From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f46.google.com (mail-pj1-f46.google.com [209.85.216.46]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9843D3A6B61 for ; Fri, 29 May 2026 19:19:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.46 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780082369; cv=none; b=fRD9G5Q9EsD+ZDDI0Ul5B3nYr73zUeA4qjvo6gjASM22wdhz5s/Um8M1eJHAaYFBUXxE5TK9hG1x1ZDdPzly8BiqXNO2jqdpnxKYe99fWkVvlJS8s8K7TxYZwBndV9MyTKV78E9yH78Ry3MA7RSIxisqBKJT1dPXJufEEt5Q6dM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780082369; c=relaxed/simple; bh=jkWZTD4QRHZiQqpe6ALyI6kMoPn3g9Suq0ijNAkRndY=; h=Mime-Version:Content-Type:Date:Message-Id:From:To:Cc:Subject: References:In-Reply-To; b=YhZpYbDj/82Y34hc5AE1CsbQhPYTEzMzkwBUzmZD6Hc7uMislac8E0G8cGJsUczNMU0jMKZM+pjUHUh5skC51K+XOwPkdm4VOXzvgDNh8Xrf93Zvxxq+JhzOHlhz/uGzqGfeE1xl3juenN7c08kFh9pIa5iU51OrQG2JGRYLv7o= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=etsalapatis.com; spf=pass smtp.mailfrom=etsalapatis.com; dkim=pass (2048-bit key) header.d=etsalapatis-com.20251104.gappssmtp.com header.i=@etsalapatis-com.20251104.gappssmtp.com header.b=X4t+REnQ; arc=none smtp.client-ip=209.85.216.46 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=etsalapatis.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=etsalapatis.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=etsalapatis-com.20251104.gappssmtp.com header.i=@etsalapatis-com.20251104.gappssmtp.com header.b="X4t+REnQ" Received: by mail-pj1-f46.google.com with SMTP id 98e67ed59e1d1-36bb3551f6eso1241110a91.1 for ; Fri, 29 May 2026 12:19:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=etsalapatis-com.20251104.gappssmtp.com; s=20251104; t=1780082368; x=1780687168; darn=vger.kernel.org; h=in-reply-to:references:subject:cc:to:from:message-id:date :content-transfer-encoding:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=p/gCygVuvCix+pnQ33/MTL/P0DmU8fAWMpRNiF7Wi6A=; b=X4t+REnQGDH0cMNf6c4pG9G3Nin9oq66m+t7oExqOmaPUFpBqWIusRD1BUR+I4vjwx zd22YtofKieKZ2H5uqFB5hb+2uVVQDP7nc/00FEPr1yOzLsDbqkfNY/Mi4b/jf0CfH3f FNSQ/joJed7m0IYYdn+9wz1ZQj6ldx30+c5RKztQnu52gbByqiTLUTjfdseWwcJf15PY t3KH83PcDb6xbt9Do1ZG6yBW8cdaYb49amdAaTsHogZ2ceg5uV8sdoB7hDfDA1U3sZ4c cNCSSitU4TEozLsQH2qCPAk3uyvdc43nIR4apmnLENcnmr6NDAShRKcOoW0RG2CcMD4Y JAhA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780082368; x=1780687168; h=in-reply-to:references:subject:cc:to:from:message-id:date :content-transfer-encoding:mime-version:x-gm-gg:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=p/gCygVuvCix+pnQ33/MTL/P0DmU8fAWMpRNiF7Wi6A=; b=jTYNxBy1qLpqmcPDvCWbQ90K6lFFimq+nbzp7VFneZ5aMohEThxWesYQhpDxp4BoR8 qeuOBVvHm6rPqcETBd/oBGclyHjTO+HmtXcyIQfS7OeAFD5DR2nQgzIUFg3h2zgZyRuW +wUjKKagG4D6kCtAqIXRGz10rusTHwoB8dQqYCiDV52XUW8QFysMpdopCWtmLhJnRzH6 9fgV1I1K+7/SkEo8zaku5ILnBdLoPo2ncwe+Z6ALgM72VtMgnWn6dLW8te3SWH4TP1FK JhOq5a+sA/7rGQ3X6cw/duPK1+YuxzfjP56ujSEwQcFFAgVrprIX46pxQGInlEPXhcCW aa5Q== X-Forwarded-Encrypted: i=1; AFNElJ+7vSYEVlZDFhoVZS3eDBV5wsQdL5OC2NUshh7/xz6Db7RqqAJW5eWD1/tD5Ji5FC7Ya4uqvpL8QpVOAVs=@vger.kernel.org X-Gm-Message-State: AOJu0YzSg9zWzcR/dXlXBVlSnxcQkOZpR4pPAeSrOHsyeehPaHStIjKp NfU8JllNKiS90tqVp7Jc2AlfBlkzo++RBfDrD4BV83xQ/vngdxKzqUnYszwvG87qJrk= X-Gm-Gg: Acq92OFFJj+NhtaEBnyYcM1jOhqYz0lwNyoHbge2cXkuUsrb72T3IbsxKH0nkUj0A9B JCXaVLUJ/PO9bMzo0nuqUrDkw18EdEdlPlYvt/B2eecoG5VR02CLhgZhAYzGubtewKWomkOPkt8 lXkER1p/DzH+r2YF6ZJt8f8X+C246G+nsqMGWU+MLO3eCH1jT09qMvM08GLpXeZyhXSb9OYhe65 Hm6617Coo42w92QxL9Be32yssAcUuY1eVamvAsYovkx3K4DDK5EF+vK97VKAbDP5c6n/NFkEsNl qHKnHdxM3u9h+88fg5dTfm/Un0jO24v+YGPG3pZmwnM1D4qWksh2e3WxfpakRtkfcAr/cs+DsYl LKYPuS4RplzdjfPh4d/ubKQgPEwfzfDcRND2/btYJLFo086U9rDQqYg0UvEPam7qVNOhgg+IkBD zipLOrMPeAG5GzFrwUj04C+61BE1w8x0+F06c= X-Received: by 2002:a17:90b:278f:b0:36b:bec8:94c5 with SMTP id 98e67ed59e1d1-36c4ff364dbmr495717a91.10.1780082367780; Fri, 29 May 2026 12:19:27 -0700 (PDT) Received: from localhost ([2001:569:58a0:da00:a5c8:c4ce:f7c1:40c1]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-36bc6a34dabsm2787591a91.12.2026.05.29.12.19.26 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Fri, 29 May 2026 12:19:27 -0700 (PDT) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=UTF-8 Date: Fri, 29 May 2026 15:19:26 -0400 Message-Id: From: "Emil Tsalapatis" To: "Vlad Poenaru" , "Alexei Starovoitov" , "Daniel Borkmann" , "Andrii Nakryiko" , Cc: "Martin KaFai Lau" , "Eduard Zingerman" , "Kumar Kartikeya Dwivedi" , "Song Liu" , "Yonghong Song" , "Jiri Olsa" , =?utf-8?q?Toke_H=C3=B8iland-J=C3=B8rgensen?= , , Subject: Re: [PATCH bpf] bpf, lpm_trie: Allow lookups from sleepable BPF programs X-Mailer: aerc 0.21.0-0-g5549850facc2 References: <20260529174233.2954240-1-vlad.wing@gmail.com> In-Reply-To: <20260529174233.2954240-1-vlad.wing@gmail.com> On Fri May 29, 2026 at 1:42 PM EDT, Vlad Poenaru wrote: > trie_lookup_elem() annotates its rcu_dereference_check() walks with > only rcu_read_lock_bh_held(). Because rcu_dereference_check(p, c) > resolves to "c || rcu_read_lock_held()", this passes for XDP/NAPI and > classic RCU readers but fails for sleepable BPF programs, which enter > via __bpf_prog_enter_sleepable() and hold only rcu_read_lock_trace(). > > A sleepable LSM hook that ends up doing bpf_map_lookup_elem() on an LPM > trie therefore triggers lockdep on debug kernels: > > =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D > WARNING: suspicious RCU usage > 7.1.0-... Tainted: G E > ----------------------------- > kernel/bpf/lpm_trie.c:249 suspicious rcu_dereference_check() usage! > 1 lock held by net_tests/540: > #0: (rcu_tasks_trace_srcu_struct){....}-{0:0}, > at: __bpf_prog_enter_sleepable+0x26/0x280 > Call Trace: > dump_stack_lvl > lockdep_rcu_suspicious > trie_lookup_elem > bpf_prog_..._enforce_security_socket_connect > bpf_trampoline_... > security_socket_connect > __sys_connect > do_syscall_64 > > This is lockdep-only -- no UAF, since Tasks Trace RCU does serialize > against the trie's reclaim path -- but it spams the console once per > distinct callsite on every debug kernel running a sleepable BPF LSM > that does map lookups on an LPM trie, which is increasingly common. > > Other map types already use the bpf_rcu_lock_held() helper, which > accepts all three contexts (classic, BH, Tasks Trace). Use it here as > well, matching the established convention. > > Fixes: 694cea395fde ("bpf: Allow RCU-protected lookups to happen from bh = context") > Cc: stable@vger.kernel.org > Signed-off-by: Vlad Poenaru Reviewed-by: Emil Tsalapatis > --- > kernel/bpf/lpm_trie.c | 4 ++-- > 1 file changed, 2 insertions(+), 2 deletions(-) > > diff --git a/kernel/bpf/lpm_trie.c b/kernel/bpf/lpm_trie.c > index 0f57608b385d..ac36063cb7e6 100644 > --- a/kernel/bpf/lpm_trie.c > +++ b/kernel/bpf/lpm_trie.c > @@ -246,7 +246,7 @@ static void *trie_lookup_elem(struct bpf_map *map, vo= id *_key) > =20 > /* Start walking the trie from the root node ... */ > =20 > - for (node =3D rcu_dereference_check(trie->root, rcu_read_lock_bh_held()= ); > + for (node =3D rcu_dereference_check(trie->root, bpf_rcu_lock_held()); > node;) { > unsigned int next_bit; > size_t matchlen; > @@ -280,7 +280,7 @@ static void *trie_lookup_elem(struct bpf_map *map, vo= id *_key) > */ > next_bit =3D extract_bit(key->data, node->prefixlen); > node =3D rcu_dereference_check(node->child[next_bit], > - rcu_read_lock_bh_held()); > + bpf_rcu_lock_held()); > } > =20 > if (!found)