From: sashiko-bot@kernel.org
To: "Jay Wang" <wanjay@amazon.com>
Cc: "Petr Pavlu" <petr.pavlu@suse.com>,
linux-trace-kernel@vger.kernel.org, sched-ext@lists.linux.dev,
bpf@vger.kernel.org, linux-input@vger.kernel.org,
dmitry.torokhov@gmail.com, linux-modules@vger.kernel.org,
linux-perf-users@vger.kernel.org, ojeda@kernel.org,
gary@garyguo.net
Subject: Re: [PATCH bpf-next v4 12/12] kbuild, bpf: allow building the vmlinux BTF as a module
Date: Fri, 02 Oct 2026 09:14:17 +0000 [thread overview]
Message-ID: <20261002091417.8DFF81F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20261001225214.12351-13-wanjay@amazon.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] bpf: unprivileged local DoS via infinite request_module() spam
--
commit 83161d8b7e8e5c9b7cb283e38033cefcc6cf4b26
Author: Jay Wang <wanjay@amazon.com>
kbuild, bpf: allow building the vmlinux BTF as a module
Make CONFIG_DEBUG_INFO_BTF a tristate. With =m the vmlinux BTF is not
part of the kernel image: it is carried by a new module, btf_vmlinux, and
loaded the first time user space asks for something that needs it.
Otherwise it behaves as with =y, with the exceptions btf.rst lists.
> diff --git a/Documentation/bpf/btf.rst b/Documentation/bpf/btf.rst
> index 29de1222c3e73..7d44374b67ba0 100644
> --- a/Documentation/bpf/btf.rst
> +++ b/Documentation/bpf/btf.rst
> @@ -1276,6 +1276,74 @@ format.::
> .long 58
> .long 8206 # Line 8 Col 14
>
> +6.1 Kernel BTF
> +--------------
> +
> +With CONFIG_DEBUG_INFO_BTF=y the BTF of the kernel is generated at link time
> +from its DWARF and placed in the .BTF section of vmlinux, which is read-only
> +data of the kernel image. It is available as /sys/kernel/btf/vmlinux and, if
> +CONFIG_DEBUG_INFO_BTF_MODULES is set, module BTF is generated as split BTF
> +against it and available as /sys/kernel/btf/<module>.
> +
> +With CONFIG_DEBUG_INFO_BTF=m the same BTF is generated, but it is not part of
> +the kernel image or of the vmlinux ELF file (vmlinux.unstripped in the build
> +tree keeps it, for module BTF generation). It is delivered by the
> +btf_vmlinux module, which the kernel loads the first time user space asks for
> +something that needs the BTF: reading /sys/kernel/btf/vmlinux, enumerating
[Severity: High]
Does this allow an unprivileged local denial of service through infinite
request_module() spam?
If the btf_vmlinux module is missing or fails to load, reading the
world-readable (0444) /sys/kernel/btf/vmlinux sysfs file will continually
trigger request_module() errors.
Since the failure is intentionally not cached:
kernel/bpf/sysfs_btf.c:btf_sysfs_vmlinux_read() {
...
void *data = btf_sysfs_vmlinux_load(&size);
...
}
kernel/bpf/btf.c:btf_vmlinux_data() {
...
request_module("%s", btf_vmlinux_link.module_name);
...
}
Can an unprivileged user loop read() syscalls on this file, bypass the
kmod_concurrent_max limit over time, or sequentially spawn modprobe usermode
helpers thousands of times per second, leading to a CPU/fork bomb effect?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261001225214.12351-1-wanjay@amazon.com?part=12
next prev parent reply other threads:[~2026-10-02 9:14 UTC|newest]
Thread overview: 41+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-01 22:52 [PATCH bpf-next v4 00/12] bpf: make the vmlinux BTF an on-demand loadable module (CONFIG_DEBUG_INFO_BTF=m) to save ~5.4 MB memory Jay Wang
2026-10-01 22:52 ` [PATCH bpf-next v4 01/12] bpf: pass the vmlinux BTF to btf_parse_module() and let it adopt the data Jay Wang
2026-10-02 9:14 ` sashiko-bot
2026-10-01 22:52 ` [PATCH bpf-next v4 02/12] bpf: split the kfunc, dtor kfunc and struct_ops registration bodies Jay Wang
2026-10-02 9:14 ` sashiko-bot
2026-10-01 22:52 ` [PATCH bpf-next v4 03/12] bpf: fetch the vmlinux BTF where kernel types enter a program Jay Wang
2026-10-02 9:14 ` sashiko-bot
2026-10-01 22:52 ` [PATCH bpf-next v4 04/12] bpf: take the vmlinux BTF from the btf_vmlinux module Jay Wang
2026-10-01 23:45 ` bot+bpf-ci
2026-10-02 9:14 ` sashiko-bot
2026-10-02 11:48 ` Alexei Starovoitov
2026-10-01 22:52 ` [PATCH bpf-next v4 05/12] bpf, tracing: load the vmlinux BTF where tracefs and bpffs requests start Jay Wang
2026-10-02 9:14 ` sashiko-bot
2026-10-01 22:52 ` [PATCH bpf-next v4 06/12] bpf: defer vmlinux kfunc and struct_ops registrations Jay Wang
2026-10-02 9:14 ` sashiko-bot
2026-10-01 22:52 ` [PATCH bpf-next v4 07/12] bpf: keep module BTF until the vmlinux BTF is available Jay Wang
2026-10-01 23:45 ` bot+bpf-ci
2026-10-02 9:14 ` sashiko-bot
2026-10-01 22:52 ` [PATCH bpf-next v4 08/12] bpf: expose deferred .BTF.base module BTF in sysfs from module load Jay Wang
2026-10-02 9:14 ` sashiko-bot
2026-10-01 22:52 ` [PATCH bpf-next v4 09/12] bpf, trace, net: prepare CONFIG_DEBUG_INFO_BTF checks for a tristate Jay Wang
2026-10-02 9:14 ` sashiko-bot
2026-10-05 11:32 ` Nicolas Schier
2026-10-01 22:52 ` [PATCH bpf-next v4 10/12] resolve_btfids: add --btf_link to fill in .BTF.link records Jay Wang
2026-10-01 23:29 ` bot+bpf-ci
2026-10-02 9:14 ` sashiko-bot
2026-10-01 22:52 ` [PATCH bpf-next v4 11/12] tools, samples: take the vmlinux BTF from vmlinux.unstripped first Jay Wang
2026-10-02 9:14 ` sashiko-bot
2026-10-05 11:17 ` Nicolas Schier
2026-10-01 22:52 ` [PATCH bpf-next v4 12/12] kbuild, bpf: allow building the vmlinux BTF as a module Jay Wang
2026-10-02 9:14 ` sashiko-bot [this message]
2026-10-02 9:47 ` Alan Maguire
2026-10-02 4:36 ` [PATCH bpf-next v4 00/12] bpf: make the vmlinux BTF an on-demand loadable module (CONFIG_DEBUG_INFO_BTF=m) to save ~5.4 MB memory Ihor Solodrai
2026-10-02 7:34 ` Jay Wang
2026-10-02 10:05 ` Alan Maguire
2026-10-02 20:58 ` Ihor Solodrai
2026-10-03 6:38 ` Alexei Starovoitov
2026-10-03 11:45 ` Alan Maguire
2026-10-03 12:19 ` Alexei Starovoitov
2026-10-04 22:21 ` Jay Wang
2026-10-05 19:01 ` Ihor Solodrai
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261002091417.8DFF81F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=dmitry.torokhov@gmail.com \
--cc=gary@garyguo.net \
--cc=linux-input@vger.kernel.org \
--cc=linux-modules@vger.kernel.org \
--cc=linux-perf-users@vger.kernel.org \
--cc=linux-trace-kernel@vger.kernel.org \
--cc=ojeda@kernel.org \
--cc=petr.pavlu@suse.com \
--cc=sashiko-reviews@lists.linux.dev \
--cc=sched-ext@lists.linux.dev \
--cc=wanjay@amazon.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox