* [PATCH] bpf/verifier: allow calling bpf_kptr_xchg while holding a lock
@ 2026-01-22 8:14 chengkaitao
2026-01-23 3:34 ` Alexei Starovoitov
0 siblings, 1 reply; 2+ messages in thread
From: chengkaitao @ 2026-01-22 8:14 UTC (permalink / raw)
To: ast, daniel, john.fastabend, andrii, martin.lau, eddyz87, song,
yonghong.song, kpsingh, sdf, haoluo, jolsa
Cc: bpf, linux-kernel, Chengkaitao
From: Chengkaitao <chengkaitao@kylinos.cn>
For the following scenario:
struct tree_node {
struct bpf_rb_node node;
struct request __kptr *req;
u64 key;
};
struct bpf_rb_root tree_root __contains(tree_node, node);
struct bpf_spin_lock tree_lock;
If we need to traverse all nodes in the rbtree, retrieve the __kptr
pointer from each node, and read kernel data from the referenced
object, using bpf_kptr_xchg appears unavoidable.
This patch skips the BPF verifier checks for bpf_kptr_xchg when
called while holding a lock.
Signed-off-by: Chengkaitao <chengkaitao@kylinos.cn>
---
kernel/bpf/verifier.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
index 3135643d5695..05a6a6606b6c 100644
--- a/kernel/bpf/verifier.c
+++ b/kernel/bpf/verifier.c
@@ -20387,7 +20387,8 @@ static int do_check_insn(struct bpf_verifier_env *env, bool *do_print_state)
if (env->cur_state->active_locks) {
if ((insn->src_reg == BPF_REG_0 &&
- insn->imm != BPF_FUNC_spin_unlock) ||
+ insn->imm != BPF_FUNC_spin_unlock &&
+ insn->imm != BPF_FUNC_kptr_xchg) ||
(insn->src_reg == BPF_PSEUDO_KFUNC_CALL &&
(insn->off != 0 || !kfunc_spin_allowed(insn->imm)))) {
verbose(env,
--
2.50.1 (Apple Git-155)
^ permalink raw reply [flat|nested] 2+ messages in thread* Re: [PATCH] bpf/verifier: allow calling bpf_kptr_xchg while holding a lock
2026-01-22 8:14 [PATCH] bpf/verifier: allow calling bpf_kptr_xchg while holding a lock chengkaitao
@ 2026-01-23 3:34 ` Alexei Starovoitov
0 siblings, 0 replies; 2+ messages in thread
From: Alexei Starovoitov @ 2026-01-23 3:34 UTC (permalink / raw)
To: chengkaitao
Cc: Alexei Starovoitov, Daniel Borkmann, John Fastabend,
Andrii Nakryiko, Martin KaFai Lau, Eduard, Song Liu,
Yonghong Song, KP Singh, Stanislav Fomichev, Hao Luo, Jiri Olsa,
bpf, LKML, Chengkaitao
On Thu, Jan 22, 2026 at 12:14 AM chengkaitao <pilgrimtao@gmail.com> wrote:
>
> From: Chengkaitao <chengkaitao@kylinos.cn>
>
> For the following scenario:
> struct tree_node {
> struct bpf_rb_node node;
> struct request __kptr *req;
> u64 key;
> };
> struct bpf_rb_root tree_root __contains(tree_node, node);
> struct bpf_spin_lock tree_lock;
>
> If we need to traverse all nodes in the rbtree, retrieve the __kptr
> pointer from each node, and read kernel data from the referenced
> object, using bpf_kptr_xchg appears unavoidable.
>
> This patch skips the BPF verifier checks for bpf_kptr_xchg when
> called while holding a lock.
>
> Signed-off-by: Chengkaitao <chengkaitao@kylinos.cn>
The idea of the patch makes sense, but selftests is required
and you have to use proper full name in SOB.
pw-bot: cr
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-01-23 3:34 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-01-22 8:14 [PATCH] bpf/verifier: allow calling bpf_kptr_xchg while holding a lock chengkaitao
2026-01-23 3:34 ` Alexei Starovoitov
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®