From: bot+bpf-ci@kernel.org
To: wangqing7171@gmail.com,ast@kernel.org,daniel@iogearbox.net,john.fastabend@gmail.com,andrii@kernel.org,martin.lau@linux.dev,eddyz87@gmail.com,song@kernel.org,yonghong.song@linux.dev,kpsingh@kernel.org,sdf@fomichev.me,haoluo@google.com,jolsa@kernel.org
Cc: bpf@vger.kernel.org,linux-kernel@vger.kernel.org,wangqing7171@gmail.com,syzbot+b4c5ad098c821bf8d8bc@syzkaller.appspotmail.com,ast@kernel.org,andrii@kernel.org,daniel@iogearbox.net,martin.lau@kernel.org,eddyz87@gmail.com,yonghong.song@linux.dev,clm@meta.com,ihor.solodrai@linux.dev
Subject: Re: [PATCH] bpf: Fix use-after-free in __bpf_trace_run()
Date: Wed, 4 Mar 2026 07:54:41 +0000 (UTC) [thread overview]
Message-ID: <1c92317f67a41ca1ea84e2cd52cd276f8e3c63be7b128b42564bbef4b427e4a6@mail.kernel.org> (raw)
In-Reply-To: <20260304070927.178464-1-wangqing7171@gmail.com>
[-- Attachment #1: Type: text/plain, Size: 2316 bytes --]
> Fix by calling tracepoint_synchronize_unregister() to ensure tp_probes
> is freed before allowing the link to be freed.
tracepoint_synchronize_unregister() calls synchronize_rcu_tasks_trace()
and synchronize_srcu(&tracepoint_srcu), which wait for in-flight
readers to complete. They do not ensure that call_srcu() or
call_rcu_tasks_trace() callbacks (the ones that actually kfree
tp_probes in rcu_free_old_probes()) have been invoked -- that
would require srcu_barrier()/rcu_barrier().
The fix is correct because after tracepoint_synchronize_unregister()
returns, no tracepoint callback can still be executing with a reference
to the link through the old tp_probes array. Would it be more precise
to say the synchronization ensures all in-flight tracepoint callbacks
have completed, rather than that tp_probes is freed?
> The link(struct bpf_raw_tp_link) was freed when link->link.prog.
This sentence is difficult to parse. Perhaps something like "The
link (struct bpf_raw_tp_link) was freed before accessing
link->link.prog"?
> diff --git a/kernel/bpf/syscall.c b/kernel/bpf/syscall.c
> index 274039e36465..b179e96ebf2b 100644
> --- a/kernel/bpf/syscall.c
> +++ b/kernel/bpf/syscall.c
> @@ -3783,6 +3783,12 @@ static void bpf_raw_tp_link_release(struct bpf_link *link)
>
> bpf_probe_unregister(raw_tp->btp, raw_tp);
> bpf_put_raw_tracepoint(raw_tp->btp);
> +
> + /*
> + * Ensure tp_probes is freed before the link. This prevents
> + * use-after-free in __bpf_trace_run() when a tracepoint fires.
> + */
Same observation as above about the commit message. The comment says
"Ensure tp_probes is freed before the link" but
tracepoint_synchronize_unregister() ensures all in-flight tracepoint
callbacks have completed, not that the tp_probes freeing callback
has run. The UAF prevention comes from readers finishing, not from
a freeing order.
Something like "Wait for all in-flight tracepoint callbacks to
complete so the link is no longer reachable through tp_probes" would
more accurately describe the guarantee.
> + tracepoint_synchronize_unregister();
> }
---
AI reviewed your patch. Please fix the bug or email reply why it's not a bug.
See: https://github.com/kernel-patches/vmtest/blob/master/ci/claude/README.md
CI run summary: https://github.com/kernel-patches/bpf/actions/runs/22659523367
prev parent reply other threads:[~2026-03-04 7:54 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-03-04 7:09 Qing Wang
2026-03-04 7:54 ` bot+bpf-ci [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1c92317f67a41ca1ea84e2cd52cd276f8e3c63be7b128b42564bbef4b427e4a6@mail.kernel.org \
--to=bot+bpf-ci@kernel.org \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=clm@meta.com \
--cc=daniel@iogearbox.net \
--cc=eddyz87@gmail.com \
--cc=haoluo@google.com \
--cc=ihor.solodrai@linux.dev \
--cc=john.fastabend@gmail.com \
--cc=jolsa@kernel.org \
--cc=kpsingh@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=martin.lau@kernel.org \
--cc=martin.lau@linux.dev \
--cc=sdf@fomichev.me \
--cc=song@kernel.org \
--cc=syzbot+b4c5ad098c821bf8d8bc@syzkaller.appspotmail.com \
--cc=wangqing7171@gmail.com \
--cc=yonghong.song@linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®