Re: [PATCH bpf-next v5 10/14] bpf: Report Resource Lifetime reference leaks
Eduard Zingerman <[email protected]>
| Newsgroups | org.kernel.vger.bpf |
|---|---|
| Message-ID | <[email protected]> |
On Sat, 2026-08-15 at 07:34 +0000, [email protected] wrote: > > diff --git a/kernel/bpf/diagnostics.c b/kernel/bpf/diagnostics.c > > index 058574a1411e..5d20ea9e470e 100644 > > --- a/kernel/bpf/diagnostics.c > > +++ b/kernel/bpf/diagnostics.c > > [ ... ] > > > @@ -1735,6 +1736,96 @@ void bpf_diag_mem_bounds(struct bpf_verifier_env *env, u32 insn_idx, int regno, > > env, "Add or adjust a bounds check that proves offset + access_size stays within the object."); > > } > > > > +static const char *diag_lock_name(const struct bpf_reference_state *lock) > > +{ > > + switch (lock->type) { > > + case REF_TYPE_LOCK: > > + return "bpf_spin_lock"; > > + case REF_TYPE_RES_LOCK: > > + return "resource spin lock"; > > + case REF_TYPE_RES_LOCK_IRQ: > > + return "IRQ-saving resource spin lock"; > > + default: > > + return "lock"; > > + } > > +} > > + > > +static void diag_res_report(struct bpf_verifier_env *env, u32 insn_idx, const char *problem, > > + const char *reason) > > +{ > > + bpf_diag_header(env, RESOURCE_LIFETIME_SAFETY, problem); > > + diag_reason(env, "%s", reason); > > + > > + diag_section(env, "At"); > > + bpf_diag_source(env, insn_idx, "error", "%s", problem); > > +} > > [ ... ] > > > +void bpf_diag_leak(struct bpf_verifier_env *env, u32 ref_id, u32 alloc_insn, u32 fail_insn) > > +{ > > + struct bpf_diag_history_opts opts = { > > + .scope = BPF_DIAG_HISTORY_SCOPE_REF, > > + .ref_id = ref_id, > > + }; > > + > > + bpf_diag_header(env, RESOURCE_LIFETIME_SAFETY, "unreleased resource"); > > + diag_reason( > > + env, "Owned resource (id=%u) was acquired at instruction %u and still needs to be released before this exit path.", > > + ref_id, alloc_insn); > > + > > + diag_section(env, "At"); > > + bpf_diag_source(env, fail_insn, "error", > > + "owned resource (id=%u) still needs release", ref_id); > > + > > + diag_print_history(env, &opts); > > + > > + diag_suggestion( > > + env, "Release or transfer ownership of the acquired resource on every path before the program exits."); > > +} > > Does the exit-path wording fit all three call sites? bpf_diag_leak() > says "still needs to be released before this exit path" and "before > the program exits", but check_reference_leak() is reached from three > different code paths via check_resource_leak(): > > process_bpf_exit_full() <- actual program exit > check_helper_call() <- tail_call rejection > check_ld_abs() <- BPF_LD_[ABS|IND] rejection > > For BPF_LD_[ABS|IND], the reference is not lost at an exit at all. Bot is confused.