From: Eduard Zingerman <eddyz87@gmail.com>
To: bot+bpf-ci@kernel.org, memxor@gmail.com, bpf@vger.kernel.org
Cc: ast@kernel.org, andrii@kernel.org, daniel@iogearbox.net,
emil@etsalapatis.com, kkd@meta.com, kernel-team@meta.com,
martin.lau@kernel.org, yonghong.song@linux.dev, clm@meta.com,
ihor.solodrai@linux.dev
Subject: Re: [PATCH bpf-next v5 11/14] bpf: Report Call Type Safety argument errors
Date: Sat, 15 Aug 2026 11:00:48 -0700 [thread overview]
Message-ID: <668871823f90f69896d3db27b56db2f53e481162.camel@gmail.com> (raw)
In-Reply-To: <3eda33675965763aa9b2e6a5784f32b34a6a83988a55fbea98b0dbd0cf3b088d@mail.kernel.org>
On Sat, 2026-08-15 at 07:49 +0000, bot+bpf-ci@kernel.org wrote:
> > diff --git a/kernel/bpf/diagnostics.c b/kernel/bpf/diagnostics.c
> > index 5d20ea9e470e..99784d465881 100644
> > --- a/kernel/bpf/diagnostics.c
> > +++ b/kernel/bpf/diagnostics.c
>
> [ ... ]
>
> > diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
> > index f5bf8cf644b8..2c067be53106 100644
> > --- a/kernel/bpf/verifier.c
> > +++ b/kernel/bpf/verifier.c
>
> [ ... ]
>
> > @@ -12417,29 +12552,43 @@ static int check_kfunc_args(struct bpf_verifier_env *env, struct bpf_call_arg_me
> >
> > t = btf_type_skip_modifiers(btf, args[i].type, NULL);
> >
> > - if (btf_type_is_ptr(t) && (bpf_register_is_null(reg) || type_may_be_null(reg->type)) &&
> > + if (btf_type_is_ptr(t)) {
> > + ref_t = btf_type_skip_modifiers(btf, t->type, &ref_id);
> > + ref_tname = btf_name_by_offset(btf, ref_t->name_off);
> > + }
> > +
> > + if (btf_type_is_ptr(t) &&
> > + (bpf_register_is_null(reg) || type_may_be_null(reg->type)) &&
> > !type_may_be_null(kf_arg_type)) {
> > + const char *expected_type;
> > +
> > + expected_type = bpf_diag_fmt_btf_type(env, btf, ref_id);
> > verbose(env, "Possibly NULL pointer passed to trusted %s\n",
> > reg_arg_name(env, argno));
> > + bpf_diag_call_arg_fmt(env, insn_idx, argno, func_name,
> > + "Add a NULL check and call the kfunc only on the non-NULL path.",
> > + "the pointer may be NULL, but this kfunc requires a non-NULL pointer to %s",
> > + expected_type);
> > return -EACCES;
> > }
> >
> > if (regno == meta->release_regno && !is_kfunc_arg_dynptr(meta->btf, &args[i]) &&
> > !reg_is_referenced(env, reg) && !bpf_register_is_null(reg)) {
> > + const char *expected_type;
> > +
> > + expected_type = bpf_diag_fmt_btf_type(env, btf, ref_id);
> > verbose(env, "release kfunc %s expects referenced PTR_TO_BTF_ID passed to %s\n",
> > func_name, reg_arg_name(env, argno));
> > + bpf_diag_call_arg_fmt(env, insn_idx, argno, func_name,
> > + "Pass the resource-owning pointer returned by the matching acquire kfunc, and avoid calling the release kfunc after ownership has already been transferred or released.",
> > + "release kfuncs require a resource-owning value of type %s returned by a matching acquire kfunc",
> > + expected_type);
> > return -EINVAL;
> > }
>
> When the kfunc parameter is a plain void*, will bpf_diag_fmt_btf_type()
> format it correctly? For a void* parameter, ref_id becomes 0 after
> btf_type_skip_modifiers() and bpf_diag_fmt_btf_type() produces the
> literal string "()" for type ID 0.
