* [PATCH bpf-next v2 0/2] libbpf: Fix struct and union zero detection in BTF dumper
@ 2026-10-01 3:42 Luis Vieira
2026-10-01 3:42 ` [PATCH bpf-next v2 1/2] " Luis Vieira
2026-10-01 3:42 ` [PATCH bpf-next v2 2/2] selftests/bpf: Add regression test for BTF dump zero detection Luis Vieira
0 siblings, 2 replies; 4+ messages in thread
From: Luis Vieira @ 2026-10-01 3:42 UTC (permalink / raw)
To: Andrii Nakryiko, Eduard Zingerman, Ihor Solodrai,
Alexei Starovoitov, Daniel Borkmann, Kumar Kartikeya Dwivedi,
Martin KaFai Lau, Song Liu, Yonghong Song, Jiri Olsa,
Emil Tsalapatis, Shuah Khan
Cc: bpf, linux-kernel, linux-kselftest, Luis Vieira
Fix struct and union zero detection in the BTF dumper and add the
regression coverage in a separate selftest patch.
Changes in v2:
- Split the regression selftest into a separate patch, as requested by
Andrii Nakryiko.
- Link to v1:
https://patch.msgid.link/20260928-libbpf-btf-enodata-fix-v1-1-56dae4cab778@gmail.com
---
Luis Vieira (2):
libbpf: Fix struct and union zero detection in BTF dumper
selftests/bpf: Add regression test for BTF dump zero detection
tools/lib/bpf/btf_dump.c | 2 +-
tools/testing/selftests/bpf/prog_tests/btf_dump.c | 5 +++++
2 files changed, 6 insertions(+), 1 deletion(-)
---
base-commit: 6a75c73eebd4d497ded7d08b47894f9ddbebb5a9
change-id: 20260928-libbpf-btf-enodata-fix-ac6381645ab8
Best regards,
--
Luis Vieira <luisflavieira@gmail.com>
^ permalink raw reply [flat|nested] 4+ messages in thread* [PATCH bpf-next v2 1/2] libbpf: Fix struct and union zero detection in BTF dumper 2026-10-01 3:42 [PATCH bpf-next v2 0/2] libbpf: Fix struct and union zero detection in BTF dumper Luis Vieira @ 2026-10-01 3:42 ` Luis Vieira 2026-10-01 4:24 ` bot+bpf-ci 2026-10-01 3:42 ` [PATCH bpf-next v2 2/2] selftests/bpf: Add regression test for BTF dump zero detection Luis Vieira 1 sibling, 1 reply; 4+ messages in thread From: Luis Vieira @ 2026-10-01 3:42 UTC (permalink / raw) To: Andrii Nakryiko, Eduard Zingerman, Ihor Solodrai, Alexei Starovoitov, Daniel Borkmann, Kumar Kartikeya Dwivedi, Martin KaFai Lau, Song Liu, Yonghong Song, Jiri Olsa, Emil Tsalapatis, Shuah Khan Cc: bpf, linux-kernel, linux-kselftest, Luis Vieira btf_dump_type_data_check_zero() uses -ENODATA to indicate that a value is zero. The array path handles this sentinel correctly, but the struct and union path compares the return value against positive ENODATA. As a result, the member loop returns after examining its first member. A nested struct or union whose first member is zero can therefore be treated as entirely zero even when a later member is non-zero. Compare against -ENODATA so zero members are skipped while looking for a non-zero member. Signed-off-by: Luis Vieira <luisflavieira@gmail.com> --- tools/lib/bpf/btf_dump.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tools/lib/bpf/btf_dump.c b/tools/lib/bpf/btf_dump.c index 996e61b5f11f..ad43bbd3b442 100644 --- a/tools/lib/bpf/btf_dump.c +++ b/tools/lib/bpf/btf_dump.c @@ -2564,7 +2564,7 @@ static int btf_dump_type_data_check_zero(struct btf_dump *d, bit_sz = btf_member_bitfield_size(t, i); err = btf_dump_type_data_check_zero(d, mtype, m->type, data + moffset / 8, moffset % 8, bit_sz); - if (err != ENODATA) + if (err != -ENODATA) return err; } return -ENODATA; -- 2.43.0 ^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH bpf-next v2 1/2] libbpf: Fix struct and union zero detection in BTF dumper 2026-10-01 3:42 ` [PATCH bpf-next v2 1/2] " Luis Vieira @ 2026-10-01 4:24 ` bot+bpf-ci 0 siblings, 0 replies; 4+ messages in thread From: bot+bpf-ci @ 2026-10-01 4:24 UTC (permalink / raw) To: luisflavieira, andrii, eddyz87, ihor.solodrai, ast, daniel, memxor, martin.lau, song, yonghong.song, jolsa, emil, shuah Cc: bpf, linux-kernel, linux-kselftest, luisflavieira, ast, andrii, daniel, martin.lau, eddyz87, yonghong.song, mason, ihor.solodrai [-- Attachment #1: Type: text/plain, Size: 3572 bytes --] > libbpf: Fix struct and union zero detection in BTF dumper TL;DR: - Fix may read past the buffer end when dumping a truncated struct, since later members are now scanned unbounded - Missing Fixes: tag > libbpf: Fix struct and union zero detection in BTF dumper > > btf_dump_type_data_check_zero() uses -ENODATA to indicate that a value > is zero. The array path handles this sentinel correctly, but the struct > and union path compares the return value against positive ENODATA. > > As a result, the member loop returns after examining its first member. > A nested struct or union whose first member is zero can therefore be > treated as entirely zero even when a later member is non-zero. > > Compare against -ENODATA so zero members are skipped while looking for > a non-zero member. > > Signed-off-by: Luis Vieira <luisflavieira@gmail.com> This looks like a bug fix, but there is no Fixes: tag. The faulty "if (err != ENODATA)" comparison came in with the original typed data dumper support. Should this include: Fixes: 920d16af9b42 ("libbpf: BTF dumper support for typed data") > diff --git a/tools/lib/bpf/btf_dump.c b/tools/lib/bpf/btf_dump.c > --- a/tools/lib/bpf/btf_dump.c > +++ b/tools/lib/bpf/btf_dump.c [ ... ] > @@ -2564,7 +2564,7 @@ static int btf_dump_type_data_check_zero(struct btf_dump *d, > bit_sz = btf_member_bitfield_size(t, i); > err = btf_dump_type_data_check_zero(d, mtype, m->type, data + moffset / 8, > moffset % 8, bit_sz); > - if (err != ENODATA) > + if (err != -ENODATA) > return err; > } > return -ENODATA; Can this now read past the end of the caller's buffer when data_sz is smaller than the type? btf_dump_type_data_check_overflow() only bounds-checks base types and skips structs, unions and arrays, so a truncated struct still reaches btf_dump_type_data_check_zero(). Before this change the member loop returned after the first member. With -ENODATA, the loop proceeds to later members, and the base type checks they reach never compare against d->typed_dump->data_end: btf_dump_base_type_check_zero() does memcmp(data, bytecmp, nr_bytes) btf_dump_get_enum_value() dereferences data directly For example, with: struct outer { int a; struct inner { int x; int y; } s; }; and btf_dump__dump_type_data(d, outer_id, buf, 8, &opts) using an 8 byte buf, a != 0 and s.x == 0: btf_dump_struct_data() btf_dump_dump_type_data(s) btf_dump_type_data_check_overflow(s) /* no bounds check for STRUCT */ btf_dump_type_data_check_zero(s) x is zero, returns -ENODATA, loop continues y: btf_dump_base_type_check_zero() reads 4 bytes at data + 8, which is data_end The outcome then depends on bytes beyond the buffer. If they are non-zero, the struct is treated as non-zero and the later y member fails with -E2BIG. If they are zero, the struct is skipped and the call succeeds with the truncated data. The array branch has the same unbounded scan, but the comment on TEST_BTF_DUMP_DATA_OVER says overflow checking should trump "is field zero?" checks. Should the member checks in this path be bounded by data_end? I don't see a later patch in this series that addresses this. The follow-up selftest commit (f1b0479c0af4) only exercises a full-size buffer. --- AI reviewed your patch. Please fix the bug or email reply why it's not a bug. See: https://github.com/kernel-patches/vmtest/blob/master/ci/claude/README.md CI run summary: https://github.com/kernel-patches/bpf/actions/runs/36812677691 ^ permalink raw reply [flat|nested] 4+ messages in thread
* [PATCH bpf-next v2 2/2] selftests/bpf: Add regression test for BTF dump zero detection 2026-10-01 3:42 [PATCH bpf-next v2 0/2] libbpf: Fix struct and union zero detection in BTF dumper Luis Vieira 2026-10-01 3:42 ` [PATCH bpf-next v2 1/2] " Luis Vieira @ 2026-10-01 3:42 ` Luis Vieira 1 sibling, 0 replies; 4+ messages in thread From: Luis Vieira @ 2026-10-01 3:42 UTC (permalink / raw) To: Andrii Nakryiko, Eduard Zingerman, Ihor Solodrai, Alexei Starovoitov, Daniel Borkmann, Kumar Kartikeya Dwivedi, Martin KaFai Lau, Song Liu, Yonghong Song, Jiri Olsa, Emil Tsalapatis, Shuah Khan Cc: bpf, linux-kernel, linux-kselftest, Luis Vieira Add a regression test for a nested struct whose first member is zero and second member is non-zero. This verifies that struct and union zero detection continues checking later members instead of treating the entire nested value as zero. Signed-off-by: Luis Vieira <luisflavieira@gmail.com> --- tools/testing/selftests/bpf/prog_tests/btf_dump.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/tools/testing/selftests/bpf/prog_tests/btf_dump.c b/tools/testing/selftests/bpf/prog_tests/btf_dump.c index 17fa44cb9c91..5a5ee001ac8b 100644 --- a/tools/testing/selftests/bpf/prog_tests/btf_dump.c +++ b/tools/testing/selftests/bpf/prog_tests/btf_dump.c @@ -1146,6 +1146,11 @@ static void test_btf_dump_struct_data(struct btf *btf, struct btf_dump *d, "(union bpf_iter_link_info){.map = (struct){.map_fd = (__u32)1,},.cgroup = (struct){.order = (enum bpf_cgroup_iter_order)BPF_CGROUP_ITER_SELF_ONLY,.cgroup_fd = (__u32)1,},.task = (struct){.tid = (__u32)1,.pid = (__u32)1,},}", { .cgroup = { .order = 1, .cgroup_fd = 1, }}); + /* nested structs with zero first member and non-zero second member */ + TEST_BTF_DUMP_DATA(btf, d, "union", str, union bpf_iter_link_info, BTF_F_COMPACT, + "(union bpf_iter_link_info){.cgroup = (struct){.cgroup_fd = (__u32)1,},.task = (struct){.pid = (__u32)1,},}", + { .cgroup = { .cgroup_fd = 1 }}); + /* struct skb with nested structs/unions; because type output is so * complex, we don't do a string comparison, just verify we return * the type size as the amount of data displayed. -- 2.43.0 ^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-10-01 4:24 UTC | newest] Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed) -- links below jump to the message on this page -- 2026-10-01 3:42 [PATCH bpf-next v2 0/2] libbpf: Fix struct and union zero detection in BTF dumper Luis Vieira 2026-10-01 3:42 ` [PATCH bpf-next v2 1/2] " Luis Vieira 2026-10-01 4:24 ` bot+bpf-ci 2026-10-01 3:42 ` [PATCH bpf-next v2 2/2] selftests/bpf: Add regression test for BTF dump zero detection Luis Vieira
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®