Re: [PATCH bpf-next v6 0/9] bpf: add support for KASAN checks in JITed programs
Andrii Nakryiko <[email protected]>
| Newsgroups | org.kernel.vger.linux-kselftest,org.kernel.vger.bpf,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <CAEf4BzZHMmfKTAxq+eo1Muq16EveZrjO_ONdFvWTs1rwrhh3oQ@mail.gmail.com> |
On Tue, Aug 4, 2026 at 10:45 AM Alexis Lothoré (eBPF Foundation) <[email protected]> wrote: > > Hello, > this is v6 of the series aiming to bring basic support for KASAN checks > to BPF JITed programs. This new revision takes a step back on stack > accessing insn tracking, as the previous attempt was fragile and > error-prone, it brings back a simpler tracking, at the cost of some > unecessary checks being inserted. While at it, I took this time a look > at how many accesses are being instrumented, and how many of those > are "wrongly" instrumented (because they access stack), and I got > those rough numbers on the whole selftests set: > - total: 451997 checks inserted > - checks added on stack access (checking reg == BPF_REG_FP, not precise, > but gives a rough idea): 21786 > > So that makes ~5% of "over-instrumented" accesses > > Original cover letter: > > "Traditional" KASAN allows to spot memory management mistakes by > reserving a fraction of memory as "shadow memory" that will map to the > rest of the memory and allow its monitoring. Each memory-accessing > instruction is then instrumented at build time to call some ASAN check > function, that will analyze the corresponding bits in shadow memory, and > if it detects the access as invalid, trigger a detailed report. The goal > of this series is to replicate this mechanism for BPF programs when they > are being JITed into native instructions: that's then the JIT compiler > that is in charge of inserting calls to the corresponding kasan checks, > when a program is being loaded into the kernel. This task involves: > - identifying at program load time the instructions performing memory > accesses > - identifying those accesses properties (size ? read or write ?) to > define the relevant kasan check function to call > - just before the identified instructions: > - perform the basic context saving (ie: saving registers) > - inserting a call to the relevant kasan check function > - restore context > - whenever the instrumented program executes, if it performs an invalid > access, it triggers a kasan report identical to those instrumented on > kernel side at build time. > > The series comes with new selftests programs that generate a wide > variety of kasan reports: those need the kernel to be running with > kasan_multi_shot enabled. > > As discussed in [1], this series is based on some choices and > assumptions: > - it focuses on x86_64 for now, and so only on KASAN_GENERIC > - not all memory accessing BPF instructions are being instrumented: > - it discards instructions accessing BPF program stack (already > monitored by page guards) > - it discards possibly faulting instructions, like BPF_PROBE_MEM or > BPF_PROBE_ATOMIC insns > > --- > Changes in v6: > - dropped instruction original offset tracking > - when patching instructions, track former non_stack_access flag by > passing original insn to adjust_insn_aux_data > - drop unecessary dep on CONFIG_KASAN in Kconfig > - fold patch adding the emit_kasan_helper into the patch actually > calling it, to avoid an unused static function warning > - move stack access check out of emit_kasan_check > - replace hardcoded ip value by a computed value > - add OoB testing > - add fix commit to make cmdline_contains stricter > > - Link to v5: https://patch.msgid.link/[email protected] > > Changes in v5: > - fixed a few instruction offset for generated fixups > - fix insn marking for single insn patches > - enforce more checks in tests > - skip tests if kasan_multi_shot isn't enabled > - Link to v4: https://patch.msgid.link/[email protected] > > Changes in v4: > - fix insn_offs_in_patch leakage in bpf_convert_ctx_access > - handle BPF_ATOMIC in is_mem_insn > - correctly mark fixup instructions if a single insn is generated > - clarify new kconfig (Andrey) and drop VMAP_STACK dep > - refactor BPF_FETCH atomic handling in JIT loop > - make kernel log reading resilient to unrelated, interleaved logs in > the selftests > - make new test kfuncs depend on BPF_JIT_KASAN rather than KASAN_GENERIC > - Link to v3: https://patch.msgid.link/[email protected] > > Changes in v3: > - Do not insert KASAN instrumentation when dealing with cBPF > - Fix stack-accessing insn tracking for verifier patches, as original > instruction location in the generated patch may vary > - drop cBPF support for stack-accessing insn marking > - make sure to flag correctly memory access if different verifier states > involve different memory types (eg: stack in one path, non-stack in > another path) > - refactor BPF_ST handling in x86 JIT compiler > - improve tests coverage (cover instrumentation for a few patches > emitted by the verifier) > - Link to v2: https://patch.msgid.link/[email protected] > > Changes in v2: > - declare asan functions as extern in JIT compiler rather than exposing > them in kasan header > - invert stack-accessing instructions marking to make sure not to skip > instructions that could end up accessing to-be-checked memory > - fix stack accesses marking when verifier patches instructions > - add best effort marking for cBPF > - add missing call depth accounting in jited instrumentation > - skip unused registers in kasan instrumentation save/restore > - remove faulty stack align in kasan instrumentation > - drop commit skipping some jit-related tests > - cover missing instructions: BPF_ST and atomics > - completely rework tests: directly tune shadow memory, increase > coverage, do not consume kernel logs > - Link to v1: https://patch.msgid.link/[email protected] > > To: Alexei Starovoitov <[email protected]> > To: Daniel Borkmann <[email protected]> > To: John Fastabend <[email protected]> > To: Andrii Nakryiko <[email protected]> > To: Martin KaFai Lau <[email protected]> > To: Eduard Zingerman <[email protected]> > To: Kumar Kartikeya Dwivedi <[email protected]> > To: Song Liu <[email protected]> > To: Yonghong Song <[email protected]> > To: Jiri Olsa <[email protected]> > To: Thomas Gleixner <[email protected]> > To: Borislav Petkov <[email protected]> > To: Dave Hansen <[email protected]> > To: [email protected] > To: "H. Peter Anvin" <[email protected]> > To: Shuah Khan <[email protected]> > To: Ingo Molnar <[email protected]> > To: Andrey Konovalov <[email protected]> > Cc: [email protected] > Cc: Bastien Curutchet <[email protected]> > Cc: Thomas Petazzoni <[email protected]> > Cc: [email protected] > Cc: [email protected] > Cc: [email protected] > > --- > Alexis Lothoré (eBPF Foundation) (9): > bpf: mark instructions accessing program stack > bpf: add BPF_JIT_KASAN for KASAN instrumentation of JITed programs > bpf, x86: refactor BPF_ST management in do_jit > bpf, x86: emit KASAN checks in x86 JITed programs > bpf, x86: enable KASAN for JITed programs on x86 > selftests/bpf: make cmdline_contains stricter > selftests/bpf: add helpers for KASAN in JIT testing > selftests/bpf: move bpf_jit_harden helper into testing_helpers > selftests/bpf: add tests to validate KASAN on JIT programs > Alexis, please resend your patch set rebased on the latest bpf-next, it has a merge conflict. Hopefully we'll get around to reviewing this after the resend, thanks! pw-bot: cr > arch/x86/Kconfig | 1 + > arch/x86/net/bpf_jit_comp.c | 283 ++++++++++--- > include/linux/bpf_verifier.h | 2 + > kernel/bpf/Kconfig | 17 + > kernel/bpf/fixups.c | 45 +- > kernel/bpf/verifier.c | 9 + > .../selftests/bpf/prog_tests/bpf_insn_array.c | 44 +- > tools/testing/selftests/bpf/prog_tests/kasan.c | 454 ++++++++++++++++++++ > tools/testing/selftests/bpf/progs/kasan.c | 462 +++++++++++++++++++++ > tools/testing/selftests/bpf/progs/kasan_harden.c | 41 ++ > .../testing/selftests/bpf/test_kmods/bpf_testmod.c | 55 +++ > tools/testing/selftests/bpf/testing_helpers.c | 32 ++ > tools/testing/selftests/bpf/testing_helpers.h | 1 + > tools/testing/selftests/bpf/unpriv_helpers.c | 21 +- > tools/testing/selftests/bpf/unpriv_helpers.h | 2 + > 15 files changed, 1369 insertions(+), 100 deletions(-) > --- > base-commit: 5fb2b9636c7043f415a12e3336f2bf6983c9e93a > change-id: 20260126-kasan-fcd68f64cd7b > > Best regards, > -- > Alexis Lothoré (eBPF Foundation) <[email protected]> >