Re: [PATCH bpf-next v3 12/18] bpf: Classify kfunc mem_size args from BTF without register state
Amery Hung <[email protected]> Sun, 2 Aug 2026 14:32:06 -0700
| Newsgroups | dev.linux.lists.sashiko-reviews,org.kernel.vger.bpf |
|---|---|
| Message-ID | <CAMB2axP6CHeFRbBFxqnM9Ficnp-KgT+sYKVFVbdLX1b6jraXhA@mail.gmail.com> |
On Sat, Aug 1, 2026 at 1:09=E2=80=AFAM <[email protected]> wrote: > > Thank you for your contribution! Sashiko AI review found 1 potential issu= e(s) to consider: > - [High] Removing the register type check from `is_kfunc_arg_mem_size()` = allows a BPF program to pass a pointer register as a memory size parameter = (`__sz`), which triggers a `verifier_bug` and a kernel warning. > -- > > --- Patch [12]: [PATCH bpf-next v3 12/18] bpf: Classify kfunc mem_size ar= gs from BTF without register state --- > commit e7666ea9e561228e1708d772f8e42d33c514cde8 > Author: Amery Hung <[email protected]> > > bpf: Classify kfunc mem_size args from BTF without register state > > This commit removes register state checks from is_kfunc_arg_mem_size() an= d > is_kfunc_arg_const_mem_size(). It relies solely on BTF to classify kfunc > memory size arguments to further decouple argument type classification fr= om > register state. > > > diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c > > index 6fc22a4e38b26..d65da54f9c0f8 100644 > > --- a/kernel/bpf/verifier.c > > +++ b/kernel/bpf/verifier.c > > @@ -10785,26 +10785,24 @@ static bool is_kfunc_rcu_protected(struct bpf= _call_arg_meta *meta) > > } > > > > static bool is_kfunc_arg_mem_size(const struct btf *btf, > > - const struct btf_param *arg, > > - const struct bpf_reg_state *reg) > > + const struct btf_param *arg) > > { > > const struct btf_type *t; > > > > t =3D btf_type_skip_modifiers(btf, arg->type, NULL); > > - if (!btf_type_is_scalar(t) || reg->type !=3D SCALAR_VALUE) > > + if (!btf_type_is_scalar(t)) > > [Severity: High] > Does removing this SCALAR_VALUE check allow a BPF program to pass a point= er > register instead of a scalar to a kfunc's size argument, potentially > triggering a verifier_bug()? The issue is only temporary. It is not bisect safe but simplifies the patches. The issue will go away after patch 17 once check_mem_size_reg() is dispatched on KF_ARG_MEM_SIZE. > > If get_kfunc_ptr_arg_type() sets arg_mem_size purely based on BTF, > check_kfunc_args() will process the memory pointer argument, peek ahead a= t > the size argument, and call check_mem_size_reg(): A later patch will also defer mem+size checking to KF_ARG_MEM_SIZE similar to helper (look back) so check_mem_size_reg() will only be called after size if validated. > > kernel/bpf/verifier.c:check_kfunc_args() { > ... > ret =3D check_mem_size_reg(env, buff_reg, size_reg, argno, next_argno= , > BPF_READ | BPF_WRITE, true, meta); > ... > } > > This happens before the main loop reaches the size argument and ensures i= t is > a SCALAR_VALUE. > > If a pointer register with a fixed zero offset is passed, > check_mem_size_reg() might assume it is a valid scalar value of 0, pass t= he > boundary checks, and call mark_chain_precision(). This explicitly trigger= s > verifier_bug(env, "backtracking misuse") if the register is not a > SCALAR_VALUE. > > Could this lead to a kernel panic on systems with panic_on_warn=3D1? > > > return false; > > > > return btf_param_match_suffix(btf, arg, "__sz"); > > } > > -- > Sashiko AI review =C2=B7 https://sashiko.dev/#/patchset/20260801074633.15= [email protected]?part=3D12