From: Eduard Zingerman <eddyz87@gmail.com>
To: Amery Hung <ameryhung@gmail.com>, bpf@vger.kernel.org
Cc: alexei.starovoitov@gmail.com, andrii@kernel.org,
daniel@iogearbox.net, memxor@gmail.com, kernel-team@meta.com
Subject: Re: [PATCH bpf-next v2 03/18] bpf: Split kfunc map argument into __const_map and __map
Date: Mon, 27 Jul 2026 09:48:28 -0700 [thread overview]
Message-ID: <ea6041eda0af3980637490f08c97be2539f1ed33.camel@gmail.com> (raw)
In-Reply-To: <015164cfd5ac0c3bae007313c3859fef6a583233.camel@gmail.com>
On Fri, 2026-07-24 at 12:07 -0700, Amery Hung wrote:
> Kfuncs used a single '__map' suffix (KF_ARG_PTR_TO_MAP) for two different
> things: a verifier-known map matched by map_uid against a bound
> timer/wq/task_work object (bpf_wq_init, bpf_task_work_schedule*), and an
> opaque 'struct bpf_map *' used only at runtime (bpf_arena_*), which may be a
> map fd or a PTR_TO_BTF_ID struct bpf_map (e.g. a bpf_map iterator's ctx->map).
>
> That combined path only accepted the btf map form due to type confusion. The
> 'if (!reg->map_ptr)' check reads reg->map_ptr, which aliases reg->btf in the
> bpf_reg_state union. A PTR_TO_BTF_ID register always has a non-NULL reg->btf,
> so the guard silently passed and validation fell through to
> process_kf_arg_ptr_to_btf_id(). It also recorded PTR_TO_BTF_ID info in
> meta->map, which would be meaningless.
What a bug, I wonder if we have more places like that.
In LLVM code base they use the following pattern:
class foo {
int tag;
union {
struct bar_info { ... } bar;
struct buz_info { ... } buz;
};
};
struct bar_info *get_bar(class foo *f) {
if (f->tag != BAR)
fatal_error(); // the error is compiled away in release builds
return &f->bar;
}
And similar pattern with checks in getter for just mutually exclusive
fields. I wonder if we should adopt the same approach.
> Split the annotation to avoid such type confusion and to align with
> helper:
>
> - '__const_map' -> KF_ARG_CONST_MAP_PTR: verifier-known map, handled by
> process_map_ptr_arg() like helper ARG_CONST_MAP_PTR.
>
> - '__map' -> KF_ARG_PTR_TO_BTF_ID: opaque struct bpf_map, validated by
> process_kf_arg_ptr_to_btf_id(). A map fd still matches via
> reg2btf_ids[CONST_PTR_TO_MAP], so bpf_arena_alloc_pages(&map) keeps
> working.
>
> Signed-off-by: Amery Hung <ameryhung@gmail.com>
> ---
Reviewed-by: Eduard Zingerman <eddyz87@gmail.com>
next prev parent reply other threads:[~2026-07-27 16:48 UTC|newest]
Thread overview: 44+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-24 19:07 [PATCH bpf-next v2 00/18] Generate bpf_func_proto for kfunc Amery Hung
2026-07-24 19:07 ` [PATCH bpf-next v2 01/18] bpf: Drop process_timer_func wrappers Amery Hung
2026-07-25 1:39 ` Eduard Zingerman
2026-07-24 19:07 ` [PATCH bpf-next v2 02/18] bpf: Unify const map ptr argument checking for helpers and kfuncs Amery Hung
2026-07-24 19:28 ` sashiko-bot
2026-07-24 20:49 ` Amery Hung
2026-07-24 21:29 ` Kumar Kartikeya Dwivedi
2026-07-25 1:57 ` Eduard Zingerman
