mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH bpf v3 0/2] bpf: Reject bare pointer for __arg_trusted arg
@ 2026-10-06 16:06 Yiyang Chen
  2026-10-06 16:06 ` [PATCH bpf v3 1/2] " Yiyang Chen
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: Yiyang Chen @ 2026-10-06 16:06 UTC (permalink / raw)
  To: Alexei Starovoitov, Daniel Borkmann, John Fastabend,
	Andrii Nakryiko, Eduard Zingerman, Kumar Kartikeya Dwivedi,
	Martin KaFai Lau, Song Liu, Yonghong Song, Jiri Olsa,
	Emil Tsalapatis, Ihor Solodrai, Shuah Khan
  Cc: bpf, linux-kernel, linux-kselftest, Amery Hung, Yiyang Chen

A global subprogram parameter tagged __arg_trusted is verified as holding a
PTR_TRUSTED pointer, but its call-site type check also accepts bare
PTR_TO_BTF_ID. This lets a caller pass a pointer without lifetime protection
to code verified for raw trusted-pointer accesses.

Reject the bare pointer while preserving referenced, trusted, and
RCU-protected arguments. The latter is used by sched-ext programs that pass
the result of an RCU-protected kfunc through trusted-and-nullable global
subprogram arguments.

Add a rejection test for the bare pointer and a positive regression test for
the RCU-protected case.

This series targets bpf, which uses separate global-subprogram and kfunc
argument checkers.

Changes in v3:
- Preserve RCU-protected arguments accepted by existing sched-ext programs.
- Make the MEM_RCU case a positive regression test.
- Use the preferred multi-line comment style.
- Link to v2: https://lore.kernel.org/r/20261005-a3-arg-trusted-v4-v2-0-319ce2936949@mails.tsinghua.edu.cn

Changes in v2:
- Retarget the fix to btf_check_func_arg_match(), where the subprogram
  argument check lives in this tree, instead of check_func_arg().
- Run the check after check_reg_type() and check_func_arg_reg_off() so type
  and offset diagnostics keep their wording.

v1: https://lore.kernel.org/bpf/20261005-a3-arg-trusted-v4-v1-0-50ee0268fd39@mails.tsinghua.edu.cn/

---
Yiyang Chen (2):
      bpf: Reject bare pointer for __arg_trusted arg
      selftests/bpf: Cover bare and RCU __arg_trusted arguments

 kernel/bpf/verifier.c                              | 24 +++++++++++++++
 .../selftests/bpf/progs/verifier_global_ptr_args.c | 34 ++++++++++++++++++++++
 2 files changed, 58 insertions(+)

base-commit: ff47652a4b66c067c765a7ad464d930b5a9367cc
change-id: 20261005-a3-arg-trusted-v4-9d5d9485e5ba
-- 
Yiyang Chen <chenyy23@mails.tsinghua.edu.cn>


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-10-06 16:57 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-06 16:06 [PATCH bpf v3 0/2] bpf: Reject bare pointer for __arg_trusted arg Yiyang Chen
2026-10-06 16:06 ` [PATCH bpf v3 1/2] " Yiyang Chen
2026-10-06 16:06 ` [PATCH bpf v3 2/2] selftests/bpf: Cover bare and RCU __arg_trusted arguments Yiyang Chen
2026-10-06 16:57 ` [PATCH bpf v3 0/2] bpf: Reject bare pointer for __arg_trusted arg Alexei Starovoitov

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®