From: Ihor Solodrai <ihor.solodrai@linux.dev>
To: Alexei Starovoitov <ast@kernel.org>,
Andrii Nakryiko <andrii@kernel.org>,
Daniel Borkmann <daniel@iogearbox.net>,
Eduard Zingerman <eddyz87@gmail.com>,
Kumar Kartikeya Dwivedi <memxor@gmail.com>
Cc: Amery Hung <ameryhung@gmail.com>,
Emil Tsalapatis <emil@etsalapatis.com>,
Nicholas Carlini <npc@anthropic.com>,
bpf@vger.kernel.org, linux-kernel@vger.kernel.org,
kernel-team@meta.com
Subject: [PATCH bpf-next v2 00/11] bpf: Scope callback arguments to their frame
Date: Fri, 9 Oct 2026 13:27:47 -0700 [thread overview]
Message-ID: <20261009202759.50520-1-ihor.solodrai@linux.dev> (raw)
A callback-calling helper or kfunc can pass its callback a pointer
that is only valid for the callback invocation, and the verifier has
no way to express that lifetime.
Two helpers need fixing:
* bpf_user_ringbuf_drain() passes a CONST_PTR_TO_DYNPTR over a
sample it releases as soon as the callback returns. Saving this
pointer in callback_ctx leaves it pointing into reused kernel
stack and allows arbitrary kernel read and write (bpf-next only,
see patch #8).
* bpf_for_each_map_elem() over an array or per-CPU array map passes
the address of a u32 held in bpf_for_each_array_elem()'s own frame,
leaking four bytes of kernel stack.
Both arguments point into a helper's own frame, with nothing
longer-lived to anchor them to. Rejecting spills of the dynptr pointer
alone would still allow derived slices and clones to escape.
Introduce REF_TYPE_FRAME for this use case: a reference owned by a
callee frame, dropped when the frame is popped. Tie each argument to
this reference so callback return invalidates it and its descendants.
Callback setters repeat register defaults and map metadata setup,
while reference release couples descendant invalidation to object
release. The refactoring patches give common initialization one owner
and separate invalidation from reference removal. Frame lifetime
tracking can then reuse the existing reference machinery.
---
Patches #1-6 are non-functional preparation. Patch #7 introduces
REF_TYPE_FRAME and its diagnostics; #8 and #10 apply it to the
helpers, and #9 and #11 add selftests.
v1->v2:
* Add the refactoring patches: release frame references in one scan,
and fold diagnostics into the REF_TYPE_FRAME introduction
* Replace temporary argument mask and deferred register scan with
reference acquisition directly in the owning verifier state during
callback setup (Eduard)
* Reuse callback_park_dynptr() for the nested drain test
v1: https://lore.kernel.org/r/20260922010333.1226537-1-ihor.solodrai@linux.dev
---
Ihor Solodrai (11):
bpf: Set up callee state outside of setup_func_entry()
bpf: Pass the owning verifier state to callback setters
bpf: Append complete reference states
bpf: Separate reference removal from descendant invalidation
bpf: Share map-backed callback register setup
bpf: Rely on callback frame initialization defaults
bpf: Introduce REF_TYPE_FRAME in the verifier
bpf: Scope the bpf_user_ringbuf_drain() dynptr to its callback frame
selftests/bpf: Cover the user ringbuf callback dynptr lifetime
bpf: Scope the bpf_for_each_map_elem() array key to the callback frame
selftests/bpf: Cover callback-frame map key lifetime
include/linux/bpf.h | 5 +
include/linux/bpf_verifier.h | 6 +-
kernel/bpf/arraymap.c | 18 +-
kernel/bpf/diagnostics.c | 3 +
kernel/bpf/diagnostics.h | 1 +
kernel/bpf/states.c | 4 +
kernel/bpf/verifier.c | 392 +++++++++---------
.../selftests/bpf/progs/exceptions_fail.c | 20 +
.../selftests/bpf/progs/user_ringbuf_fail.c | 135 ++++++
.../bpf/progs/verifier_iterating_callbacks.c | 91 ++++
10 files changed, 476 insertions(+), 199 deletions(-)
base-commit: e1d84a37cba984388988d2f1ddc84561413f0db2
--
2.56.0
next reply other threads:[~2026-10-09 20:28 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-09 20:27 Ihor Solodrai [this message]
2026-10-09 20:27 ` [PATCH bpf-next v2 01/11] bpf: Set up callee state outside of setup_func_entry() Ihor Solodrai
2026-10-09 20:27 ` [PATCH bpf-next v2 02/11] bpf: Pass the owning verifier state to callback setters Ihor Solodrai
2026-10-09 20:27 ` [PATCH bpf-next v2 03/11] bpf: Append complete reference states Ihor Solodrai
2026-10-09 20:27 ` [PATCH bpf-next v2 04/11] bpf: Separate reference removal from descendant invalidation Ihor Solodrai
2026-10-09 20:27 ` [PATCH bpf-next v2 05/11] bpf: Share map-backed callback register setup Ihor Solodrai
2026-10-09 20:27 ` [PATCH bpf-next v2 06/11] bpf: Rely on callback frame initialization defaults Ihor Solodrai
2026-10-09 20:27 ` [PATCH bpf-next v2 07/11] bpf: Introduce REF_TYPE_FRAME in the verifier Ihor Solodrai
2026-10-09 20:27 ` [PATCH bpf-next v2 08/11] bpf: Scope the bpf_user_ringbuf_drain() dynptr to its callback frame Ihor Solodrai
2026-10-09 20:27 ` [PATCH bpf-next v2 09/11] selftests/bpf: Cover the user ringbuf callback dynptr lifetime Ihor Solodrai
2026-10-09 20:27 ` [PATCH bpf-next v2 10/11] bpf: Scope the bpf_for_each_map_elem() array key to the callback frame Ihor Solodrai
2026-10-09 20:27 ` [PATCH bpf-next v2 11/11] selftests/bpf: Cover callback-frame map key lifetime Ihor Solodrai
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261009202759.50520-1-ihor.solodrai@linux.dev \
--to=ihor.solodrai@linux.dev \
--cc=ameryhung@gmail.com \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=eddyz87@gmail.com \
--cc=emil@etsalapatis.com \
--cc=kernel-team@meta.com \
--cc=linux-kernel@vger.kernel.org \
--cc=memxor@gmail.com \
--cc=npc@anthropic.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®