summaryrefslogtreecommitdiff
path: root/tools/lib/bpf
AgeCommit message (Collapse)Author
6 dayslibbpf: Keep format strings of bpf_printk() in .rodata.strAlexei Starovoitov
bpf_printk(), BPF_SNPRINTF(), BPF_SEQ_PRINTF() and bpf_stream_printk() copy the format into a static const array, which the compiler puts into .rodata. When global data of the object is in arena .rodata is there too and the helper doesn't take the format: R1 type=scalar expected=fp, pkt, pkt_meta, map_key, map_value, mem, ringbuf_mem, buf, trusted_ptr_, ctx String literals are in .rodata.str1.1, which libbpf keeps in a read-only map. No compiler flag moves a named array there. Put the arrays into .rodata.str with a section attribute. An object that uses the macros gets one more map, .rodata.str. Signed-off-by: Alexei Starovoitov <ast@kernel.org> Link: https://lore.kernel.org/bpf/20261002124714.180012-14-alexei.starovoitov@gmail.com Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
6 dayslibbpf: Keep global data in arena when the object has .arena.dataAlexei Starovoitov
All memory of a Rust program is arena, global data included. There are no address spaces in Rust to say so. LLVM also drops bounds checks of indexes into constant tables of core that it proved, so the verifier can't check the access as access to map value. The object asks for it with a section named .arena.data. What is in the section doesn't matter: #[used] #[link_section = ".arena.data"] static DATA_IN_ARENA: u8 = 0; or in C: char data_in_arena SEC(".arena.data"); There is nothing to tell to libbpf, so bpftool, veristat and other loaders work with such objects as they are. When the object has the section: - .data, .bss and .rodata sections are appended to arena data after __arena variables, at the alignment of the section. Like __arena variables the data is at the end of arena. - relocations of insns against the sections become relocations against the arena map. - array maps of the sections are not created. - when the object has no arena map libbpf creates one that is as large as the data. bpf_object__find_map_by_name(obj, "arena") finds it and bpf_map__set_max_entries() makes room for allocations. __arena variables still need the arena map to be declared. Read-only sections that stay frozen array maps: - .data.rel.ro and sections that have relocations in them. The kernel recognizes pointers to functions in them by value for callx. - .rodata.str*. They hold const strings for __str arguments of kfuncs. A copy of them is in arena too. The program dereferences pointers that it loads from data, so pointers to data that are stored in data become addresses of arena, wherever the pointer is. The arena map is created ahead of the other maps then, since its address goes into their data. A pointer to .rodata.str* points to the copy. A pointer to a section that is not in arena fails the load: sec '.data': pointer to 'tbl' at offset 8 can't be resolved: sec '.data.rel.ro' is not in arena So does an arena that is pinned or reused. libbpf doesn't mmap it, so its address is not known. Programs of the object are loaded with BPF_F_ARENA_SCALAR, since they access the data through plain numbers. Signed-off-by: Alexei Starovoitov <ast@kernel.org> Link: https://lore.kernel.org/bpf/20261002124714.180012-13-alexei.starovoitov@gmail.com Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
10 dayslibbpf: Fix cleanup on invalid CO-RE relocation offsetsLuis Vieira
bpf_object__relocate_core() allocates a CO-RE candidate cache before processing relocation records. Two instruction offset validation failures return -EINVAL directly instead of going through the common cleanup path. These checks were moved into bpf_object__relocate_core() when bpf_core_apply_relo() was split, preserving direct returns that were safe in the previous helper but now bypass cleanup. Route both failures through the out path so the candidate cache and target BTF override are released. Signed-off-by: Luis Vieira <luisflavieira@gmail.com> Signed-off-by: Alexei Starovoitov <ast@kernel.org> Link: https://patch.msgid.link/20260929-libbpf-core-relo-cleanup-v1-1-c9cd0b5775a9@gmail.com
10 dayslibbpf: Render decl_tags in btf_dumpIhor Solodrai
BTF_KIND_DECL_TAG is an attribute on a declaration: with kind_flag=0 the tag name is the argument of a btf_decl_tag(), and with kind_flag=1 it encodes a complete __attribute__. When doing btf_dump, render both forms at every declaration btf_dump emits - a record, a record member and a typedef: struct foo { ... } __attribute__((bar)); struct foo { int a __attribute__((bar)); }; typedef struct { ... } __attribute__((bar)) foo_t; A decl tag is a standalone type pointing at its target. Build an index of decl tags in btf_dump_resize(). Keep it as a flat array sorted by (target ID, tag ID). This allows for a stable emission order in btf_dump_emit_decl_tags(). btf_dump_emit_decl_tags() binary searches for where the target's entries would begin and walks tags while the target matches. A record shares its target with its members, so the component_idx is matched there. A record attribute goes after the closing brace, where __attribute__((packed)) already goes. A member attribute goes after the bit-field width: clang rejects one between the declarator and the ':'. A typedef takes it after the declarator, so a typedef of an anonymous record can carry two groups at once, one binding to the record and one to the typedef. This closes a generic gap in btf_dump, which silently dropped every decl tag it was given. Signed-off-by: Ihor Solodrai <ihor.solodrai@linux.dev> Signed-off-by: Alexei Starovoitov <ast@kernel.org> Acked-by: Eduard Zingerman <eddyz87@gmail.com> Link: https://patch.msgid.link/20260929234608.48503-3-ihor.solodrai@linux.dev