2026-07-24 19:07 ` [PATCH bpf-next v2 03/18] bpf: Split kfunc map argument into __const_map and __map Amery Hung
[not found] ` <015164cfd5ac0c3bae007313c3859fef6a583233.camel@gmail.com>
2026-07-27 16:48 ` Eduard Zingerman [this message]
2026-07-24 19:07 ` [PATCH bpf-next v2 04/18] bpf: Pass kfunc meta to mem and mem_size check Amery Hung
2026-07-27 18:37 ` Eduard Zingerman
2026-07-24 19:07 ` [PATCH bpf-next v2 05/18] bpf: Check helper and kfunc mem+size arguments identically Amery Hung
2026-07-27 20:39 ` Eduard Zingerman
2026-07-27 20:51 ` Eduard Zingerman
2026-07-24 19:08 ` [PATCH bpf-next v2 06/18] selftests/bpf: Add tests for helper and kfunc mem+size arguments Amery Hung
2026-07-24 19:25 ` sashiko-bot
2026-07-27 20:40 ` Eduard Zingerman
2026-07-24 19:08 ` [PATCH bpf-next v2 07/18] bpf: Check fixed-size mem args of helpers and kfuncs the same way Amery Hung
2026-07-24 19:32 ` sashiko-bot
2026-07-24 20:39 ` Amery Hung
2026-07-27 21:17 ` Eduard Zingerman
2026-07-24 19:08 ` [PATCH bpf-next v2 08/18] bpf: Express ARG_CONST_SIZE_OR_ZERO as ARG_CONST_SIZE | SCALAR_MAYBE_ZERO Amery Hung
2026-07-27 22:29 ` Eduard Zingerman
2026-07-24 19:08 ` [PATCH bpf-next v2 09/18] bpf: Rename ARG_CONST_SIZE{,_OR_ZERO} to ARG_MEM_SIZE{,_OR_ZERO} Amery Hung
2026-07-24 19:08 ` [PATCH bpf-next v2 10/18] bpf: Fold __szk const size handling into the scalar arg path Amery Hung
2026-07-27 22:48 ` Eduard Zingerman
2026-07-24 19:08 ` [PATCH bpf-next v2 11/18] bpf: Classify kfunc mem_size args from BTF without register state Amery Hung
2026-07-24 19:38 ` sashiko-bot
2026-07-24 22:52 ` Amery Hung
2026-07-27 22:50 ` Eduard Zingerman
2026-07-24 19:08 ` [PATCH bpf-next v2 12/18] bpf: Handle NULL kfunc pointer args without a KF_ARG_PTR_TO_NULL type Amery Hung
2026-07-27 23:15 ` Eduard Zingerman
2026-07-24 19:08 ` [PATCH bpf-next v2 13/18] bpf: Distinguish fixed- and variable-size kfunc mem args with MEM_FIXED_SIZE Amery Hung
2026-07-27 23:30 ` Eduard Zingerman
2026-07-24 19:08 ` [PATCH bpf-next v2 14/18] bpf: Check helper mem+size in ARG_PTR_TO_MEM case Amery Hung
2026-07-24 19:47 ` sashiko-bot
2026-07-24 21:10 ` Amery Hung
2026-07-27 23:39 ` Eduard Zingerman
2026-07-24 19:08 ` [PATCH bpf-next v2 15/18] bpf: Classify kfunc pointer arguments from BTF, resolve type against the register Amery Hung
2026-07-24 19:08 ` [PATCH bpf-next v2 16/18] bpf: Tag nullable kfunc pointer args with PTR_MAYBE_NULL Amery Hung
2026-07-24 19:38 ` sashiko-bot
2026-07-24 19:08 ` [PATCH bpf-next v2 17/18] bpf: Classify scalar kfunc arguments from BTF Amery Hung
2026-07-24 19:08 ` [PATCH bpf-next v2 18/18] bpf: Generate kfunc argument prototype at add-call time Amery Hung
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ea6041eda0af3980637490f08c97be2539f1ed33.camel@gmail.com \
--to=eddyz87@gmail.com \
--cc=alexei.starovoitov@gmail.com \
--cc=ameryhung@gmail.com \
--cc=andrii@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=kernel-team@meta.com \
--cc=memxor@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox