From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-ej1-f49.google.com (mail-ej1-f49.google.com [209.85.218.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B8A6B3161AB for ; Wed, 7 Jan 2026 09:29:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.218.49 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1767778165; cv=none; b=ARLu4yREB7iI/2v/nN4w+O1gyj707w4SasY/9paT8PAFGtsUahY1IF77d8DHwXys2zBzCT/X08/DKiDMQ82hkKmAWUdD8fiSeFuRExQCFPPzXlztM2m5X67pwd4w86kUSy90umnqok08H7B+YSGgh/LNzQHza2PIS/prvi2laek= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1767778165; c=relaxed/simple; bh=2lLk2OnF51neQ23htcb5Tc9D7Pjc7rtydCq04TCve7c=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=ctESemzfvn894/4Zc3LTTH3VlZhRMs6C2p21vp0UO+Iz2DB0V9YBq/aNIuEW/HVDdQ0dS1MQredSxJ97bBDQIUgknBUHN+WKVCq9O+hpg9vfYBKu+/CnEoKmr6PcJS7mxZYDQA4oFG5bY69zBroHMFpMZ+O0icg2wQT1aZfSkFA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=a1eyvgy4; arc=none smtp.client-ip=209.85.218.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="a1eyvgy4" Received: by mail-ej1-f49.google.com with SMTP id a640c23a62f3a-b7277324204so296367066b.0 for ; Wed, 07 Jan 2026 01:29:23 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1767778162; x=1768382962; darn=vger.kernel.org; h=in-reply-to:content-transfer-encoding:content-disposition :mime-version:references:message-id:subject:cc:to:from:date:from:to :cc:subject:date:message-id:reply-to; bh=qAmBFvHljQCF3L3oXr+WZULma4DAz/lJTXBequgmr24=; b=a1eyvgy4fNsijNJupgIOWUWgBjJwmLpNrSZPp7emXiqaeADTp5vxwfh8EbcTHFUSC0 B3JvPm5RsOs1ZgnfjbBVLCXoPygyVgXo5ynyyv2+RK9l9ByYgXb6r9ZQYpvzTIA5Ja8X T97Ws0093jMXNXdBH0TMsTKYvUhWcpRhj1EqoGgDtOt8W4R0pwvSwVFenLfHy3VNsvSB TpHgCDMjlqmouTvSST3vyCf/KNcXOeBcf37BF8/nahCzY1MKoiiCS2oNwh08QvwtnWnH UczWgbmdurWlRVBOKdCH5jC5gHYSfgT1RCec4co28rTCYMSgv2mXNAWe7DGMKlv7Xak/ Qpdg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1767778162; x=1768382962; h=in-reply-to:content-transfer-encoding:content-disposition :mime-version:references:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=qAmBFvHljQCF3L3oXr+WZULma4DAz/lJTXBequgmr24=; b=d1D4tDVL5xKNlQfzTtCT0+L0OiZgL7mfsQ1JjCqY58Vu8CiLsAMVqYEZfz1YH0lr90 tWwKkdWlrxRPyHnWRCa13l61PqV/nYi5CZ533eYuNINRNdzN8b7rn04zfCicov4Guo4i h5jfNVgd5noHmfb/OZCrsY0P6cEZ93XNC7q9VhqU8qxdD+ovpmYm0WJpEQbDRfyPx0Wz 77DBRh+PilRTLljrXG9EGbfwJeFBH4SXhG7Bd+MzJFHgGUo59m54ofCLBT82XvBc3xe4 RTrec+prRPlZulaTrXCRwb2T/r8H4J/iK2MZlGKhCCmmODiIHztEvA56tZP6Vx8mAAVK 0f6Q== X-Forwarded-Encrypted: i=1; AJvYcCUQ/pArn+qiZXCI0N32USmxCBj2tpqAaJGo6PLG3sLyvGJ3YeRUwZsDqT/5DlEnWQHCSvYk1VCo573Vyl4=@vger.kernel.org X-Gm-Message-State: AOJu0YwUsbVcuvBh8B7GfmIBwX9jYIYmu/nhA9cU7g0K9J9ATzp7fM4w FUSb+/UxzSo+vn0MV/KO2yx1TJWGgPcYzehlg2oWLAE2A3fikhUf6FOH95sBLlU+mA== X-Gm-Gg: AY/fxX5L4Q1iMAO3xnVShMwu2gXLwJHpsj0f5TE5WQC0eGmcBHo+OfrXoBC0Sbw43TG Lg3rFCWid/JZ3kgxIEmugBAC4tAJB06wYgBvjul5Pg6grutLAyG9d5sNT4E6XAQzr67HxOM/OFv /5KDb9o2sXodOHf6yKC25tnyUH2/OxU8UPZCKLgayFs+f+GK4gdizcnwZuJCEGTEgU/BwMtJnL8 3aMNlMHGO+lXO+6Z3NyvxhLUevI+i3P9upCPR6wwk4yHLuWobDa9ZHDTLicyAoxmxXTLpk+bAsj lFKbUSt4J8banoLbf+2bgDYCf9kABxetHgMc9ssY6HI5SSPsa9mrtdoppPNRRmP4T+eub/FN2tX iu4FZ+otFImmvW7PL09mFylKybXJwZSry7Wy/1sM2LHmLSQVs6sBbhQsQW+a9oJZPFrK3tXlQaK v0dWZQBr2N4vzXuSkN7yNnzPNHo7bo5q/zjRs1u/450V2+yVi6hL0ULA== X-Google-Smtp-Source: AGHT+IEZ569HZDlJCwAETH6UvXRvz+tkMRRxeKTBnNpUb4XcosV6KbxuzsGMXy5rQgg3tcmEAr8VOQ== X-Received: by 2002:a17:907:cd0e:b0:b73:5b9a:47c7 with SMTP id a640c23a62f3a-b8445413775mr187603266b.51.1767778161682; Wed, 07 Jan 2026 01:29:21 -0800 (PST) Received: from google.com (14.59.147.34.bc.googleusercontent.com. [34.147.59.14]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-b842a4cfd97sm444211066b.36.2026.01.07.01.29.20 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 07 Jan 2026 01:29:21 -0800 (PST) Date: Wed, 7 Jan 2026 09:29:16 +0000 From: Matt Bobrowski To: Kumar Kartikeya Dwivedi , g@google.com Cc: Alexei Starovoitov , Tejun Heo , Roman Gushchin , bpf , linux-mm , LKML , JP Kobryn , Alexei Starovoitov , Daniel Borkmann , Shakeel Butt , Michal Hocko , Johannes Weiner Subject: Re: [PATCH bpf-next v4 3/6] mm: introduce bpf_get_root_mem_cgroup() BPF kfunc Message-ID: References: <20251223044156.208250-1-roman.gushchin@linux.dev> <20251223044156.208250-4-roman.gushchin@linux.dev> <7ia4ms2zwuqb.fsf@castle.c.googlers.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: On Tue, Jan 06, 2026 at 04:13:24PM +0100, Kumar Kartikeya Dwivedi wrote: > On Mon, 5 Jan 2026 at 22:04, Matt Bobrowski wrote: > > > > On Mon, Jan 05, 2026 at 08:05:54AM -0800, Alexei Starovoitov wrote: > > > On Sun, Jan 4, 2026 at 11:49 PM Matt Bobrowski wrote: > > > > > > > > > > > > > > No need for a new KF flag. Any struct returned by kfunc should be > > > > > trusted or trusted_or_null if KF_RET_NULL was specified. > > > > > I don't remember off the top of my head, but this behavior > > > > > is already implemented or we discussed making it this way. > > > > > > > > Hm, I do not see any evidence of this kind of semantic currently > > > > implemented, so perhaps it was only discussed at some point. Would you > > > > like me to put forward a patch that introduces this kind of implicit > > > > trust semantic for BPF kfuncs returning pointer to struct types? > > > > > > Hmm. What about these: > > > BTF_ID_FLAGS(func, scx_bpf_cpu_rq) > > > BTF_ID_FLAGS(func, scx_bpf_locked_rq, KF_RET_NULL) > > > BTF_ID_FLAGS(func, scx_bpf_cpu_curr, KF_RET_NULL | KF_RCU_PROTECTED) > > > > > > I thought they're returning a trusted pointer without acquiring it. > > > iirc the last one returns trusted in RCU CS, > > > but the first two return just a legacy ptr_to_btf_id ? > > > This is something to fix asap then. > > > > No, AFAIU they do not. These simply return a regular pointer to BTF ID > > (PTR_TO_BTF_ID), rather than a formally "trusted" pointer (which would > > carry the PTR_TRUSTED flag or a ref_obj_id). scx_bpf_cpu_curr returns > > a MEM_RCU pointer (via KF_RCU_PROTECTED), which is somewhat considered > > to be trusted within a RCU read-side critical section *ONLY*. > > > > Kumar/Tejun, > > Yeah, they don't return a trusted pointer. I think it would make sense > to change the behavior here by default. Thanks for chiming in and confirming this Kumar! I also agree that any BPF kfunc returning a pointer should be treated as being implicitly trusted by default. I can't think of any scenario whereby a BPF kfunc would want to return a pointer that'd fundamentally be untrusted, but there always could be some exceptions. Anyway, I will work on this and send something through for review soon. > A non-trusted pointer cannot be passed to kfuncs taking trusted > arguments, so hopefully it will only make things more permissive and > doesn't break anything. We can only hope! ;)