BPF List
 help / color / mirror / Atom feed
From: Leon Hwang <leon.hwang@linux.dev>
To: chenyuan_fl@163.com, alexei.starovoitov@gmail.com,
	ast@kernel.org, leon.hwang@linux.dev
Cc: bpf@vger.kernel.org, daniel@iogearbox.net, andrii@kernel.org,
	eddyz87@gmail.com, memxor@gmail.com, martin.lau@linux.dev,
	yonghong.song@linux.dev, john.fastabend@gmail.com,
	song@kernel.org, ihor.solodrai@linux.dev,
	Yuan Chen <chenyuan@kylinos.cn>
Subject: Re: [PATCH bpf-next v2 1/2] bpf: Keep target extended until its last freplace link detaches
Date: Thu, 24 Sep 2026 15:06:16 +0800	[thread overview]
Message-ID: <d3e65c94-45d9-4c67-a276-103c5e7fa052@linux.dev> (raw)
In-Reply-To: <20260924023737.1140521-2-chenyuan_fl@163.com>

On 24/9/26 10:37, chenyuan_fl@163.com wrote:
> From: Yuan Chen <chenyuan@kylinos.cn>
> 
> The is_extended / prog_array_member_cnt protocol introduced by commit
> d6083f040d5d ("bpf: Prevent tailcall infinite loop caused by freplace")
> keeps a prog extended by a freplace program out of prog_array maps, and
> vice versa: once a tail call re-enters an extended subprogram, its
> tail_call_cnt resets on every execution and the loop never terminates.
> 
> But is_extended is a plain boolean, while one target prog can carry
> several freplace links at the same time, one on its entry and one on a
> global subprogram.  __bpf_trampoline_unlink_prog() cleared is_extended
> whenever *any* freplace link detached, so detaching one of two links
> re-armed the unbounded loop through the remaining one.

A prog may have multiple global subprogs. And each of the subprogs can
be attached with freplace prog. When all the subprogs are attached with
freplace progs then detach one of the freplace prog, the *is_extended*
becomes *false*, which relaxes the restriction between tailcall and
freplace introduced by the commit d6083f040d5d ("bpf: Prevent tailcall
infinite loop caused by freplace").

> 
> Replace the is_extended boolean with a count of the freplace links
> attached to each target prog, so the target stays extended until its
> last link detaches.  Also rename bpf_freplace_check_tgt_prog() to
> bpf_freplace_link_tgt_prog(), as the helper has never been a pure
> check: it reserves the target prog on success.
> 
> Fixes: d6083f040d5d ("bpf: Prevent tailcall infinite loop caused by freplace")
> Signed-off-by: Yuan Chen <chenyuan@kylinos.cn>
> 

[...]

> @@ -933,7 +933,7 @@ static int __bpf_trampoline_link_prog(struct bpf_tramp_node *node,
>  		/* Cannot attach extension if fentry/fexit are in use. */
>  		if (cnt)
>  			return -EBUSY;
> -		err = bpf_freplace_check_tgt_prog(tgt_prog);
> +		err = bpf_freplace_link_tgt_prog(tgt_prog);
>  		if (err)
>  			return err;
>  		tr->extension_prog = node->link->prog;

                return bpf_arch_text_poke(tr->func.addr, BPF_MOD_NOP,
                                          BPF_MOD_JUMP, NULL,
                                          node->link->prog->bpf_func);


I think there are existing issues here: if bpf_arch_text_poke() returns
error, the tr->extension_prog and aux->freplace_link_cnt should be
rollbacked.

Thanks,
Leon

> @@ -979,7 +979,7 @@ static int __bpf_trampoline_unlink_prog(struct bpf_tramp_node *node,
>  					 tr->extension_prog->bpf_func, NULL);
>  		tr->extension_prog = NULL;
>  		guard(mutex)(&tgt_prog->aux->ext_mutex);
> -		tgt_prog->aux->is_extended = false;
> +		tgt_prog->aux->freplace_link_cnt--;
>  		return err;
>  	}
>  	bpf_trampoline_remove_prog(tr, node);


  reply	other threads:[~2026-09-24  7:06 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-24  2:37 [PATCH bpf-next v2 0/2] bpf: Keep target extended until its last freplace link detaches chenyuan_fl
2026-09-24  2:37 ` [PATCH bpf-next v2 1/2] " chenyuan_fl
2026-09-24  7:06   ` Leon Hwang [this message]
2026-09-24  9:48     ` Jiri Olsa
2026-09-24  9:58     ` chenyuan
2026-09-25  4:35       ` [PATCH bpf-next] bpf: Roll back freplace link state when bpf_arch_text_poke() fails chenyuan_fl
2026-09-25  5:18         ` bot+bpf-ci
2026-09-25  6:05         ` Leon Hwang
2026-09-28  9:08           ` chenyuan
2026-09-24  2:37 ` [PATCH bpf-next v2 2/2] selftests/bpf: Verify is_extended with multiple freplace links chenyuan_fl
2026-09-24  7:06   ` Leon Hwang
2026-09-24  8:42 ` [PATCH bpf-next v2 0/2] bpf: Keep target extended until its last freplace link detaches Jiri Olsa
2026-09-24  9:00 ` patchwork-bot+netdevbpf

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=d3e65c94-45d9-4c67-a276-103c5e7fa052@linux.dev \
    --to=leon.hwang@linux.dev \
    --cc=alexei.starovoitov@gmail.com \
    --cc=andrii@kernel.org \
    --cc=ast@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=chenyuan@kylinos.cn \
    --cc=chenyuan_fl@163.com \
    --cc=daniel@iogearbox.net \
    --cc=eddyz87@gmail.com \
    --cc=ihor.solodrai@linux.dev \
    --cc=john.fastabend@gmail.com \
    --cc=martin.lau@linux.dev \
    --cc=memxor@gmail.com \
    --cc=song@kernel.org \
    --cc=yonghong.song@linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox