mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH bpf-next v2 00/11] bpf: Scope callback arguments to their frame
@ 2026-10-09 20:27 Ihor Solodrai
  2026-10-09 20:27 ` [PATCH bpf-next v2 01/11] bpf: Set up callee state outside of setup_func_entry() Ihor Solodrai
                   ` (10 more replies)
  0 siblings, 11 replies; 12+ messages in thread
From: Ihor Solodrai @ 2026-10-09 20:27 UTC (permalink / raw)
  To: Alexei Starovoitov, Andrii Nakryiko, Daniel Borkmann,
	Eduard Zingerman, Kumar Kartikeya Dwivedi
  Cc: Amery Hung, Emil Tsalapatis, Nicholas Carlini, bpf, linux-kernel,
	kernel-team

A callback-calling helper or kfunc can pass its callback a pointer
that is only valid for the callback invocation, and the verifier has
no way to express that lifetime.

Two helpers need fixing:

  * bpf_user_ringbuf_drain() passes a CONST_PTR_TO_DYNPTR over a
    sample it releases as soon as the callback returns. Saving this
    pointer in callback_ctx leaves it pointing into reused kernel
    stack and allows arbitrary kernel read and write (bpf-next only,
    see patch #8).

  * bpf_for_each_map_elem() over an array or per-CPU array map passes
    the address of a u32 held in bpf_for_each_array_elem()'s own frame,
    leaking four bytes of kernel stack.

Both arguments point into a helper's own frame, with nothing
longer-lived to anchor them to. Rejecting spills of the dynptr pointer
alone would still allow derived slices and clones to escape.

Introduce REF_TYPE_FRAME for this use case: a reference owned by a
callee frame, dropped when the frame is popped. Tie each argument to
this reference so callback return invalidates it and its descendants.

Callback setters repeat register defaults and map metadata setup,
while reference release couples descendant invalidation to object
release. The refactoring patches give common initialization one owner
and separate invalidation from reference removal. Frame lifetime
tracking can then reuse the existing reference machinery.

---

Patches #1-6 are non-functional preparation. Patch #7 introduces
REF_TYPE_FRAME and its diagnostics; #8 and #10 apply it to the
helpers, and #9 and #11 add selftests.

v1->v2:
  * Add the refactoring patches: release frame references in one scan,
    and fold diagnostics into the REF_TYPE_FRAME introduction
  * Replace temporary argument mask and deferred register scan with
    reference acquisition directly in the owning verifier state during
    callback setup (Eduard)
  * Reuse callback_park_dynptr() for the nested drain test

v1: https://lore.kernel.org/r/20260922010333.1226537-1-ihor.solodrai@linux.dev

---

Ihor Solodrai (11):
  bpf: Set up callee state outside of setup_func_entry()
  bpf: Pass the owning verifier state to callback setters
  bpf: Append complete reference states
  bpf: Separate reference removal from descendant invalidation
  bpf: Share map-backed callback register setup
  bpf: Rely on callback frame initialization defaults
  bpf: Introduce REF_TYPE_FRAME in the verifier
  bpf: Scope the bpf_user_ringbuf_drain() dynptr to its callback frame
  selftests/bpf: Cover the user ringbuf callback dynptr lifetime
  bpf: Scope the bpf_for_each_map_elem() array key to the callback frame
  selftests/bpf: Cover callback-frame map key lifetime

 include/linux/bpf.h                           |   5 +
 include/linux/bpf_verifier.h                  |   6 +-
 kernel/bpf/arraymap.c                         |  18 +-
 kernel/bpf/diagnostics.c                      |   3 +
 kernel/bpf/diagnostics.h                      |   1 +
 kernel/bpf/states.c                           |   4 +
 kernel/bpf/verifier.c                         | 392 +++++++++---------
 .../selftests/bpf/progs/exceptions_fail.c     |  20 +
 .../selftests/bpf/progs/user_ringbuf_fail.c   | 135 ++++++
 .../bpf/progs/verifier_iterating_callbacks.c  |  91 ++++
 10 files changed, 476 insertions(+), 199 deletions(-)


base-commit: e1d84a37cba984388988d2f1ddc84561413f0db2
-- 
2.56.0


^ permalink raw reply	[flat|nested] 12+ messages in thread

end of thread, other threads:[~2026-10-09 20:29 UTC | newest]

Thread overview: 12+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-09 20:27 [PATCH bpf-next v2 00/11] bpf: Scope callback arguments to their frame Ihor Solodrai
2026-10-09 20:27 ` [PATCH bpf-next v2 01/11] bpf: Set up callee state outside of setup_func_entry() Ihor Solodrai
2026-10-09 20:27 ` [PATCH bpf-next v2 02/11] bpf: Pass the owning verifier state to callback setters Ihor Solodrai
2026-10-09 20:27 ` [PATCH bpf-next v2 03/11] bpf: Append complete reference states Ihor Solodrai
2026-10-09 20:27 ` [PATCH bpf-next v2 04/11] bpf: Separate reference removal from descendant invalidation Ihor Solodrai
2026-10-09 20:27 ` [PATCH bpf-next v2 05/11] bpf: Share map-backed callback register setup Ihor Solodrai
2026-10-09 20:27 ` [PATCH bpf-next v2 06/11] bpf: Rely on callback frame initialization defaults Ihor Solodrai
2026-10-09 20:27 ` [PATCH bpf-next v2 07/11] bpf: Introduce REF_TYPE_FRAME in the verifier Ihor Solodrai
2026-10-09 20:27 ` [PATCH bpf-next v2 08/11] bpf: Scope the bpf_user_ringbuf_drain() dynptr to its callback frame Ihor Solodrai
2026-10-09 20:27 ` [PATCH bpf-next v2 09/11] selftests/bpf: Cover the user ringbuf callback dynptr lifetime Ihor Solodrai
2026-10-09 20:27 ` [PATCH bpf-next v2 10/11] bpf: Scope the bpf_for_each_map_elem() array key to the callback frame Ihor Solodrai
2026-10-09 20:27 ` [PATCH bpf-next v2 11/11] selftests/bpf: Cover callback-frame map key lifetime Ihor Solodrai

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®