* [PATCH bpf-next v3 0/2] bpf: Fix sleepable check for tracing prog
@ 2026-08-04 14:57 Leon Hwang
2026-08-04 14:57 ` [PATCH bpf-next v3 1/2] " Leon Hwang
0 siblings, 1 reply; 4+ messages in thread
From: Leon Hwang @ 2026-08-04 14:57 UTC (permalink / raw)
To: bpf
Cc: Alexei Starovoitov, Daniel Borkmann, John Fastabend,
Andrii Nakryiko, Eduard Zingerman, Kumar Kartikeya Dwivedi,
Martin KaFai Lau, Song Liu, Yonghong Song, Jiri Olsa,
Emil Tsalapatis, Ihor Solodrai, Shuah Khan, Sechang Lim,
Varun R Mallya, Leon Hwang, Viktor Malik, linux-kernel,
linux-kselftest, netdev
When CONFIG_FUNCTION_ERROR_INJECTION is disabled, a sleepable tracing prog
is allowed to attach to '__x64_'-alike prefix symbols.
It is because the verifier does not verify whether the symbol is a kernel
function or a bpf prog. That said, a sleepable tracing prog is allowed to
attach to a bpf prog target whose name has '__x64_'-alike prefix.
For example, a sleepable fentry prog attaches to a '__x64_sys_nop' XDP
prog, and copies buffer from a user pointer with bpf_copy_from_user()
helper. After attaching the XDP prog to lo interface, the kernel BUG
could be triggered by 'ping -c 1 -W 1 127.0.0.1':
[ 3.460756] BUG: sleeping function called from invalid context at kernel/bpf/trampoline.c:1324
Fix it by disallowing sleepable tracing prog always when its target btf
is not kernel's btf.
Changes:
v2 -> v3:
* Use btf_is_kernel() instead of passing 'tgt_prog'. (per Andrii)
* v2: https://lore.kernel.org/bpf/20260725132624.78373-1-leon.hwang@linux.dev/
v1 -> v2:
* Drop redundant 'prog->sleepable' check. (per Viktor)
* Collect Acked-by from Viktor, Thanks.
* v1: https://lore.kernel.org/bpf/20260724141422.10463-1-leon.hwang@linux.dev/
Leon Hwang (2):
bpf: Fix sleepable check for tracing prog
selftests/bpf: Verify rejection of sleepable tracing prog
kernel/bpf/verifier.c | 3 +
.../selftests/bpf/prog_tests/fexit_bpf2bpf.c | 57 +++++++++++++++++++
.../selftests/bpf/progs/fentry_sleepable.c | 18 ++++++
tools/testing/selftests/bpf/progs/xdp_dummy.c | 6 ++
4 files changed, 84 insertions(+)
create mode 100644 tools/testing/selftests/bpf/progs/fentry_sleepable.c
--
2.55.0
^ permalink raw reply [flat|nested] 4+ messages in thread
* [PATCH bpf-next v3 1/2] bpf: Fix sleepable check for tracing prog
2026-08-04 14:57 [PATCH bpf-next v3 0/2] bpf: Fix sleepable check for tracing prog Leon Hwang
@ 2026-08-04 14:57 ` Leon Hwang
2026-08-04 23:39 ` Andrii Nakryiko
0 siblings, 1 reply; 4+ messages in thread
From: Leon Hwang @ 2026-08-04 14:57 UTC (permalink / raw)
To: bpf
Cc: Alexei Starovoitov, Daniel Borkmann, John Fastabend,
Andrii Nakryiko, Eduard Zingerman, Kumar Kartikeya Dwivedi,
Martin KaFai Lau, Song Liu, Yonghong Song, Jiri Olsa,
Emil Tsalapatis, Ihor Solodrai, Shuah Khan, Sechang Lim,
Varun R Mallya, Leon Hwang, Viktor Malik, linux-kernel,
linux-kselftest, netdev
When CONFIG_FUNCTION_ERROR_INJECTION is disabled, a sleepable tracing prog
is allowed to attach to '__x64_'-alike prefix symbols.
It is because the verifier does not verify whether the symbol is a kernel
function or a bpf prog. That said, a sleepable tracing prog is allowed to
attach to a bpf prog target whose name has '__x64_'-alike prefix.
For example, a sleepable fentry prog attaches to a '__x64_sys_nop' XDP
prog, and copies buffer from a user pointer with bpf_copy_from_user()
helper. After attaching the XDP prog to lo interface, the kernel BUG
could be triggered by 'ping -c 1 -W 1 127.0.0.1':
[ 3.460756] BUG: sleeping function called from invalid context at kernel/bpf/trampoline.c:1324
Fix it by disallowing sleepable tracing prog always when its target btf
is not kernel's btf.
