From: Ihor Solodrai <ihor.solodrai@linux.dev>
To: sashiko-reviews@lists.linux.dev
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf-next v2 3/6] selftests/bpf: Verify arena type tags in resolve_btfids test
Date: Thu, 6 Aug 2026 14:09:46 -0700 [thread overview]
Message-ID: <39401518-a0af-49f9-a247-1e3793bb0648@linux.dev> (raw)
In-Reply-To: <20260805231755.966CC1F000E9@smtp.kernel.org>
On 8/5/26 4:17 PM, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [Medium] Missing NULL pointer check on the result of `btf__type_by_id()` causes a segmentation fault when a kfunc symbol is missing.
> --
>
> --- Patch [3]: [PATCH bpf-next v2 3/6] selftests/bpf: Verify arena type tags in resolve_btfids test ---
> commit 833ac8bbb8ac1055e25790da1396864987e31541
> Author: Ihor Solodrai <ihor.solodrai@linux.dev>
>
> selftests/bpf: Verify arena type tags in resolve_btfids test
>
> This commit extends test_resolve_btfids() to assert that resolve_btfids
> emits the address_space(1) type attribute on the return type and arguments
> of kfuncs marked with KF_ARENA_RET, KF_ARENA_ARG1 or KF_ARENA_ARG2.
>
>> diff --git a/tools/testing/selftests/bpf/prog_tests/resolve_btfids.c b/tools/testing/selftests/bpf/prog_tests/resolve_btfids.c
>> index ac51fd4548214..8482f00046d4c 100644
>> --- a/tools/testing/selftests/bpf/prog_tests/resolve_btfids.c
>> +++ b/tools/testing/selftests/bpf/prog_tests/resolve_btfids.c
> [ ... ]
>> @@ -227,6 +260,39 @@ void test_resolve_btfids(void)
>> check_kfunc_set(&test_kfunc_set);
>> check_kfunc_set(&test_kfunc_set_rev);
>>
>> + /*
>> + * Check resolve_btfids wrapped exactly the arena-flagged return/args
>> + * with the address_space(1) type attribute, and left other
>> + * pointers/returns untouched.
>> + */
>> + for (i = 0; i < ARRAY_SIZE(kfunc_symbols); i++) {
>> + const struct btf_type *fn, *proto;
>> + const struct btf_param *params;
>> + const char *name = kfunc_symbols[i].name;
>> + u32 fl = kfunc_symbols[i].flags;
>> + __u32 nr;
>> +
>> + fn = btf__type_by_id(btf, kfunc_symbols[i].id);
>> + if (!ASSERT_TRUE(btf_is_func(fn), name))
>> + continue;
>
> [Severity: Medium]
> Could this cause a segmentation fault if a kfunc symbol is missing?
>
> If resolve_symbols() fails to find a kfunc in the parsed BTF file, the
> symbol's id remains -1. When -1 is passed to btf__type_by_id(), it
> returns NULL.
>
> Since btf_is_func() unconditionally accesses the info member, passing a
> NULL pointer to it would crash the test program before the ASSERT_TRUE
> evaluates.
>
> Should we check if fn is NULL before passing it to btf_is_func()?
We are fine with the test program crashing here. Wontfix.
>
>> + proto = btf__type_by_id(btf, fn->type);
>> + if (!ASSERT_TRUE(btf_is_func_proto(proto), name))
>> + continue;
> [ ... ]
>
next prev parent reply other threads:[~2026-08-06 21:10 UTC|newest]
Thread overview: 27+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-05 23:06 [PATCH bpf-next v2 0/6] resolve_btfids: Implement BTF tags emission for kfuncs Ihor Solodrai
2026-08-05 23:06 ` [PATCH bpf-next v2 1/6] resolve_btfids: Deduplicate BTF after btf2btf transformations Ihor Solodrai
2026-08-06 19:05 ` Eduard Zingerman
2026-08-06 20:48 ` Ihor Solodrai
2026-08-06 20:52 ` Eduard Zingerman
2026-08-05 23:06 ` [PATCH bpf-next v2 2/6] resolve_btfids: Process KF_ARENA_* flags in resolve_btfids Ihor Solodrai
2026-08-06 19:12 ` Eduard Zingerman
2026-08-06 21:02 ` Ihor Solodrai
2026-08-06 21:12 ` Eduard Zingerman
2026-08-06 21:16 ` Ihor Solodrai
2026-08-05 23:06 ` [PATCH bpf-next v2 3/6] selftests/bpf: Verify arena type tags in resolve_btfids test Ihor Solodrai
2026-08-05 23:17 ` sashiko-bot
2026-08-06 21:09 ` Ihor Solodrai [this message]
2026-08-06 19:15 ` Eduard Zingerman
2026-08-05 23:06 ` [PATCH bpf-next v2 4/6] resolve_btfids: Emit bpf_kfunc and bpf_fastcall decl tags Ihor Solodrai
2026-08-06 19:18 ` Eduard Zingerman
2026-08-05 23:06 ` [PATCH bpf-next v2 5/6] selftests/bpf: Verify decl tags emission in resolve_btfids test Ihor Solodrai
2026-08-06 19:20 ` Eduard Zingerman
2026-08-05 23:06 ` [PATCH bpf-next v2 6/6] docs, resolve_btfids: Document kfunc BTF annotation emission Ihor Solodrai
2026-08-05 23:16 ` sashiko-bot
2026-08-06 21:12 ` Ihor Solodrai
2026-08-06 0:01 ` bot+bpf-ci
2026-08-06 21:13 ` Ihor Solodrai
2026-08-06 19:47 ` Eduard Zingerman
2026-08-06 21:06 ` Ihor Solodrai
2026-08-06 21:17 ` Eduard Zingerman
2026-08-06 21:19 ` Ihor Solodrai
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=39401518-a0af-49f9-a247-1e3793bb0648@linux.dev \
--to=ihor.solodrai@linux.dev \
--cc=bpf@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox