Re: [PATCH bpf-next v2 0/2] bpf: Fix sleepable check for tracing prog

Andrii Nakryiko <[email protected]>
Newsgroups org.kernel.vger.linux-kselftest,org.kernel.vger.bpf,org.kernel.vger.linux-kernel,org.kernel.vger.netdev
Message-ID <CAEf4BzaoQaODE4F1wfrp37=83bePY=gKpunacKr3rmO230+B3Q@mail.gmail.com>
On Sat, Jul 25, 2026 at 6:27 AM Leon Hwang <[email protected]> wrote:
>
> When CONFIG_FUNCTION_ERROR_INJECTION is disabled, a sleepable tracing prog
> is allowed to attach to '__x64_'-alike prefix symbols.
>
> It is because the verifier does not verify whether the symbol is a kernel
> function or a bpf prog. That said, a sleepable tracing prog is allowed to
> attach to a bpf prog target whose name has '__x64_'-alike prefix.
>
> For example, a sleepable fentry prog attaches to a '__x64_sys_nop' XDP

we do have addr, so we should be able to distinguish between attaching
to kernel function vs BPF program, no?

> prog, and copies buffer from a user pointer with bpf_copy_from_user()
> helper. After attaching the XDP prog to lo interface, the kernel BUG
> could be triggered by 'ping -c 1 -W 1 127.0.0.1':
>
> [    3.460756] BUG: sleeping function called from invalid context at kernel/bpf/trampoline.c:1324
>
> Fix it by disallowing sleepable tracing prog always when its target is
> bpf prog.

what happens when we freplace sleepable BPF program/subprogram with
another sleepable BPF subprogram? And same question for sleepable
fentry/fexit program attaching to sleepable BPF program? Is it
something that just cannot work or we can actually allow that?

>
> Changes:
> v1 -> v2:
> * Drop redundant 'prog->sleepable' check.
> * Collect Acked-by from Viktor, Thanks.
> * v1: https://lore.kernel.org/bpf/[email protected]/
>
> Leon Hwang (2):
>   bpf: Fix sleepable check for tracing prog
>   selftests/bpf: Verify rejection of sleepable tracing prog
>
>  kernel/bpf/verifier.c                         |  9 ++-
>  .../selftests/bpf/prog_tests/fexit_bpf2bpf.c  | 57 +++++++++++++++++++
>  .../selftests/bpf/progs/fentry_sleepable.c    | 19 +++++++
>  tools/testing/selftests/bpf/progs/xdp_dummy.c |  6 ++
>  4 files changed, 88 insertions(+), 3 deletions(-)
>  create mode 100644 tools/testing/selftests/bpf/progs/fentry_sleepable.c
>
> --
> 2.55.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.