BPF List
 help / color / mirror / Atom feed
* [PATCH bpf-next v4 0/2] bpf: Destroy callee-local dynptrs on subprog return
@ 2026-09-17  5:19 Xu Yunxiang
  2026-09-17  5:19 ` [PATCH bpf-next v4 1/2] " Xu Yunxiang
  2026-09-17  5:20 ` [PATCH bpf-next v4 2/2] selftests/bpf: Test dynptr teardown " Xu Yunxiang
  0 siblings, 2 replies; 5+ messages in thread
From: Xu Yunxiang @ 2026-09-17  5:19 UTC (permalink / raw)
  To: bpf; +Cc: ast, daniel, andrii, eddyz87, memxor, ameryhung, sashiko-bot

A dynptr data slice is valid only while the specific dynptr that produced
it remains valid. prepare_func_exit() currently frees a callee stack without
running the normal dynptr teardown. A slice derived from a callee-local
dynptr can therefore escape into the caller and remain usable after its
source dynptr has disappeared.

Patch 1 destroys every callee-local dynptr before freeing the frame, using
the existing stack-slot teardown so exact descendants are invalidated and
the last release-capable referenced dynptr cannot be lost. It distinguishes
function-return teardown from stack-slot overwrite in the diagnostic and
keeps the affected existing callback expectation in the same commit.

Patch 2 covers immediate use of a ring buffer clone slice, release-time
invalidation of a caller dynptr slice after it crosses a subprogram return,
an immediate skb use, and the last-reference error path. Its success control
checks that destroying a callee-local clone preserves a slice derived from
the caller-owned dynptr.

The release-time case protects existing submit-time invalidation; the
return-time cases check the lifetime of the source descriptor. The
positive control checks verifier acceptance without a runtime assertion.

Please queue the verifier fix for stable after it reaches the BPF tree.

This local v4 refresh is based on bpf-next 10c4f610b215. Teardown
follows the complete return-register copy loop, including R0:R2 on this
base.

Validation on this exact candidate, with a matching bpf_testmod:
  - W=1 verifier object and complete kernel/modules builds passed.
  - test_progs -t dynptr: 2/136 passed, no skips or failures.
  - test_progs -t file_reader: 1/8 passed, no skips or failures.
  - The qdisc invalid_dynptr_returned_slice case passed (1/1).
  - test_progs -t global_func: 3/29 passed, one conditional skip.
  - test_progs -t cb_refs: 1/0 passed, no skips or failures.
  - test_progs -t subprogs: 5/33 passed, no skips or failures.

The global-function skip is the compatibility ctx_arg_rewrite case,
which skips when the kernel supports the native context-argument tag.
The first subprogs run lacked two auxiliary BPF object files; after
packaging those already-built objects, only that group was rerun. The
kernel, runner and module were unchanged. No kernel WARN, Oops or panic
was found. The full unfiltered suite and sanitizer configurations were
not run; these results do not claim a dedicated R2 slice-return test.

Changes in v4:
  - Emit a function-return-specific diagnostic when a departing frame holds
    the last dynptr capable of releasing a referenced resource.
  - Run callee dynptr teardown before switching to the caller instruction so
    diagnostics and invalidation records identify the actual BPF_EXIT.
  - Move the existing callback expectation update into patch 1 to keep it
    with the diagnostic change.
  - Make the release-time test derive its slice from the caller-owned dynptr,
    isolating submit-time invalidation from callee teardown.
  - Rebase from e4a62833adff to bpf-next 10c4f610b215.

v3: https://lore.kernel.org/r/20260911084209.3481285-1-xyx2021@mail.ustc.edu.cn

Changes in v3:
  - Replace slice reparenting with normal destruction of every dynptr in the
    departing callee stack, as suggested by Amery.
  - Invalidate escaped clone slices on frame return and test immediate use
    before resource release.
  - Cover loss of the last release-capable dynptr and add a control preserving
    a caller-owned slice while destroying a separate callee-local clone.

v2: https://lore.kernel.org/r/20260910044006.2279547-1-xyx2021@mail.ustc.edu.cn
v1: https://lore.kernel.org/r/20260909042858.1734125-1-xyx2021@mail.ustc.edu.cn

Xu Yunxiang (2):
  bpf: Destroy callee-local dynptrs on subprog return
  selftests/bpf: Test dynptr teardown on subprog return

 kernel/bpf/verifier.c                         | 51 ++++++++--
 .../selftests/bpf/prog_tests/bpf_qdisc.c      |  2 +
 ...disc_fail__invalid_dynptr_returned_slice.c | 76 ++++++++++++++
 .../testing/selftests/bpf/progs/dynptr_fail.c | 99 ++++++++++++++++++-
 4 files changed, 220 insertions(+), 8 deletions(-)
 create mode 100644 tools/testing/selftests/bpf/progs/bpf_qdisc_fail__invalid_dynptr_returned_slice.c


base-commit: 10c4f610b215bf961235141161992f010cf7e451
-- 
2.43.0


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-09-17 14:48 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-17  5:19 [PATCH bpf-next v4 0/2] bpf: Destroy callee-local dynptrs on subprog return Xu Yunxiang
2026-09-17  5:19 ` [PATCH bpf-next v4 1/2] " Xu Yunxiang
2026-09-17  6:15   ` bot+bpf-ci
2026-09-17 14:48   ` Alexei Starovoitov
2026-09-17  5:20 ` [PATCH bpf-next v4 2/2] selftests/bpf: Test dynptr teardown " Xu Yunxiang

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox