Re: [PATCH bpf-next v3 12/18] bpf: Classify kfunc mem_size args from BTF without register state

Amery Hung <[email protected]> Sun, 2 Aug 2026 14:32:06 -0700
Newsgroups dev.linux.lists.sashiko-reviews,org.kernel.vger.bpf
Message-ID <CAMB2axP6CHeFRbBFxqnM9Ficnp-KgT+sYKVFVbdLX1b6jraXhA@mail.gmail.com>
On Sat, Aug 1, 2026 at 1:09=E2=80=AFAM <[email protected]> wrote:
>
> Thank you for your contribution! Sashiko AI review found 1 potential issu=
e(s) to consider:
> - [High] Removing the register type check from `is_kfunc_arg_mem_size()` =
allows a BPF program to pass a pointer register as a memory size parameter =
(`__sz`), which triggers a `verifier_bug` and a kernel warning.
> --
>
> --- Patch [12]: [PATCH bpf-next v3 12/18] bpf: Classify kfunc mem_size ar=
gs from BTF without register state ---
> commit e7666ea9e561228e1708d772f8e42d33c514cde8
> Author: Amery Hung <[email protected]>
>
> bpf: Classify kfunc mem_size args from BTF without register state
>
> This commit removes register state checks from is_kfunc_arg_mem_size() an=
d
> is_kfunc_arg_const_mem_size(). It relies solely on BTF to classify kfunc
> memory size arguments to further decouple argument type classification fr=
om
> register state.
>
> > diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
> > index 6fc22a4e38b26..d65da54f9c0f8 100644
> > --- a/kernel/bpf/verifier.c
> > +++ b/kernel/bpf/verifier.c
> > @@ -10785,26 +10785,24 @@ static bool is_kfunc_rcu_protected(struct bpf=
_call_arg_meta *meta)
> >  }
> >
> >  static bool is_kfunc_arg_mem_size(const struct btf *btf,
> > -                               const struct btf_param *arg,
> > -                               const struct bpf_reg_state *reg)
> > +                               const struct btf_param *arg)
> >  {
> >       const struct btf_type *t;
> >
> >       t =3D btf_type_skip_modifiers(btf, arg->type, NULL);
> > -     if (!btf_type_is_scalar(t) || reg->type !=3D SCALAR_VALUE)
> > +     if (!btf_type_is_scalar(t))
>
> [Severity: High]
> Does removing this SCALAR_VALUE check allow a BPF program to pass a point=
er
> register instead of a scalar to a kfunc's size argument, potentially
> triggering a verifier_bug()?

The issue is only temporary. It is not bisect safe but simplifies the
patches. The issue will go away after patch 17 once
check_mem_size_reg() is dispatched on KF_ARG_MEM_SIZE.

>
> If get_kfunc_ptr_arg_type() sets arg_mem_size purely based on BTF,
> check_kfunc_args() will process the memory pointer argument, peek ahead a=
t
> the size argument, and call check_mem_size_reg():

A later patch will also defer mem+size checking to KF_ARG_MEM_SIZE
similar to helper (look back) so check_mem_size_reg() will only be
called after size if validated.

>
> kernel/bpf/verifier.c:check_kfunc_args() {
>     ...
>     ret =3D check_mem_size_reg(env, buff_reg, size_reg, argno, next_argno=
,
>                              BPF_READ | BPF_WRITE, true, meta);
>     ...
> }
>
> This happens before the main loop reaches the size argument and ensures i=
t is
> a SCALAR_VALUE.
>
> If a pointer register with a fixed zero offset is passed,
> check_mem_size_reg() might assume it is a valid scalar value of 0, pass t=
he
> boundary checks, and call mark_chain_precision(). This explicitly trigger=
s
> verifier_bug(env, "backtracking misuse") if the register is not a
> SCALAR_VALUE.
>
> Could this lead to a kernel panic on systems with panic_on_warn=3D1?
>
> >               return false;
> >
> >       return btf_param_match_suffix(btf, arg, "__sz");
> >  }
>
> --
> Sashiko AI review =C2=B7 https://sashiko.dev/#/patchset/20260801074633.15=
[email protected]?part=3D12