summaryrefslogtreecommitdiff
path: root/tools/testing/selftests/bpf
diff options
context:
space:
mode:
authorAmery Hung <ameryhung@gmail.com>2026-09-11 15:04:11 -0700
committerAlexei Starovoitov <ast@kernel.org>2026-09-11 20:16:04 -0700
commit8fe994c80af271979cf2b3e830d4d3f7903edd50 (patch)
tree7fbc72ea3f2a563c67c4aaab923d3b36e34b98b0 /tools/testing/selftests/bpf
parent2bd4a975ea5d6394dcaa6c1380653ab68252c9c7 (diff)
downloadlinux-next-8fe994c80af271979cf2b3e830d4d3f7903edd50.tar.gz
linux-next-8fe994c80af271979cf2b3e830d4d3f7903edd50.zip
bpf: Consolidate function call pkt_access validation
check_func_arg() checks whether a helper permits packet pointers before dispatching argument-specific memory validation. check_kfunc_args() has no equivalent check, even though kfunc memory arguments may be backed by packet data. Move packet-access validation to check_helper_mem_access(), where the access direction is known and helper, kfunc, and global-subprogram memory arguments converge. Pass call metadata there so helpers continue to require bpf_func_proto::pkt_access, while writes through kfunc and global subprogram arguments use the program-type policy and set env->seen_direct_write. Keep call metadata when variable-size memory disables raw mode by clearing arg_raw_mem.regno instead, and pass it through the map-key path as well. This also makes kfunc and global-subprogram packet writes request the required writable-packet prologue and rejects them for program types that only support direct packet reads. Signed-off-by: Amery Hung <ameryhung@gmail.com> Link: https://lore.kernel.org/r/20260911220415.1396439-20-ameryhung@gmail.com Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Diffstat (limited to 'tools/testing/selftests/bpf')
-rw-r--r--tools/testing/selftests/bpf/progs/verifier_helper_packet_access.c4
1 files changed, 2 insertions, 2 deletions
diff --git a/tools/testing/selftests/bpf/progs/verifier_helper_packet_access.c b/tools/testing/selftests/bpf/progs/verifier_helper_packet_access.c
index 71cee3f58324..12786b72c694 100644
--- a/tools/testing/selftests/bpf/progs/verifier_helper_packet_access.c
+++ b/tools/testing/selftests/bpf/progs/verifier_helper_packet_access.c
@@ -258,7 +258,7 @@ l0_%=: r0 = 0; \
SEC("tc")
__description("helper access to packet: test11, cls unsuitable helper 1")
-__failure __msg("helper access to the packet")
+__failure __msg("function access to the packet")
__naked void test11_cls_unsuitable_helper_1(void)
{
asm volatile (" \
@@ -283,7 +283,7 @@ l0_%=: r0 = 0; \
SEC("tc")
__description("helper access to packet: test12, cls unsuitable helper 2")
-__failure __msg("helper access to the packet")
+__failure __msg("function access to the packet")
__naked void test12_cls_unsuitable_helper_2(void)
{
asm volatile (" \