Re: [PATCH bpf-next v6 0/9] bpf: add support for KASAN checks in JITed programs

Andrii Nakryiko <[email protected]>
Newsgroups org.kernel.vger.linux-kselftest,org.kernel.vger.bpf,org.kernel.vger.linux-kernel
Message-ID <CAEf4BzZHMmfKTAxq+eo1Muq16EveZrjO_ONdFvWTs1rwrhh3oQ@mail.gmail.com>
On Tue, Aug 4, 2026 at 10:45 AM Alexis Lothoré (eBPF Foundation)
<[email protected]> wrote:
>
> Hello,
> this is v6 of the series aiming to bring basic support for KASAN checks
> to BPF JITed programs. This new revision takes a step back on stack
> accessing insn tracking, as the previous attempt was fragile and
> error-prone, it brings back a simpler tracking, at the cost of some
> unecessary checks being inserted. While at it, I took this time a look
> at how many accesses are being instrumented, and how many of those
> are "wrongly" instrumented (because they access stack), and I got
> those rough numbers on the whole selftests set:
> - total: 451997 checks inserted
> - checks added on stack access (checking reg == BPF_REG_FP, not precise,
>   but gives a rough idea): 21786
>
> So that makes ~5% of "over-instrumented" accesses
>
> Original cover letter:
>
> "Traditional" KASAN allows to spot memory management mistakes by
> reserving a fraction of memory as "shadow memory" that will map to the
> rest of the memory and allow its monitoring. Each memory-accessing
> instruction is then instrumented at build time to call some ASAN check
> function, that will analyze the corresponding bits in shadow memory, and
> if it detects the access as invalid, trigger a detailed report. The goal
> of this series is to replicate this mechanism for BPF programs when they
> are being JITed into native instructions: that's then the JIT compiler
> that is in charge of inserting calls to the corresponding kasan checks,
> when a program is being loaded into the kernel. This task involves:
> - identifying at program load time the instructions performing memory
>   accesses
> - identifying those accesses properties (size ? read or write ?) to
>   define the relevant kasan check function to call
> - just before the identified instructions:
>   - perform the basic context saving (ie: saving registers)
>   - inserting a call to the relevant kasan check function
>   - restore context
> - whenever the instrumented program executes, if it performs an invalid
>   access, it triggers a kasan report identical to those instrumented on
>   kernel side at build time.
>
> The series comes with new selftests programs that generate a wide
> variety of kasan reports: those need the kernel to be running with
> kasan_multi_shot enabled.
>
> As discussed in [1], this series is based on some choices and
> assumptions:
> - it focuses on x86_64 for now, and so only on KASAN_GENERIC
> - not all memory accessing BPF instructions are being instrumented:
>   - it discards instructions accessing BPF program stack (already
>     monitored by page guards)
>   - it discards possibly faulting instructions, like BPF_PROBE_MEM or
>     BPF_PROBE_ATOMIC insns
>
> ---
> Changes in v6:
> - dropped instruction original offset tracking
> - when patching instructions, track former non_stack_access flag by
>   passing original insn to adjust_insn_aux_data
> - drop unecessary dep on CONFIG_KASAN in Kconfig
> - fold patch adding the emit_kasan_helper into the patch actually
>   calling it, to avoid an unused static function warning
> - move stack access check out of emit_kasan_check
> - replace hardcoded ip value by a computed value
> - add OoB testing
> - add fix commit to make cmdline_contains stricter
>
> - Link to v5: https://patch.msgid.link/[email protected]
>
> Changes in v5:
> - fixed a few instruction offset for generated fixups
> - fix insn marking for single insn patches
> - enforce more checks in tests
> - skip tests if kasan_multi_shot isn't enabled
> - Link to v4: https://patch.msgid.link/[email protected]
>
> Changes in v4:
> - fix insn_offs_in_patch leakage in bpf_convert_ctx_access
> - handle BPF_ATOMIC in is_mem_insn
> - correctly mark fixup instructions if a single insn is generated
> - clarify new kconfig (Andrey) and drop VMAP_STACK dep
> - refactor BPF_FETCH atomic handling in JIT loop
> - make kernel log reading resilient to unrelated, interleaved logs in
>   the selftests
> - make new test kfuncs depend on BPF_JIT_KASAN rather than KASAN_GENERIC
> - Link to v3: https://patch.msgid.link/[email protected]
>
> Changes in v3:
> - Do not insert KASAN instrumentation when dealing with cBPF
> - Fix stack-accessing insn tracking for verifier patches, as original
>   instruction location in the generated patch may vary
> - drop cBPF support for stack-accessing insn marking
> - make sure to flag correctly memory access if different verifier states
>   involve different memory types (eg: stack in one path, non-stack in
>   another path)
> - refactor BPF_ST handling in x86 JIT compiler
> - improve tests coverage (cover instrumentation for a few patches
>   emitted by the verifier)
> - Link to v2: https://patch.msgid.link/[email protected]
>
> Changes in v2:
> - declare asan functions as extern in JIT compiler rather than exposing
>   them in kasan header
> - invert stack-accessing instructions marking to make sure not to skip
>   instructions that could end up accessing to-be-checked memory
> - fix stack accesses marking when verifier patches instructions
> - add best effort marking for cBPF
> - add missing call depth accounting in jited instrumentation
> - skip unused registers in kasan instrumentation save/restore
> - remove faulty stack align in kasan instrumentation
> - drop commit skipping some jit-related tests
> - cover missing instructions: BPF_ST and atomics
> - completely rework tests: directly tune shadow memory, increase
>   coverage, do not consume kernel logs
> - Link to v1: https://patch.msgid.link/[email protected]
>
> To: Alexei Starovoitov <[email protected]>
> To: Daniel Borkmann <[email protected]>
> To: John Fastabend <[email protected]>
> To: Andrii Nakryiko <[email protected]>
> To: Martin KaFai Lau <[email protected]>
> To: Eduard Zingerman <[email protected]>
> To: Kumar Kartikeya Dwivedi <[email protected]>
> To: Song Liu <[email protected]>
> To: Yonghong Song <[email protected]>
> To: Jiri Olsa <[email protected]>
> To: Thomas Gleixner <[email protected]>
> To: Borislav Petkov <[email protected]>
> To: Dave Hansen <[email protected]>
> To: [email protected]
> To: "H. Peter Anvin" <[email protected]>
> To: Shuah Khan <[email protected]>
> To: Ingo Molnar <[email protected]>
> To: Andrey Konovalov <[email protected]>
> Cc: [email protected]
> Cc: Bastien Curutchet <[email protected]>
> Cc: Thomas Petazzoni <[email protected]>
> Cc: [email protected]
> Cc: [email protected]
> Cc: [email protected]
>
> ---
> Alexis Lothoré (eBPF Foundation) (9):
>       bpf: mark instructions accessing program stack
>       bpf: add BPF_JIT_KASAN for KASAN instrumentation of JITed programs
>       bpf, x86: refactor BPF_ST management in do_jit
>       bpf, x86: emit KASAN checks in x86 JITed programs
>       bpf, x86: enable KASAN for JITed programs on x86
>       selftests/bpf: make cmdline_contains stricter
>       selftests/bpf: add helpers for KASAN in JIT testing
>       selftests/bpf: move bpf_jit_harden helper into testing_helpers
>       selftests/bpf: add tests to validate KASAN on JIT programs
>

Alexis, please resend your patch set rebased on the latest bpf-next,
it has a merge conflict. Hopefully we'll get around to reviewing this
after the resend, thanks!

pw-bot: cr

>  arch/x86/Kconfig                                   |   1 +
>  arch/x86/net/bpf_jit_comp.c                        | 283 ++++++++++---
>  include/linux/bpf_verifier.h                       |   2 +
>  kernel/bpf/Kconfig                                 |  17 +
>  kernel/bpf/fixups.c                                |  45 +-
>  kernel/bpf/verifier.c                              |   9 +
>  .../selftests/bpf/prog_tests/bpf_insn_array.c      |  44 +-
>  tools/testing/selftests/bpf/prog_tests/kasan.c     | 454 ++++++++++++++++++++
>  tools/testing/selftests/bpf/progs/kasan.c          | 462 +++++++++++++++++++++
>  tools/testing/selftests/bpf/progs/kasan_harden.c   |  41 ++
>  .../testing/selftests/bpf/test_kmods/bpf_testmod.c |  55 +++
>  tools/testing/selftests/bpf/testing_helpers.c      |  32 ++
>  tools/testing/selftests/bpf/testing_helpers.h      |   1 +
>  tools/testing/selftests/bpf/unpriv_helpers.c       |  21 +-
>  tools/testing/selftests/bpf/unpriv_helpers.h       |   2 +
>  15 files changed, 1369 insertions(+), 100 deletions(-)
> ---
> base-commit: 5fb2b9636c7043f415a12e3336f2bf6983c9e93a
> change-id: 20260126-kasan-fcd68f64cd7b
>
> Best regards,
> --
> Alexis Lothoré (eBPF Foundation) <[email protected]>
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.