This is legit btf.c:btf_show_name() needs a fix:
--- a/kernel/bpf/btf.c
+++ b/kernel/bpf/btf.c
@@ -1172,9 +1172,9 @@ static const char *btf_show_name(struct btf_show *show)
id = 0;
break;
}
+ t = btf_type_skip_qualifiers(show->btf, id);
if (!id)
break;
- t = btf_type_skip_qualifiers(show->btf, id);
}
/* We may not be able to represent this type; bail to be safe */
if (i == BTF_SHOW_MAX_ITER)
...
next prev parent reply other threads:[~2026-08-15 18:00 UTC|newest]
Thread overview: 37+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-15 6:45 [PATCH bpf-next v5 00/14] Redesign Verification Errors Kumar Kartikeya Dwivedi
2026-08-15 6:45 ` [PATCH bpf-next v5 01/14] bpf: Add verifier diagnostics report helpers Kumar Kartikeya Dwivedi
2026-08-15 6:52 ` sashiko-bot
2026-08-15 7:20 ` bot+bpf-ci
2026-08-15 6:45 ` [PATCH bpf-next v5 02/14] bpf: Add source and instruction diagnostic context Kumar Kartikeya Dwivedi
2026-08-15 7:01 ` sashiko-bot
2026-08-15 7:34 ` bot+bpf-ci
2026-08-15 6:45 ` [PATCH bpf-next v5 03/14] bpf: Add verifier diagnostic event log Kumar Kartikeya Dwivedi
2026-08-15 7:34 ` bot+bpf-ci
2026-08-15 6:45 ` [PATCH bpf-next v5 04/14] bpf: Prune verifier diagnostics when switching paths Kumar Kartikeya Dwivedi
2026-08-15 6:46 ` [PATCH bpf-next v5 05/14] bpf: Track verifier register diagnostic events Kumar Kartikeya Dwivedi
2026-08-15 7:34 ` bot+bpf-ci
2026-08-15 7:38 ` sashiko-bot
2026-08-15 6:46 ` [PATCH bpf-next v5 06/14] bpf: Track verifier reference " Kumar Kartikeya Dwivedi
2026-08-15 6:46 ` [PATCH bpf-next v5 07/14] bpf: Track verifier context " Kumar Kartikeya Dwivedi
2026-08-15 7:20 ` bot+bpf-ci
2026-08-15 6:46 ` [PATCH bpf-next v5 08/14] bpf: Report Register Type Safety errors Kumar Kartikeya Dwivedi
2026-08-15 7:34 ` bot+bpf-ci
2026-08-15 17:29 ` Eduard Zingerman
2026-08-15 6:46 ` [PATCH bpf-next v5 09/14] bpf: Report Memory Safety bounds errors Kumar Kartikeya Dwivedi
2026-08-15 6:59 ` sashiko-bot
2026-08-15 7:34 ` bot+bpf-ci
2026-08-15 6:46 ` [PATCH bpf-next v5 10/14] bpf: Report Resource Lifetime reference leaks Kumar Kartikeya Dwivedi
2026-08-15 7:34 ` bot+bpf-ci
2026-08-15 17:36 ` Eduard Zingerman
2026-08-15 6:46 ` [PATCH bpf-next v5 11/14] bpf: Report Call Type Safety argument errors Kumar Kartikeya Dwivedi
2026-08-15 7:49 ` bot+bpf-ci
2026-08-15 18:00 ` Eduard Zingerman [this message]
2026-08-15 6:46 ` [PATCH bpf-next v5 12/14] bpf: Report Execution Context Safety errors Kumar Kartikeya Dwivedi
2026-08-15 7:34 ` bot+bpf-ci
2026-08-15 6:46 ` [PATCH bpf-next v5 13/14] bpf: Report Program Structure CFG errors Kumar Kartikeya Dwivedi
2026-08-15 7:34 ` bot+bpf-ci
2026-08-15 17:50 ` Eduard Zingerman
2026-08-15 6:46 ` [PATCH bpf-next v5 14/14] bpf: Report Policy helper and kfunc errors Kumar Kartikeya Dwivedi
2026-08-15 7:20 ` bot+bpf-ci
2026-08-15 17:39 ` Eduard Zingerman
2026-08-15 18:57 ` [PATCH bpf-next v5 00/14] Redesign Verification Errors patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=668871823f90f69896d3db27b56db2f53e481162.camel@gmail.com \
--to=eddyz87@gmail.com \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bot+bpf-ci@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=clm@meta.com \
--cc=daniel@iogearbox.net \
--cc=emil@etsalapatis.com \
--cc=ihor.solodrai@linux.dev \
--cc=kernel-team@meta.com \
--cc=kkd@meta.com \
--cc=martin.lau@kernel.org \
--cc=memxor@gmail.com \
--cc=yonghong.song@linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox