From: Mykyta Yatsenko <mykyta.yatsenko5@gmail.com>
To: Viktor Malik <vmalik@redhat.com>,
bot+bpf-ci@kernel.org, ishiyama@hpc.is.uec.ac.jp,
bpf@vger.kernel.org
Cc: andrii@kernel.org, ast@kernel.org, daniel@iogearbox.net,
martin.lau@linux.dev, martin.lau@kernel.org, eddyz87@gmail.com,
yonghong.song@linux.dev, clm@meta.com, ihor.solodrai@linux.dev
Subject: Re: [PATCH bpf-next v3 1/2] bpf: add bpf_strncasecmp kfunc
Date: Tue, 20 Jan 2026 11:02:36 +0000 [thread overview]
Message-ID: <6470f4f2-2d38-43e2-ae92-d6e4c9121eed@gmail.com> (raw)
In-Reply-To: <3d9e2ce9-3e47-4b10-aad2-93b37b235239@redhat.com>
On 1/20/26 09:29, Viktor Malik wrote:
> On 1/20/26 08:21, bot+bpf-ci@kernel.org wrote:
>>> diff --git a/kernel/bpf/helpers.c b/kernel/bpf/helpers.c
>>> index 9eaa4185e0a7..753753f039ff 100644
>>> --- a/kernel/bpf/helpers.c
>>> +++ b/kernel/bpf/helpers.c
>> [ ... ]
>>
>>> -static int __bpf_strcasecmp(const char *s1, const char *s2, bool ignore_case)
>>> +static int __bpf_strncasecmp(const char *s1, const char *s2, bool ignore_case, size_t len)
>>> {
>>> char c1, c2;
>>> - int i;
>>> + int i, max_sz;
>>>
>>> if (!copy_from_kernel_nofault_allowed(s1, 1) ||
>>> !copy_from_kernel_nofault_allowed(s2, 1)) {
>>> return -ERANGE;
>>> }
>>>
>>> + max_sz = min_t(int, len, XATTR_SIZE_MAX);
>> ^^^
>>
>> Can this truncation cause incorrect results when len > INT_MAX? The len
>> parameter is size_t, but min_t(int, ...) casts it to signed int before the
>> comparison. When len is larger than INT_MAX, the cast produces a negative
>> value, and min_t returns that negative value instead of XATTR_SIZE_MAX.
>>
>> For example, if a BPF program calls bpf_strncasecmp(s1, s2, SIZE_MAX):
>> - min_t(int, SIZE_MAX, 65536) evaluates to min_t(int, -1, 65536) = -1
>> - max_sz becomes -1
>> - The loop condition (i < max_sz) is (0 < -1), which is false
>> - The loop never executes, and the function returns 0 without comparing
>>
>> This would make bpf_strncasecmp("foo", "bar", SIZE_MAX) return 0 (equal)
>> when the strings are clearly different.
> This is a good point and we should IMO address it.
>
>> Would using min_t(size_t, len, XATTR_SIZE_MAX) avoid this issue?
> Other string kfuncs use `i < len && i < XATTR_SIZE_MAX` in the loop
> condition, I'd stick to that for consistency.
>
> Viktor
Why not just use proper type (size_t for max_sz), obviously truncation is a
problem there, so use the wider type?
>
>>> +
>>> guard(pagefault)();
>>> - for (i = 0; i < XATTR_SIZE_MAX; i++) {
>>> + for (i = 0; i < max_sz; i++) {
>> [ ... ]
>>
>>> +__bpf_kfunc int bpf_strncasecmp(const char *s1__ign, const char *s2__ign, size_t len)
>>> +{
>>> + return __bpf_strncasecmp(s1__ign, s2__ign, true, len);
>>> }
>> The BPF verifier does not validate ranges for scalar kfunc parameters, so
>> BPF programs can pass arbitrary size_t values to len, triggering the
>> truncation issue described above.
>>
>>
>> ---
>> AI reviewed your patch. Please fix the bug or email reply why it's not a bug.
>> See: https://github.com/kernel-patches/vmtest/blob/master/ci/claude/README.md
>>
>> CI run summary: https://github.com/kernel-patches/bpf/actions/runs/21162711653
next prev parent reply other threads:[~2026-01-20 11:02 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-01-20 7:03 [PATCH bpf-next v3 0/2] bpf: Add kfunc bpf_strncasecmp() Yuzuki Ishiyama
2026-01-20 7:03 ` [PATCH bpf-next v3 1/2] bpf: add bpf_strncasecmp kfunc Yuzuki Ishiyama
2026-01-20 7:21 ` bot+bpf-ci
2026-01-20 9:29 ` Viktor Malik
2026-01-20 10:59 ` Yuzuki Ishiyama
2026-01-20 11:02 ` Mykyta Yatsenko [this message]
2026-01-20 11:15 ` Viktor Malik
2026-01-20 7:03 ` [PATCH bpf-next v3 2/2] selftests/bpf: Test kfunc bpf_strncasecmp Yuzuki Ishiyama
2026-01-20 9:30 ` Viktor Malik
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=6470f4f2-2d38-43e2-ae92-d6e4c9121eed@gmail.com \
--to=mykyta.yatsenko5@gmail.com \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bot+bpf-ci@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=clm@meta.com \
--cc=daniel@iogearbox.net \
--cc=eddyz87@gmail.com \
--cc=ihor.solodrai@linux.dev \
--cc=ishiyama@hpc.is.uec.ac.jp \
--cc=martin.lau@kernel.org \
--cc=martin.lau@linux.dev \
--cc=vmalik@redhat.com \
--cc=yonghong.song@linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox