BPF List
 help / color / mirror / Atom feed
* [PATCH bpf-next v2 0/2] bpf: Keep target extended until its last freplace link detaches
@ 2026-09-24  2:37 chenyuan_fl
  2026-09-24  2:37 ` [PATCH bpf-next v2 1/2] " chenyuan_fl
                   ` (3 more replies)
  0 siblings, 4 replies; 13+ messages in thread
From: chenyuan_fl @ 2026-09-24  2:37 UTC (permalink / raw)
  To: alexei.starovoitov, ast, leon.hwang
  Cc: bpf, daniel, andrii, eddyz87, memxor, martin.lau, yonghong.song,
	john.fastabend, song, ihor.solodrai, Yuan Chen

From: Yuan Chen <chenyuan@kylinos.cn>

is_extended is a plain boolean, but one target prog can carry several
freplace links at the same time, one on its entry and one on a global
subprogram.  __bpf_trampoline_unlink_prog() cleared it whenever *any*
of them detached, so with two links on one target, detaching one of
them re-armed the unbounded tail call loop closed by commit
d6083f040d5d ("bpf: Prevent tailcall infinite loop caused by freplace"):
a single BPF_PROG_TEST_RUN on the tail-called target then panics the
kernel, reproduced on both bpf-next and master.

Patch 1 replaces the boolean with a count of the freplace links
attached to each target prog, so the target stays extended until its
last link detaches.  Patch 2 adds a selftest covering the sequence.

Changes since v1:

- freplace_link_cnt is u16 instead of u64, per Alexei's review: it is
  bounded by BPF_MAX_SUBPROGS, which counts the entry function too, so
  up to 256 links, one past u8, and it sits in the padding next to
  stack_arg_sp_adjust, so bpf_prog_aux does not grow
- dropped the separate is_extended boolean, deriving the extended state
  from the count itself
- renamed bpf_freplace_check_tgt_prog() to bpf_freplace_link_tgt_prog(),
  it reserves the target on success
- dropped the WARN_ON_ONCE() on detach, per Leon's review: the count is
  paired by the link lifetime and the sibling prog_array_member_cnt
  decrement is not guarded either

Yuan Chen (2):
  bpf: Keep target extended until its last freplace link detaches
  selftests/bpf: Verify is_extended with multiple freplace links

 include/linux/bpf.h                           |  4 +-
 kernel/bpf/arraymap.c                         |  2 +-
 kernel/bpf/trampoline.c                       |  8 +-
 .../selftests/bpf/prog_tests/tailcalls.c      | 74 +++++++++++++++++++
 .../bpf/progs/tailcall_freplace_multi.c       | 27 +++++++
 5 files changed, 108 insertions(+), 7 deletions(-)
 create mode 100644 tools/testing/selftests/bpf/progs/tailcall_freplace_multi.c

-- 
2.54.0


^ permalink raw reply	[flat|nested] 13+ messages in thread

end of thread, other threads:[~2026-09-28  9:09 UTC | newest]

Thread overview: 13+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-24  2:37 [PATCH bpf-next v2 0/2] bpf: Keep target extended until its last freplace link detaches chenyuan_fl
2026-09-24  2:37 ` [PATCH bpf-next v2 1/2] " chenyuan_fl
2026-09-24  7:06   ` Leon Hwang
2026-09-24  9:48     ` Jiri Olsa
2026-09-24  9:58     ` chenyuan
2026-09-25  4:35       ` [PATCH bpf-next] bpf: Roll back freplace link state when bpf_arch_text_poke() fails chenyuan_fl
2026-09-25  5:18         ` bot+bpf-ci
2026-09-25  6:05         ` Leon Hwang
2026-09-28  9:08           ` chenyuan
2026-09-24  2:37 ` [PATCH bpf-next v2 2/2] selftests/bpf: Verify is_extended with multiple freplace links chenyuan_fl
2026-09-24  7:06   ` Leon Hwang
2026-09-24  8:42 ` [PATCH bpf-next v2 0/2] bpf: Keep target extended until its last freplace link detaches Jiri Olsa
2026-09-24  9:00 ` patchwork-bot+netdevbpf

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox