BPF List
 help / color / mirror / Atom feed
From: Ihor Solodrai <ihor.solodrai@linux.dev>
To: sashiko-reviews@lists.linux.dev
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf-next v2 3/6] selftests/bpf: Verify arena type tags in resolve_btfids test
Date: Thu, 6 Aug 2026 14:09:46 -0700	[thread overview]
Message-ID: <39401518-a0af-49f9-a247-1e3793bb0648@linux.dev> (raw)
In-Reply-To: <20260805231755.966CC1F000E9@smtp.kernel.org>

On 8/5/26 4:17 PM, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [Medium] Missing NULL pointer check on the result of `btf__type_by_id()` causes a segmentation fault when a kfunc symbol is missing.
> --
> 
> --- Patch [3]: [PATCH bpf-next v2 3/6] selftests/bpf: Verify arena type tags in resolve_btfids test ---
> commit 833ac8bbb8ac1055e25790da1396864987e31541
> Author: Ihor Solodrai <ihor.solodrai@linux.dev>
> 
> selftests/bpf: Verify arena type tags in resolve_btfids test
> 
> This commit extends test_resolve_btfids() to assert that resolve_btfids
> emits the address_space(1) type attribute on the return type and arguments
> of kfuncs marked with KF_ARENA_RET, KF_ARENA_ARG1 or KF_ARENA_ARG2.
> 
>> diff --git a/tools/testing/selftests/bpf/prog_tests/resolve_btfids.c b/tools/testing/selftests/bpf/prog_tests/resolve_btfids.c
>> index ac51fd4548214..8482f00046d4c 100644
>> --- a/tools/testing/selftests/bpf/prog_tests/resolve_btfids.c
>> +++ b/tools/testing/selftests/bpf/prog_tests/resolve_btfids.c
> [ ... ]
>> @@ -227,6 +260,39 @@ void test_resolve_btfids(void)
>>  	check_kfunc_set(&test_kfunc_set);
>>  	check_kfunc_set(&test_kfunc_set_rev);
>>  
>> +	/*
>> +	 * Check resolve_btfids wrapped exactly the arena-flagged return/args
>> +	 * with the address_space(1) type attribute, and left other
>> +	 * pointers/returns untouched.
>> +	 */
>> +	for (i = 0; i < ARRAY_SIZE(kfunc_symbols); i++) {
>> +		const struct btf_type *fn, *proto;
>> +		const struct btf_param *params;
>> +		const char *name = kfunc_symbols[i].name;
>> +		u32 fl = kfunc_symbols[i].flags;
>> +		__u32 nr;
>> +
>> +		fn = btf__type_by_id(btf, kfunc_symbols[i].id);
>> +		if (!ASSERT_TRUE(btf_is_func(fn), name))
>> +			continue;
> 
> [Severity: Medium]
> Could this cause a segmentation fault if a kfunc symbol is missing?
> 
> If resolve_symbols() fails to find a kfunc in the parsed BTF file, the
> symbol's id remains -1. When -1 is passed to btf__type_by_id(), it
> returns NULL.
> 
> Since btf_is_func() unconditionally accesses the info member, passing a
> NULL pointer to it would crash the test program before the ASSERT_TRUE
> evaluates.
> 
> Should we check if fn is NULL before passing it to btf_is_func()?

We are fine with the test program crashing here. Wontfix.

> 
>> +		proto = btf__type_by_id(btf, fn->type);
>> +		if (!ASSERT_TRUE(btf_is_func_proto(proto), name))
>> +			continue;
> [ ... ]
> 


  reply	other threads:[~2026-08-06 21:10 UTC|newest]

Thread overview: 27+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-05 23:06 [PATCH bpf-next v2 0/6] resolve_btfids: Implement BTF tags emission for kfuncs Ihor Solodrai
2026-08-05 23:06 ` [PATCH bpf-next v2 1/6] resolve_btfids: Deduplicate BTF after btf2btf transformations Ihor Solodrai
2026-08-06 19:05   ` Eduard Zingerman
2026-08-06 20:48     ` Ihor Solodrai
2026-08-06 20:52       ` Eduard Zingerman
2026-08-05 23:06 ` [PATCH bpf-next v2 2/6] resolve_btfids: Process KF_ARENA_* flags in resolve_btfids Ihor Solodrai
2026-08-06 19:12   ` Eduard Zingerman
2026-08-06 21:02     ` Ihor Solodrai
2026-08-06 21:12       ` Eduard Zingerman
2026-08-06 21:16         ` Ihor Solodrai
2026-08-05 23:06 ` [PATCH bpf-next v2 3/6] selftests/bpf: Verify arena type tags in resolve_btfids test Ihor Solodrai
2026-08-05 23:17   ` sashiko-bot
2026-08-06 21:09     ` Ihor Solodrai [this message]
2026-08-06 19:15   ` Eduard Zingerman
2026-08-05 23:06 ` [PATCH bpf-next v2 4/6] resolve_btfids: Emit bpf_kfunc and bpf_fastcall decl tags Ihor Solodrai
2026-08-06 19:18   ` Eduard Zingerman
2026-08-05 23:06 ` [PATCH bpf-next v2 5/6] selftests/bpf: Verify decl tags emission in resolve_btfids test Ihor Solodrai
2026-08-06 19:20   ` Eduard Zingerman
2026-08-05 23:06 ` [PATCH bpf-next v2 6/6] docs, resolve_btfids: Document kfunc BTF annotation emission Ihor Solodrai
2026-08-05 23:16   ` sashiko-bot
2026-08-06 21:12     ` Ihor Solodrai
2026-08-06  0:01   ` bot+bpf-ci
2026-08-06 21:13     ` Ihor Solodrai
2026-08-06 19:47   ` Eduard Zingerman
2026-08-06 21:06     ` Ihor Solodrai
2026-08-06 21:17       ` Eduard Zingerman
2026-08-06 21:19         ` Ihor Solodrai

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=39401518-a0af-49f9-a247-1e3793bb0648@linux.dev \
    --to=ihor.solodrai@linux.dev \
    --cc=bpf@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox