mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH bpf-next v2 0/2] libbpf: Fix struct and union zero detection in BTF dumper
@ 2026-10-01  3:42 Luis Vieira
  2026-10-01  3:42 ` [PATCH bpf-next v2 1/2] " Luis Vieira
  2026-10-01  3:42 ` [PATCH bpf-next v2 2/2] selftests/bpf: Add regression test for BTF dump zero detection Luis Vieira
  0 siblings, 2 replies; 4+ messages in thread
From: Luis Vieira @ 2026-10-01  3:42 UTC (permalink / raw)
  To: Andrii Nakryiko, Eduard Zingerman, Ihor Solodrai,
	Alexei Starovoitov, Daniel Borkmann, Kumar Kartikeya Dwivedi,
	Martin KaFai Lau, Song Liu, Yonghong Song, Jiri Olsa,
	Emil Tsalapatis, Shuah Khan
  Cc: bpf, linux-kernel, linux-kselftest, Luis Vieira

Fix struct and union zero detection in the BTF dumper and add the
regression coverage in a separate selftest patch.

Changes in v2:
- Split the regression selftest into a separate patch, as requested by
  Andrii Nakryiko.
- Link to v1:
  https://patch.msgid.link/20260928-libbpf-btf-enodata-fix-v1-1-56dae4cab778@gmail.com

---
Luis Vieira (2):
      libbpf: Fix struct and union zero detection in BTF dumper
      selftests/bpf: Add regression test for BTF dump zero detection

 tools/lib/bpf/btf_dump.c                          | 2 +-
 tools/testing/selftests/bpf/prog_tests/btf_dump.c | 5 +++++
 2 files changed, 6 insertions(+), 1 deletion(-)
---
base-commit: 6a75c73eebd4d497ded7d08b47894f9ddbebb5a9
change-id: 20260928-libbpf-btf-enodata-fix-ac6381645ab8

Best regards,
--  
Luis Vieira <luisflavieira@gmail.com>


^ permalink raw reply	[flat|nested] 4+ messages in thread

* [PATCH bpf-next v2 1/2] libbpf: Fix struct and union zero detection in BTF dumper
  2026-10-01  3:42 [PATCH bpf-next v2 0/2] libbpf: Fix struct and union zero detection in BTF dumper Luis Vieira
@ 2026-10-01  3:42 ` Luis Vieira
  2026-10-01  4:24   ` bot+bpf-ci
  2026-10-01  3:42 ` [PATCH bpf-next v2 2/2] selftests/bpf: Add regression test for BTF dump zero detection Luis Vieira
  1 sibling, 1 reply; 4+ messages in thread
From: Luis Vieira @ 2026-10-01  3:42 UTC (permalink / raw)
  To: Andrii Nakryiko, Eduard Zingerman, Ihor Solodrai,
	Alexei Starovoitov, Daniel Borkmann, Kumar Kartikeya Dwivedi,
	Martin KaFai Lau, Song Liu, Yonghong Song, Jiri Olsa,
	Emil Tsalapatis, Shuah Khan
  Cc: bpf, linux-kernel, linux-kselftest, Luis Vieira

btf_dump_type_data_check_zero() uses -ENODATA to indicate that a value
is zero. The array path handles this sentinel correctly, but the struct
and union path compares the return value against positive ENODATA.

As a result, the member loop returns after examining its first member.
A nested struct or union whose first member is zero can therefore be
treated as entirely zero even when a later member is non-zero.

Compare against -ENODATA so zero members are skipped while looking for
a non-zero member.

Signed-off-by: Luis Vieira <luisflavieira@gmail.com>
---
 tools/lib/bpf/btf_dump.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/tools/lib/bpf/btf_dump.c b/tools/lib/bpf/btf_dump.c
index 996e61b5f11f..ad43bbd3b442 100644
--- a/tools/lib/bpf/btf_dump.c
+++ b/tools/lib/bpf/btf_dump.c
@@ -2564,7 +2564,7 @@ static int btf_dump_type_data_check_zero(struct btf_dump *d,
 			bit_sz = btf_member_bitfield_size(t, i);
 			err = btf_dump_type_data_check_zero(d, mtype, m->type, data + moffset / 8,
 							    moffset % 8, bit_sz);
-			if (err != ENODATA)
+			if (err != -ENODATA)
 				return err;
 		}
 		return -ENODATA;

-- 
2.43.0


^ permalink raw reply	[flat|nested] 4+ messages in thread

* [PATCH bpf-next v2 2/2] selftests/bpf: Add regression test for BTF dump zero detection
  2026-10-01  3:42 [PATCH bpf-next v2 0/2] libbpf: Fix struct and union zero detection in BTF dumper Luis Vieira
  2026-10-01  3:42 ` [PATCH bpf-next v2 1/2] " Luis Vieira
@ 2026-10-01  3:42 ` Luis Vieira
  1 sibling, 0 replies; 4+ messages in thread
From: Luis Vieira @ 2026-10-01  3:42 UTC (permalink / raw)
  To: Andrii Nakryiko, Eduard Zingerman, Ihor Solodrai,
	Alexei Starovoitov, Daniel Borkmann, Kumar Kartikeya Dwivedi,
	Martin KaFai Lau, Song Liu, Yonghong Song, Jiri Olsa,
	Emil Tsalapatis, Shuah Khan
  Cc: bpf, linux-kernel, linux-kselftest, Luis Vieira

Add a regression test for a nested struct whose first member is zero
and second member is non-zero.

This verifies that struct and union zero detection continues checking
later members instead of treating the entire nested value as zero.

Signed-off-by: Luis Vieira <luisflavieira@gmail.com>
---
 tools/testing/selftests/bpf/prog_tests/btf_dump.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/tools/testing/selftests/bpf/prog_tests/btf_dump.c b/tools/testing/selftests/bpf/prog_tests/btf_dump.c
index 17fa44cb9c91..5a5ee001ac8b 100644
--- a/tools/testing/selftests/bpf/prog_tests/btf_dump.c
+++ b/tools/testing/selftests/bpf/prog_tests/btf_dump.c
@@ -1146,6 +1146,11 @@ static void test_btf_dump_struct_data(struct btf *btf, struct btf_dump *d,
 			   "(union bpf_iter_link_info){.map = (struct){.map_fd = (__u32)1,},.cgroup = (struct){.order = (enum bpf_cgroup_iter_order)BPF_CGROUP_ITER_SELF_ONLY,.cgroup_fd = (__u32)1,},.task = (struct){.tid = (__u32)1,.pid = (__u32)1,},}",
 			   { .cgroup = { .order = 1, .cgroup_fd = 1, }});
 
+	/* nested structs with zero first member and non-zero second member */
+	TEST_BTF_DUMP_DATA(btf, d, "union", str, union bpf_iter_link_info, BTF_F_COMPACT,
+			   "(union bpf_iter_link_info){.cgroup = (struct){.cgroup_fd = (__u32)1,},.task = (struct){.pid = (__u32)1,},}",
+			   { .cgroup = { .cgroup_fd = 1 }});
+
 	/* struct skb with nested structs/unions; because type output is so
 	 * complex, we don't do a string comparison, just verify we return
 	 * the type size as the amount of data displayed.

-- 
2.43.0


^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH bpf-next v2 1/2] libbpf: Fix struct and union zero detection in BTF dumper
  2026-10-01  3:42 ` [PATCH bpf-next v2 1/2] " Luis Vieira
@ 2026-10-01  4:24   ` bot+bpf-ci
  0 siblings, 0 replies; 4+ messages in thread
From: bot+bpf-ci @ 2026-10-01  4:24 UTC (permalink / raw)
  To: luisflavieira, andrii, eddyz87, ihor.solodrai, ast, daniel,
	memxor, martin.lau, song, yonghong.song, jolsa, emil, shuah
  Cc: bpf, linux-kernel, linux-kselftest, luisflavieira, ast, andrii,
	daniel, martin.lau, eddyz87, yonghong.song, mason, ihor.solodrai

[-- Attachment #1: Type: text/plain, Size: 3572 bytes --]

> libbpf: Fix struct and union zero detection in BTF dumper

TL;DR:
- Fix may read past the buffer end when dumping a truncated struct, since
  later members are now scanned unbounded
- Missing Fixes: tag

>     libbpf: Fix struct and union zero detection in BTF dumper
>
>     btf_dump_type_data_check_zero() uses -ENODATA to indicate that a value
>     is zero. The array path handles this sentinel correctly, but the struct
>     and union path compares the return value against positive ENODATA.
>
>     As a result, the member loop returns after examining its first member.
>     A nested struct or union whose first member is zero can therefore be
>     treated as entirely zero even when a later member is non-zero.
>
>     Compare against -ENODATA so zero members are skipped while looking for
>     a non-zero member.
>
>     Signed-off-by: Luis Vieira <luisflavieira@gmail.com>

This looks like a bug fix, but there is no Fixes: tag.  The faulty
"if (err != ENODATA)" comparison came in with the original typed data
dumper support.  Should this include:

  Fixes: 920d16af9b42 ("libbpf: BTF dumper support for typed data")

> diff --git a/tools/lib/bpf/btf_dump.c b/tools/lib/bpf/btf_dump.c
> --- a/tools/lib/bpf/btf_dump.c
> +++ b/tools/lib/bpf/btf_dump.c

[ ... ]

> @@ -2564,7 +2564,7 @@ static int btf_dump_type_data_check_zero(struct btf_dump *d,
>  			bit_sz = btf_member_bitfield_size(t, i);
>  			err = btf_dump_type_data_check_zero(d, mtype, m->type, data + moffset / 8,
>  							    moffset % 8, bit_sz);
> -			if (err != ENODATA)
> +			if (err != -ENODATA)
>  				return err;
>  		}
>  		return -ENODATA;

Can this now read past the end of the caller's buffer when data_sz is
smaller than the type?

btf_dump_type_data_check_overflow() only bounds-checks base types and skips
structs, unions and arrays, so a truncated struct still reaches
btf_dump_type_data_check_zero().  Before this change the member loop
returned after the first member.  With -ENODATA, the loop proceeds to later
members, and the base type checks they reach never compare against
d->typed_dump->data_end:

  btf_dump_base_type_check_zero() does memcmp(data, bytecmp, nr_bytes)
  btf_dump_get_enum_value() dereferences data directly

For example, with:

  struct outer { int a; struct inner { int x; int y; } s; };

and btf_dump__dump_type_data(d, outer_id, buf, 8, &opts) using an 8 byte
buf, a != 0 and s.x == 0:

  btf_dump_struct_data()
    btf_dump_dump_type_data(s)
      btf_dump_type_data_check_overflow(s)   /* no bounds check for STRUCT */
      btf_dump_type_data_check_zero(s)
        x is zero, returns -ENODATA, loop continues
        y: btf_dump_base_type_check_zero() reads 4 bytes at data + 8,
           which is data_end

The outcome then depends on bytes beyond the buffer.  If they are non-zero,
the struct is treated as non-zero and the later y member fails with -E2BIG.
If they are zero, the struct is skipped and the call succeeds with the
truncated data.

The array branch has the same unbounded scan, but the comment on
TEST_BTF_DUMP_DATA_OVER says overflow checking should trump "is field
zero?" checks.  Should the member checks in this path be bounded by
data_end?

I don't see a later patch in this series that addresses this.  The
follow-up selftest commit (f1b0479c0af4) only exercises a full-size buffer.


---
AI reviewed your patch. Please fix the bug or email reply why it's not a bug.
See: https://github.com/kernel-patches/vmtest/blob/master/ci/claude/README.md

CI run summary: https://github.com/kernel-patches/bpf/actions/runs/36812677691

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-10-01  4:24 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-01  3:42 [PATCH bpf-next v2 0/2] libbpf: Fix struct and union zero detection in BTF dumper Luis Vieira
2026-10-01  3:42 ` [PATCH bpf-next v2 1/2] " Luis Vieira
2026-10-01  4:24   ` bot+bpf-ci
2026-10-01  3:42 ` [PATCH bpf-next v2 2/2] selftests/bpf: Add regression test for BTF dump zero detection Luis Vieira

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®