BPF List
 help / color / mirror / Atom feed
* [PATCH bpf-next v4 0/2] bpf: Track iterator-owned BTF pointer lifetimes
@ 2026-09-17  5:19 Xu Yunxiang
  2026-09-17  5:19 ` [PATCH bpf-next v4 1/2] " Xu Yunxiang
  2026-09-17  5:19 ` [PATCH bpf-next v4 2/2] selftests/bpf: Test iterator " Xu Yunxiang
  0 siblings, 2 replies; 6+ messages in thread
From: Xu Yunxiang @ 2026-09-17  5:19 UTC (permalink / raw)
  To: bpf
  Cc: ast, daniel, andrii, eddyz87, memxor, ameryhung, yonghong.song,
	puranjay

Associate non-RCU iterator BTF results and their trusted fields with the
lifetime that protects them. Check child-resource cleanup and invalidate
previous results before modeling the next iterator result.

Use the source register lifetime in the common dynptr constructor path,
while preserving clone relationships and explicit-release ownership.

Changes in v4:
  - Rebase onto bpf-next as requested by Amery Hung.
  - Keep update_ref_obj() and reg_is_referenced() unchanged; introduce
    reg_lifetime_id() for owned and borrowed source lifetimes.
  - Use the common constructor path instead of a FILE-only special case.
  - Capture the source lifetime before marking a BTF field destination.
  - Move next-time invalidation into process_iter_arg().
  - Share the child-reference leak check with release_reference(), while
    removing only the initially released ID from acquired references.
  - Retain the existing lifetime selftests on the new base.

Previous posting:
https://lore.kernel.org/r/20260911084254.3481508-1-xyx2021@mail.ustc.edu.cn

Review that prompted this revision:
https://lore.kernel.org/r/CAMB2axMX07j49sZRmGFm2s==FMgKFzvKPWxc8hDvU=b3Lp=VOg@mail.gmail.com

This local v4 refresh is based on bpf-next 10c4f610b215.
The code and tests are unchanged by the rebase. The Fixes tag is scoped
to the task_vma snapshot implementation and its file reference.

Validation on this exact candidate, with a matching bpf_testmod:
  - W=1 verifier object and complete kernel/modules builds passed.
  - test_progs -t iters: 109 subtests passed, no skips or failures.
  - test_progs -t dynptr: 132 subtests passed, no skips or failures.
  - test_progs -t file_reader: 8 subtests passed, no skips or failures.

The first iters run aborted because the guest lacked libgcc_s.so.1 for
pthread_exit. After adding it, only iters was rerun, with the kernel,
runner and module unchanged. No kernel WARN, Oops or panic was found.
The full unfiltered BPF suite and sanitizer configurations were not run.
The new iterator cases assert verifier load outcomes and diagnostics;
they do not assert program execution return values.

Xu Yunxiang (2):
  bpf: Track iterator-owned BTF pointer lifetimes
  selftests/bpf: Test iterator BTF pointer lifetimes

 kernel/bpf/verifier.c                         |  88 ++++-
 .../selftests/bpf/progs/iters_testmod.c       | 332 ++++++++++++++++++
 2 files changed, 405 insertions(+), 15 deletions(-)


base-commit: 10c4f610b215bf961235141161992f010cf7e451
-- 
2.43.0


^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-09-17 14:45 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-17  5:19 [PATCH bpf-next v4 0/2] bpf: Track iterator-owned BTF pointer lifetimes Xu Yunxiang
2026-09-17  5:19 ` [PATCH bpf-next v4 1/2] " Xu Yunxiang
2026-09-17  5:44   ` sashiko-bot
2026-09-17  6:48   ` bot+bpf-ci
2026-09-17 14:45   ` Alexei Starovoitov
2026-09-17  5:19 ` [PATCH bpf-next v4 2/2] selftests/bpf: Test iterator " Xu Yunxiang

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox