BPF List
 help / color / mirror / Atom feed
* [PATCH bpf-next v4 0/2] bpf: Enforce trusted BTF ID argument provenance
@ 2026-10-07 16:25 Yiyang Chen
  2026-10-07 16:25 ` [PATCH bpf-next v4 1/2] " Yiyang Chen
  2026-10-07 16:25 ` [PATCH bpf-next v4 2/2] selftests/bpf: Cover " Yiyang Chen
  0 siblings, 2 replies; 6+ messages in thread
From: Yiyang Chen @ 2026-10-07 16:25 UTC (permalink / raw)
  To: Alexei Starovoitov, Daniel Borkmann, John Fastabend,
	Andrii Nakryiko, Eduard Zingerman, Kumar Kartikeya Dwivedi,
	Martin KaFai Lau, Song Liu, Yonghong Song, Jiri Olsa,
	Emil Tsalapatis, Ihor Solodrai, Shuah Khan
  Cc: bpf, linux-kernel, linux-kselftest, Amery Hung, Brahmajit Das,
	Yiyang Chen

A global subprogram parameter tagged __arg_trusted is verified with
PTR_TRUSTED, but its call-site type check also accepts bare PTR_TO_BTF_ID and
MEM_RCU registers. This lets a callee use a pointer with weaker provenance
under the trusted-pointer contract, including passing it to a non-KF_RCU
kfunc.

Encode the trusted-pointer requirement in generated kfunc prototypes and
drive the shared provenance check from the argument contract. A KF_RCU
kfunc additionally permits MEM_RCU, while a global __arg_trusted argument
requires a referenced or trusted pointer. Normalize nullability when the
argument contract permits it.

Add rejection coverage for bare and RCU-protected global-subprogram arguments
and acceptance coverage for a nullable kfunc receiving a trusted nullable
pointer.

A separate scx_cake caller fix has been prepared but is not yet submitted.
The current veristat-scx pin still uses the old caller, which this series
rejects.

Changes in v4:
- Rebase onto bpf-next and use the shared argument checker.
- Reject MEM_RCU for global __arg_trusted arguments.
- Encode trusted and KF_RCU provenance in generated kfunc prototypes.
- Add nullable-kfunc coverage and use a 12-character Fixes SHA.
- Link to v3: https://lore.kernel.org/r/20261006-a3-arg-trusted-v4-v3-0-4619daf30e1c@mails.tsinghua.edu.cn

Changes in v3:
- Preserve RCU-protected arguments accepted by existing sched-ext programs.
- Make the MEM_RCU case a positive regression test.
- Use the preferred multi-line comment style.
- Link to v2: https://lore.kernel.org/r/20261005-a3-arg-trusted-v4-v2-0-319ce2936949@mails.tsinghua.edu.cn

Changes in v2:
- Retarget the fix to btf_check_func_arg_match(), where the subprogram
  argument check lives in this tree, instead of check_func_arg().
- Run the check after check_reg_type() and check_func_arg_reg_off() so type
  and offset diagnostics keep their wording.

v1: https://lore.kernel.org/bpf/20261005-a3-arg-trusted-v4-v1-0-50ee0268fd39@mails.tsinghua.edu.cn/

---
Yiyang Chen (2):
      bpf: Enforce trusted BTF ID argument provenance
      selftests/bpf: Cover trusted BTF ID argument provenance

 kernel/bpf/verifier.c                              | 27 ++++++++++++-----
 tools/testing/selftests/bpf/progs/iters_testmod.c  | 11 +++++++
 .../selftests/bpf/progs/verifier_global_ptr_args.c | 35 ++++++++++++++++++++++
 .../testing/selftests/bpf/test_kmods/bpf_testmod.c | 11 +++++++
 .../selftests/bpf/test_kmods/bpf_testmod_kfunc.h   |  2 ++
 5 files changed, 79 insertions(+), 7 deletions(-)

base-commit: e1d84a37cba984388988d2f1ddc84561413f0db2
change-id: 20261005-a3-arg-trusted-v4-9d5d9485e5ba
-- 
Yiyang Chen <chenyy23@mails.tsinghua.edu.cn>


^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-10-07 22:30 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-07 16:25 [PATCH bpf-next v4 0/2] bpf: Enforce trusted BTF ID argument provenance Yiyang Chen
2026-10-07 16:25 ` [PATCH bpf-next v4 1/2] " Yiyang Chen
2026-10-07 16:43   ` sashiko-bot
2026-10-07 22:30   ` Amery Hung
2026-10-07 16:25 ` [PATCH bpf-next v4 2/2] selftests/bpf: Cover " Yiyang Chen
2026-10-07 22:24   ` Amery Hung

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox