BPF List
 help / color / mirror / Atom feed
* [PATCH bpf-next v6 0/2] bpf: Destroy callee-local dynptrs on subprog return
@ 2026-09-27 12:04 Xu Yunxiang
  2026-09-27 12:04 ` [PATCH bpf-next v6 1/2] " Xu Yunxiang
                   ` (2 more replies)
  0 siblings, 3 replies; 9+ messages in thread
From: Xu Yunxiang @ 2026-09-27 12:04 UTC (permalink / raw)
  To: bpf; +Cc: ast, daniel, andrii, eddyz87, memxor, ameryhung, sashiko-bot

A dynptr data slice is valid only while the specific dynptr that produced
it remains valid. Apply normal dynptr stack-slot teardown before a callee
frame disappears, so its descendants are invalidated and its last
release-capable referenced dynptr cannot be lost.

Patch 1 adds a helper to destroy dynptrs in an inclusive range of stack
slots and reuses it for initialization, variable-offset writes and
subprogram returns. The callback diagnostic expectation changes in that
same commit. Patch 2 tests callee-local slices, last-holder rejection and
caller-owned slice compatibility.

Changes in v6, following Amery's review:
  - Replace destroy_dynptrs_on_func_exit() with the generic
    destroy_dynptrs_in_stack_slots() and use it at all three call sites.
  - Add the requested blank line before return-time teardown.
  - Clarify callee-local clone comments and rename the rejection test to
    callee_dynptr_slice_invalid_after_return().
  - Rebase onto bpf-next ea9358e1270ab.

v5:
https://lore.kernel.org/r/20260920210438.345847-1-xyx2021@mail.ustc.edu.cn
Review:
https://lore.kernel.org/r/CAMB2axMmrTb+UZ84UD48MwMtXbk1s9bWtreU3AOfjzU0fPT0BA@mail.gmail.com
https://lore.kernel.org/r/CAMB2axOEZjRV1K4Yxb4=1f2jvPHiD2rVy-+byXbvs3G0qat63g@mail.gmail.com

Validation on the rebased candidate with a matching bpf_testmod:
  - W=1 verifier, full kernel and modules builds passed.
  - Changed BPF objects and required fixtures compiled strictly.
  - dynptr: 2/137 passed; 0 skipped.
  - file_reader: 1/8 passed; 0 skipped.
  - ns_bpf_qdisc/invalid_dynptr_returned_slice: 1/1 passed; 0 skipped.
  - global_func: 3/29 passed; 3 skipped.
  - cb_refs: 1/4 passed; 0 skipped.
  - subprogs: 5/34 passed; 0 skipped.
  - verifier_var_off: 1/24 passed; 1 skipped.

No selected test failed. The VM used panic_on_warn and panic_on_oops;
no WARN_ON report, Oops or panic was found. Unprivileged BPF was
enabled only in the isolated guest; the kernel printed the expected
Spectre-v2 notice when enabling that sysctl.

The broad test_progs build used BPF_STRICT_BUILD=0 for unselected
objects requiring unavailable kernel features. The changed objects
and required fixtures were also compiled in strict mode. Annotated
lifetime tests check loading and diagnostics. The unfiltered full
suite, sanitizer and architecture matrices, and new unmodified-base
differential probes were not run in this rebase validation.

Three 512-byte stack-limit variants skip on this 2 KiB-stack kernel;
their large-stack counterparts passed. ctx_arg_rewrite skips because
the kernel supports native context-argument tags.

Please queue the verifier fix for stable after it reaches the BPF tree.

Xu Yunxiang (2):
  bpf: Destroy callee-local dynptrs on subprog return
  selftests/bpf: Test dynptr teardown on subprog return

 kernel/bpf/verifier.c                         | 40 +++++---
 .../selftests/bpf/prog_tests/bpf_qdisc.c      |  2 +
 ...disc_fail__invalid_dynptr_returned_slice.c | 76 ++++++++++++++
 .../testing/selftests/bpf/progs/dynptr_fail.c | 99 ++++++++++++++++++-
 4 files changed, 202 insertions(+), 15 deletions(-)
 create mode 100644 tools/testing/selftests/bpf/progs/bpf_qdisc_fail__invalid_dynptr_returned_slice.c


base-commit: ea9358e1270ab2c3ba6f36bd9bdda68617665516
-- 
2.43.0


^ permalink raw reply	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2026-10-05 23:40 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-27 12:04 [PATCH bpf-next v6 0/2] bpf: Destroy callee-local dynptrs on subprog return Xu Yunxiang
2026-09-27 12:04 ` [PATCH bpf-next v6 1/2] " Xu Yunxiang
2026-09-28  4:48   ` Amery Hung
2026-10-02 11:29     ` Alexei Starovoitov
2026-10-05 21:59       ` Ihor Solodrai
2026-10-05 22:33         ` Amery Hung
2026-09-27 12:04 ` [PATCH bpf-next v6 2/2] selftests/bpf: Test dynptr teardown " Xu Yunxiang
2026-09-28  5:24   ` Amery Hung
2026-10-05 23:40 ` [PATCH bpf-next v6 0/2] bpf: Destroy callee-local dynptrs " patchwork-bot+netdevbpf

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox