From: Jiri Olsa <olsajiri@gmail.com>
To: bot+bpf-ci@kernel.org
Cc: wanjay@amazon.com, bpf@vger.kernel.org, ast@kernel.org,
daniel@iogearbox.net, andrii@kernel.org, eddyz87@gmail.com,
memxor@gmail.com, alan.maguire@oracle.com, martin.lau@linux.dev,
yonghong.song@linux.dev, nathan@kernel.org, nsc@kernel.org,
linux-kbuild@vger.kernel.org, mcgrof@kernel.org,
petr.pavlu@suse.com, linux-modules@vger.kernel.org,
arnd@arndb.de, linux-kernel@vger.kernel.org, abuehaze@amazon.com,
doebel@amazon.de, jay.wang.upstream@gmail.com,
martin.lau@kernel.org, mason@kernel.org, ihor.solodrai@linux.dev
Subject: Re: [PATCH bpf-next 3/6] bpf: fetch the vmlinux BTF where kernel types enter a program
Date: Thu, 24 Sep 2026 13:26:36 +0200 [thread overview]
Message-ID: <arUI7ORFZCegI5ep@krava> (raw)
In-Reply-To: <39f6151d364d966f70b7802cfd4bbca15734a7945478265ecc681f1779e50abb@mail.kernel.org>
On Wed, Sep 23, 2026 at 06:28:43AM +0000, bot+bpf-ci@kernel.org wrote:
SNIP
> > diff --git a/kernel/trace/bpf_trace.c b/kernel/trace/bpf_trace.c
> > index 195f78db9bda..c022b2877f0b 100644
> > --- a/kernel/trace/bpf_trace.c
> > +++ b/kernel/trace/bpf_trace.c
> > @@ -1015,7 +1015,8 @@ static int bpf_btf_printf_prepare(struct btf_ptr *ptr, u32 btf_ptr_size,
> > if (btf_ptr_size != sizeof(struct btf_ptr))
> > return -EINVAL;
> >
> > - *btf = bpf_get_btf_vmlinux();
> > + /* Called from a running program: only use the BTF if it is parsed. */
> > + *btf = bpf_peek_btf_vmlinux();
> >
> > if (IS_ERR_OR_NULL(*btf))
> > return IS_ERR(*btf) ? PTR_ERR(*btf) : -EINVAL;
>
> Swapping bpf_get_btf_vmlinux() for bpf_peek_btf_vmlinux() is correct as a
> sleeping-in-program-context fix, but does anything in this commit arrange
> for the BTF to have been parsed by the time bpf_snprintf_btf() or
> bpf_seq_printf_btf() run?
>
> The compensating verifier-time fetch in check_helper_call() is gated on
> helper_uses_vmlinux_btf(), which only matches base_type(ret_type) ==
> RET_PTR_TO_BTF_ID or base_type(arg_type[i]) == ARG_PTR_TO_BTF_ID.
>
> bpf_snprintf_btf_proto and bpf_seq_printf_btf_proto contain neither: their
> arguments are ARG_PTR_TO_MEM / ARG_CONST_SIZE / ARG_ANYTHING and the return
> is RET_INTEGER, because the BTF type id travels inside the struct btf_ptr
> the program passes by value rather than in a register type.
>
> So helper_uses_vmlinux_btf() returns false for exactly the two helpers
> whose runtime fetch was just weakened.
>
> On a CONFIG_DEBUG_INFO_BTF=m kernel where the BTF is present but not yet
> parsed, bpf_peek_btf_vmlinux() returns NULL and the helper returns -EINVAL.
> A working bpf_snprintf_btf() or bpf_seq_printf_btf() call silently starts
> failing, depending on whether unrelated activity already triggered the
> parse.
>
> The changelog frames this as behaving "as they do on a kernel without BTF",
> but the BTF is available, just unparsed, and the previous code would have
> produced correct output.
>
> Should the fix be at verify time - teaching helper_uses_vmlinux_btf(), or
> check_bpf_snprintf_call(), or the *_btf protos, to force the fetch? The
> forward range 90fe51b6b36a..2f5aab95d2b8 contains no code change for this.
seems valid to me, could we just check for these two print helpers in
helper_uses_vmlinux_btf ?
jirka
next prev parent reply other threads:[~2026-09-24 11:26 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-23 5:39 [PATCH bpf-next 0/6] bpf: make the vmlinux BTF an on-demand loadable module (CONFIG_DEBUG_INFO_BTF=m) to save ~5.4 MB memory Jay Wang
2026-09-23 5:39 ` [PATCH bpf-next 1/6] bpf: pass the vmlinux BTF to btf_parse_module() and let it adopt the data Jay Wang
2026-09-23 5:39 ` [PATCH bpf-next 2/6] bpf: split the kfunc, dtor kfunc and struct_ops registration bodies Jay Wang
2026-09-23 6:16 ` bot+bpf-ci
2026-09-23 5:39 ` [PATCH bpf-next 3/6] bpf: fetch the vmlinux BTF where kernel types enter a program Jay Wang
2026-09-23 6:28 ` bot+bpf-ci
2026-09-24 11:26 ` Jiri Olsa [this message]
2026-09-23 5:39 ` [PATCH bpf-next 4/6] bpf: take the vmlinux BTF from the btf_vmlinux module Jay Wang
2026-09-23 5:39 ` [PATCH bpf-next 5/6] bpf: defer registrations until the vmlinux BTF is available Jay Wang
2026-09-23 6:41 ` bot+bpf-ci
2026-09-23 5:39 ` [PATCH bpf-next 6/6] kbuild, bpf: allow building the vmlinux BTF as a module Jay Wang
2026-09-23 8:27 ` [PATCH bpf-next 0/6] bpf: make the vmlinux BTF an on-demand loadable module (CONFIG_DEBUG_INFO_BTF=m) to save ~5.4 MB memory Alan Maguire
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=arUI7ORFZCegI5ep@krava \
--to=olsajiri@gmail.com \
--cc=abuehaze@amazon.com \
--cc=alan.maguire@oracle.com \
--cc=andrii@kernel.org \
--cc=arnd@arndb.de \
--cc=ast@kernel.org \
--cc=bot+bpf-ci@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=doebel@amazon.de \
--cc=eddyz87@gmail.com \
--cc=ihor.solodrai@linux.dev \
--cc=jay.wang.upstream@gmail.com \
--cc=linux-kbuild@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-modules@vger.kernel.org \
--cc=martin.lau@kernel.org \
--cc=martin.lau@linux.dev \
--cc=mason@kernel.org \
--cc=mcgrof@kernel.org \
--cc=memxor@gmail.com \
--cc=nathan@kernel.org \
--cc=nsc@kernel.org \
--cc=petr.pavlu@suse.com \
--cc=wanjay@amazon.com \
--cc=yonghong.song@linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®