Fixes: 16d9c5660692 ("bpf: Always allow sleepable programs on syscalls")
Acked-by: Viktor Malik <vmalik@redhat.com>
Signed-off-by: Leon Hwang <leon.hwang@linux.dev>
---
kernel/bpf/verifier.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
index b274004fccfd..7bb541e343b2 100644
--- a/kernel/bpf/verifier.c
+++ b/kernel/bpf/verifier.c
@@ -19019,6 +19019,9 @@ static int btf_id_allow_sleepable(u32 btf_id, unsigned long addr, const struct b
switch (prog->type) {
case BPF_PROG_TYPE_TRACING:
+ if (!btf_is_kernel(btf))
+ return -EINVAL;
+
t = btf_type_by_id(btf, btf_id);
if (!t)
return -EINVAL;
--
2.55.0
^ permalink raw reply related [flat|nested] 4+ messages in thread* Re: [PATCH bpf-next v3 1/2] bpf: Fix sleepable check for tracing prog
2026-08-04 14:57 ` [PATCH bpf-next v3 1/2] " Leon Hwang
@ 2026-08-04 23:39 ` Andrii Nakryiko
2026-08-05 1:52 ` Leon Hwang
0 siblings, 1 reply; 4+ messages in thread
From: Andrii Nakryiko @ 2026-08-04 23:39 UTC (permalink / raw)
To: Leon Hwang
Cc: bpf, Alexei Starovoitov, Daniel Borkmann, John Fastabend,
Andrii Nakryiko, Eduard Zingerman, Kumar Kartikeya Dwivedi,
Martin KaFai Lau, Song Liu, Yonghong Song, Jiri Olsa,
Emil Tsalapatis, Ihor Solodrai, Shuah Khan, Sechang Lim,
Varun R Mallya, Viktor Malik, linux-kernel, linux-kselftest,
netdev
On Tue, Aug 4, 2026 at 7:57 AM Leon Hwang <leon.hwang@linux.dev> wrote:
>
> When CONFIG_FUNCTION_ERROR_INJECTION is disabled, a sleepable tracing prog
> is allowed to attach to '__x64_'-alike prefix symbols.
>
> It is because the verifier does not verify whether the symbol is a kernel
> function or a bpf prog. That said, a sleepable tracing prog is allowed to
> attach to a bpf prog target whose name has '__x64_'-alike prefix.
>
> For example, a sleepable fentry prog attaches to a '__x64_sys_nop' XDP
> prog, and copies buffer from a user pointer with bpf_copy_from_user()
> helper. After attaching the XDP prog to lo interface, the kernel BUG
> could be triggered by 'ping -c 1 -W 1 127.0.0.1':
>
> [ 3.460756] BUG: sleeping function called from invalid context at kernel/bpf/trampoline.c:1324
>
> Fix it by disallowing sleepable tracing prog always when its target btf
> is not kernel's btf.
>
> Fixes: 16d9c5660692 ("bpf: Always allow sleepable programs on syscalls")
> Acked-by: Viktor Malik <vmalik@redhat.com>
> Signed-off-by: Leon Hwang <leon.hwang@linux.dev>
> ---
> kernel/bpf/verifier.c | 3 +++
> 1 file changed, 3 insertions(+)
>
> diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
> index b274004fccfd..7bb541e343b2 100644
> --- a/kernel/bpf/verifier.c
> +++ b/kernel/bpf/verifier.c
> @@ -19019,6 +19019,9 @@ static int btf_id_allow_sleepable(u32 btf_id, unsigned long addr, const struct b
>
> switch (prog->type) {
> case BPF_PROG_TYPE_TRACING:
> + if (!btf_is_kernel(btf))
> + return -EINVAL;
> +
see sashiko reply, just move it outside of switch and disallow
sleepable for anything that is not kernel/module BTF, regardless of
program type
pw-bot: cr
> t = btf_type_by_id(btf, btf_id);
> if (!t)
> return -EINVAL;
> --
> 2.55.0
>
^ permalink raw reply [flat|nested] 4+ messages in thread* Re: [PATCH bpf-next v3 1/2] bpf: Fix sleepable check for tracing prog
2026-08-04 23:39 ` Andrii Nakryiko
@ 2026-08-05 1:52 ` Leon Hwang
0 siblings, 0 replies; 4+ messages in thread
From: Leon Hwang @ 2026-08-05 1:52 UTC (permalink / raw)
To: Andrii Nakryiko
Cc: bpf, Alexei Starovoitov, Daniel Borkmann, John Fastabend,
Andrii Nakryiko, Eduard Zingerman, Kumar Kartikeya Dwivedi,
Martin KaFai Lau, Song Liu, Yonghong Song, Jiri Olsa,
Emil Tsalapatis, Ihor Solodrai, Shuah Khan, Sechang Lim,
Varun R Mallya, Viktor Malik, linux-kernel, linux-kselftest,
netdev
On 5/8/26 07:39, Andrii Nakryiko wrote:
> On Tue, Aug 4, 2026 at 7:57 AM Leon Hwang <leon.hwang@linux.dev> wrote:
[...]
>> diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
>> index b274004fccfd..7bb541e343b2 100644
>> --- a/kernel/bpf/verifier.c
>> +++ b/kernel/bpf/verifier.c
>> @@ -19019,6 +19019,9 @@ static int btf_id_allow_sleepable(u32 btf_id, unsigned long addr, const struct b
>>
>> switch (prog->type) {
>> case BPF_PROG_TYPE_TRACING:
>> + if (!btf_is_kernel(btf))
>> + return -EINVAL;
>> +
>
> see sashiko reply, just move it outside of switch and disallow
> sleepable for anything that is not kernel/module BTF, regardless of
> program type
>
Ack.
I think another Fixes tag is needed for the LSM case.
Thanks,
Leon
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-08-05 1:53 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-04 14:57 [PATCH bpf-next v3 0/2] bpf: Fix sleepable check for tracing prog Leon Hwang
2026-08-04 14:57 ` [PATCH bpf-next v3 1/2] " Leon Hwang
2026-08-04 23:39 ` Andrii Nakryiko
2026-08-05 1:52 ` Leon Hwang
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox