already has a program
attached. It retrieves the interface index for "bond_nest2" and asserts that
attaching to it returns an error.

> diff --git a/tools/testing/selftests/bpf/prog_tests/xdp_bonding.c b/tools/testing/selftests/bpf/prog_tests/xdp_bonding.c
> index c42488e445c28..486e0f9a2adac 100644
> --- a/tools/testing/selftests/bpf/prog_tests/xdp_bonding.c
> +++ b/tools/testing/selftests/bpf/prog_tests/xdp_bonding.c
[ ... ]
> @@ -488,10 +489,23 @@ static void test_xdp_bonding_nested(struct skeletons *skeletons)
>  	if (!ASSERT_OK(err, "set bond_nest2 master"))
>  		goto out;
>  
> +	nest2 = if_nametoindex("bond_nest2");
> +	if (!ASSERT_GE(nest2, 0, "if_nametoindex bond_nest2"))
> +		goto out;
> +

[Severity: Medium]
Will this assertion accept an invalid interface index if if_nametoindex()
fails?

If if_nametoindex("bond_nest2") fails, it returns 0. The ASSERT_GE check
accepts 0, which then propagates down to bpf_program__attach_xdp().

>  	link = bpf_program__attach_xdp(skeletons->xdp_dummy->progs.xdp_dummy_prog, bond);
> -	ASSERT_OK_PTR(link, "attach program to master");
> +	if (!ASSERT_OK_PTR(link, "attach program to master"))
> +		goto out;
> +
> +	/* Attaching to a nested slave is not allowed either. Only the direct
> +	 * upper is consulted, so this only holds if every device the program
> +	 * was propagated to records it.
> +	 */
> +	link2 = bpf_program__attach_xdp(skeletons->xdp_dummy->progs.xdp_dummy_prog, nest2);
> +	ASSERT_ERR_PTR(link2, "attach program to nested slave when master has program");

[Severity: Medium]
Could a failure to resolve the interface index result in a false-positive test
success here?

If nest2 is 0 from a previous if_nametoindex() failure,
bpf_program__attach_xdp() will predictably fail. Because the test expects
attachment to fail for nesting restrictions, the expected-failure assertion
is satisfied, which could silently mask test environment setup failures.

>  
>  out:
> +	bpf_link__destroy(link2);
>  	bpf_link__destroy(link);
>  	system("ip link del bond");
>  	system("ip link del bond_nest1");

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260928223648.2739371-1-kuba@kernel.org?part=4

  reply	other threads:[~2026-09-29 22:37 UTC|newest]

Thread overview: 19+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-28 22:36 [PATCH net-next 0/5] net: fix a couple of problems with XDP and bonding Jakub Kicinski
2026-09-28 22:36 ` [PATCH net-next 1/5] net: record XDP programs propagated to lower devices Jakub Kicinski
2026-09-29 22:36   ` sashiko-bot
2026-09-29 23:32   ` Stanislav Fomichev
2026-09-30  4:38   ` netdev-bot+sashiko
2026-09-28 22:36 ` [PATCH net-next 2/5] netdevsim: add ndo_xdp_xmit Jakub Kicinski
2026-09-29 23:32   ` Stanislav Fomichev
2026-09-30  4:38   ` netdev-bot+sashiko
2026-09-28 22:36 ` [PATCH net-next 3/5] selftests: drv-net: check tcp-data-split against an already attached XDP Jakub Kicinski
2026-09-29 23:32   ` Stanislav Fomichev
2026-09-30  4:38   ` netdev-bot+sashiko
2026-09-28 22:36 ` [PATCH net-next 4/5] selftests/bpf: check XDP attach on a nested bond slave Jakub Kicinski
2026-09-29 22:37   ` sashiko-bot [this message]
2026-09-29 23:32   ` Stanislav Fomichev
2026-09-30  4:38   ` netdev-bot+sashiko
2026-09-28 22:36 ` [PATCH net-next 5/5] net: drop GSO skbs instead of handing them to XDP Jakub Kicinski
2026-09-29 22:37   ` sashiko-bot
2026-09-29 23:33   ` Stanislav Fomichev
2026-09-30  4:38   ` netdev-bot+sashiko

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260929223701.197371F00893@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=kuba@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox