From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f170.google.com (mail-pf1-f170.google.com [209.85.210.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 68AC63A1D14 for ; Wed, 5 Aug 2026 23:41:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.170 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785973276; cv=none; b=a93Fk5eX5AOXBc+3lxOCdFXB7F1yeOiO2oPq8wFcd/PRDIgS8XYPXC9R2t2R/XYCwvE/RlQ3/kvwU1iZTb2GcTof/rAXt1hOWEmXKZcS+ySG7yPZ2RMSc9qdWulhP+gPdbDug21/VThovPIZG3orNkQYKGQowd8vGlVcDJu05xg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785973276; c=relaxed/simple; bh=Jis2S4tgjn6374XnFYCkZXB27nmh2T+Ik9kheVWfYjc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=JCgphVqSgXsZfcMFdJU9vRnzIEG4gomgG+78b9aMGI5dKh1LA/SDBSzKhcX3wxlPrIxUc7BEtGYboVW5Vkm/j7nPtg3I2Ge5Buw0zt7h5Df5k7GTiImZOJL2QHsft6k0hmfUbg6KE6aFHms5XLEdmvDQthfFO68sexMdP3BOTlQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=nvGZ9guY; arc=none smtp.client-ip=209.85.210.170 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="nvGZ9guY" Received: by mail-pf1-f170.google.com with SMTP id d2e1a72fcca58-8486ac3f347so432071b3a.1 for ; Wed, 05 Aug 2026 16:41:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785973275; x=1786578075; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=HrIf+Edn++d6wNFgJNuIXpHXoc2jM8IzZvutcAUZv5o=; b=nvGZ9guYBD0PSqSH357cUO0eeWmSyeU7nwpHa3Jz95zi/Cf6KVHMJK07FVZ9s9wZbK DJWmTAmYhhg0Lry5d/cgPHk3eITsGXs/qa+SxnZWcUzap75KnXKHPEq23cuUly3O0dbv B/W0z+KprfFbf1k4ZJmPkGey4YDnFLDUbUdcZkRqhmb33sYlgqyz4Wg9kmto+oqqeQnW Z5a+CgFpHRpu7uGr3XXCLioOjS+7Wxux8HAwO3RQoMY/TYaI2yVwpjW/ZY618WDKDORB T0/szcRyW+vn+1bZI4i2yfIUISOIh4M5UXjV7Wx2As6w+chg6cp8VtcgZdkz5Yf+dQiF Dvwg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785973275; x=1786578075; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=HrIf+Edn++d6wNFgJNuIXpHXoc2jM8IzZvutcAUZv5o=; b=VWJey8louCvLVoCKjop1eVDwD1emFlE/UTB2624xKDaLgxIBFLqUb9gLMPiFkdeBp0 cq81pDuTAGq55spwJJlMZtsTQxvQZCqN5sTpcNTnxieVZXR1yaufWhtoEH7DHVr8opjb vQLr2l+kR8ri+oPXhdu/jJSV+xxXv3m7b84qyIOTrP70v+VkkQrtQmUSFrj9YOs+vOxn uaDcEWn1MYZbHNM11ApHYw/cINeNYA7FlBY/qk3WhwhbVXzlvaKrjd8UrWG+Yeu1BWI5 eg1xZak9lsrk32PboyRf7Djbvrlm6bzWVQ03e7tHhVgcrGBbKU+ERIhKf/5hSH+FryX+ 5g4Q== X-Forwarded-Encrypted: i=1; AHgh+RrumM6bDY5DnhQZMx6qvdlVig59EWNaQ/49e3YODeexucZuJPi8S36e1LwgUaeiU+ZQQ05l6MrbgRSnuqs=@vger.kernel.org X-Gm-Message-State: AOJu0YxJZ31sVmbaJLJAb3KgjzXuGqH4b3zqv6+a/NZGhDLvBvtWJ4EX j3d90wVIWPlBYsH4stCLrwydwx0zZPrn7E9vRBHoHPImERlZHRiE9PYp X-Gm-Gg: AR+sD11T+RFNGotEVMGFryVhmTsY17MKHF2Vy8d06g1+bMcb6Dk6pnEY89KLfie9lS8 Jsy6Iv/QRP56mRWTJrniNddeuHnX98eCG1DpA8ww8FhE5G2CcGSvqtGzPx73rJJaZQudDalTpcz CGKxDmgRgg4CfQgzZZZQbnjpywoht/j65mVzeVmNBiuBCnbAIDCJtZLtMTXAQzsvWr7TGIijqT+ fqc4lQ0LuBFm95+Pn0nXzk5Obh5JV67o4VjpCfLJaw0JgeEErXZlyz01X1X/6/Z5G7yCiVbszat bu4789Qh2bSa+0vRvhu0LXAR6fTfR/hkLcWGqyQ7C4ex5LoqWuRVyG4PJATr6vrJ8qcOpI31FNL v65VcXW0Gmh0eKqJ5z/cPpZFyJYQgH9bZrkZN1RBwP8NyOl9dMsjDLMDNsKrUpzcrea2K0TMJho 632YYn4u1gLcUopoJK17HTwticQxtObStrdSfYBHOiOl32Sv8afPz7Zb+Swy8S49Cmu23wDsIsw yiy67xGgkZy9izQ X-Received: by 2002:a05:6a00:13a7:b0:84b:9a69:156d with SMTP id d2e1a72fcca58-84f47b4992cmr277476b3a.0.1785973274699; Wed, 05 Aug 2026 16:41:14 -0700 (PDT) Received: from patterson.cs.ubc.ca (patterson.cs.ubc.ca. [198.162.52.65]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84f45bc5696sm139516b3a.53.2026.08.05.16.41.13 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 05 Aug 2026 16:41:14 -0700 (PDT) From: Ning Ding To: bpf@vger.kernel.org Cc: memxor@gmail.com, puranjay@kernel.org, paulmck@kernel.org, Ning Ding , Alexei Starovoitov , Daniel Borkmann , John Fastabend , Andrii Nakryiko , Eduard Zingerman , Martin KaFai Lau , Song Liu , Yonghong Song , Jiri Olsa , Emil Tsalapatis , Ihor Solodrai , linux-kernel@vger.kernel.org Subject: [PATCH bpf-next 1/2] bpf: Account for preempt and IRQ state in RCU protection Date: Wed, 5 Aug 2026 16:39:33 -0700 Message-ID: <20260805233940.3966981-2-dingning04@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260805233940.3966981-1-dingning04@gmail.com> References: <20260805233940.3966981-1-dingning04@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Disabling preemption or local IRQs keeps the current CPU in an RCU read-side critical section, but in_rcu_cs() does not account for either state. The verifier therefore rejects safe kptr accesses and invalidates pointers when another RCU source ends. Include preemption-disabled and IRQ-disabled state in in_rcu_cs(). Invalidate RCU-protected pointers on RCU unlock, preempt enable, or IRQ restore only after the final protection ends. Signed-off-by: Ning Ding --- kernel/bpf/verifier.c | 13 ++++++++++--- 1 file changed, 10 insertions(+), 3 deletions(-) diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c index d925197c2e5f7..a1005783db300 100644 --- a/kernel/bpf/verifier.c +++ b/kernel/bpf/verifier.c @@ -4452,8 +4452,9 @@ static bool in_sleepable(struct bpf_verifier_env *env) static bool in_rcu_cs(struct bpf_verifier_env *env) { return env->cur_state->active_rcu_locks || - env->cur_state->active_locks || - !in_sleepable(env); + env->cur_state->active_irq_id || + env->cur_state->active_preempt_locks || + env->cur_state->active_locks || !in_sleepable(env); } /* Once GCC supports btf_type_tag the following mechanism will be replaced with tag check */ @@ -11663,6 +11664,9 @@ static int process_irq_flag(struct bpf_verifier_env *env, struct bpf_reg_state * err = unmark_stack_slot_irq_flag(env, reg, kfunc_class); if (err) return err; + + if (!in_rcu_cs(env)) + invalidate_rcu_protected_refs(env); } return 0; } @@ -13181,7 +13185,8 @@ static int check_kfunc_call(struct bpf_verifier_env *env, struct bpf_insn *insn, verbose(env, "unmatched rcu read unlock (kernel function %s)\n", func_name); return -EINVAL; } - if (--env->cur_state->active_rcu_locks == 0) + env->cur_state->active_rcu_locks--; + if (!in_rcu_cs(env)) invalidate_rcu_protected_refs(env); } else if (preempt_disable) { env->cur_state->active_preempt_locks++; @@ -13191,6 +13196,8 @@ static int check_kfunc_call(struct bpf_verifier_env *env, struct bpf_insn *insn, return -EINVAL; } env->cur_state->active_preempt_locks--; + if (!in_rcu_cs(env)) + invalidate_rcu_protected_refs(env); } if (sleepable && !in_sleepable_context(env)) { -- 2.43.0