10 dayslibbpf: Walk types in btf_dump_resize(), not in mark_referenced()Ihor Solodrai
btf_dump_mark_referenced() both walks every type added since the last resize and decides what each one references. Move the walk out to btf_dump_resize() and hand the function one type at a time, so a second per-type job can share the same pass instead of adding another one. No functional change. Signed-off-by: Ihor Solodrai <ihor.solodrai@linux.dev> Signed-off-by: Alexei Starovoitov <ast@kernel.org> Acked-by: Eduard Zingerman <eddyz87@gmail.com> Link: https://patch.msgid.link/20260929234608.48503-2-ihor.solodrai@linux.dev
14 dayslibbpf: Fix static linking of externs placed in allocated sectionsAndrii Nakryiko
Clang puts an extern variable that ends up with a section, an extern map in .maps or an arena global in .addr_space.<N>, into the BTF DATASEC of that section, next to the object's own definitions and with offset 0. Unlike .kconfig and .ksyms, that section is a real allocated ELF section whenever the same object also defines a variable in it. The static linker handles such externs incorrectly in two ways. The output symbol of an unresolved extern gets the destination section's index and offset instead of staying SHN_UNDEF with a zero value. For ephemeral sections both are 0, so this only shows up for allocated sections, where the extern turns into a size-zero NOTYPE definition. Linking the output again then fails with "conflicting non-weak symbol" against a strong definition of that variable, or, against a weak one, keeps the bogus symbol and resolves every reference to offset 0 of the section. And if the section of the object with the extern doesn't start at offset 0 of the output section, the output symbol fails linker_sanity_check_elf_symtab() on the next link with "invalid extern symbol" before any of that. When the extern is resolved by a later object in the same link, the DATASEC entry appended for the extern keeps its placeholder offset, as linker_append_btf() only updates the size of an existing entry. The ELF symbol and the BTF secinfo then disagree and skeleton generation fails with: Error: Something is wrong for .addr_space.1's variable #1: need offset 0, already at 8. Keep unresolved externs SHN_UNDEF with a zero value in the output symbol table, and once an extern is resolved take the offset of its DATASEC entry from the ELF symbol, which already accounts for weak vs. strong resolution. Signed-off-by: Andrii Nakryiko <andrii@kernel.org> Signed-off-by: Alexei Starovoitov <ast@kernel.org> Link: https://patch.msgid.link/20260926000243.2830819-1-andrii@kernel.org
2026-09-25libbpf: Add bpf_prog_stream_open()Kumar Kartikeya Dwivedi
Expose the BPF_PROG_STREAM_OPEN command through a low-level libbpf wrapper. The options structure carries stream open flags, including non-blocking mode, while leaving room for future extensions. Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com> Signed-off-by: Alexei Starovoitov <ast@kernel.org> Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com> Link: https://patch.msgid.link/20260925045536.1480933-4-memxor@gmail.com
2026-09-24Merge git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf 7.3-rc4Alexei Starovoitov
Cross-merge BPF and other fixes after downstream PR. Conflicts: kernel/bpf/helpers.c tools/testing/selftests/bpf/prog_tests/cb_refs.c tools/testing/selftests/bpf/prog_tests/verifier.c Signed-off-by: Alexei Starovoitov <ast@kernel.org>
2026-09-24libbpf: Add support for BTF kinds LOC[_PARAM|_PROTO|SEC]Alan Maguire
Add support for new kinds to libbpf. BTF_KIND_LOC_PARAM and BTF_KIND_LOC_PROTO are dedup-able so add support for their deduplication, whereas since BTF_KIND_LOCSEC contains a unique offset it is not. LOC_PARAM is considered a primary type since it contains no external references; LOC_PROTO is a reference type consisting of LOC_PARAM references so they are handled in the primary and reference dedup phases respectively. For BTF field iteration, BTF_KIND_LOCSEC needs 2 m_offs[] values for the associated KIND_FUNC and KIND_LOC_PROTO type ids in each LOCSEC entry. Add APIs to add location param, location prototypes and location sections and btf_is_* tests, data accessors for each. For BTF distillation we add location info to split BTF. Signed-off-by: Alan Maguire <alan.maguire@oracle.com> Signed-off-by: Alexei Starovoitov <ast@kernel.org> Acked-by: Eduard Zingerman <eddyz87@gmail.com> Link: https://patch.msgid.link/20260924111428.75957-3-alan.maguire@oracle.com
2026-09-24libbpf: Support pointers to functions in read-only data in light skeletonAlexei Starovoitov
Light skeleton doesn't create maps. The loader prog does at run time. Teach gen_loader to create a copy of .rodata map with offsets of functions for a prog, see create_func_ptr_map(). - Such maps are not maps of the object and are not in the loader ctx. Reserve slots in fd_array after the maps of the object for them and close their fds when the loader is done or fails. The progs hold them. Which progs have callx is not known when the loader is initialized, so reserve for every prog if .text has callx and for the progs that have callx otherwise. - Add bpf_gen__func_ptr_map_create() that emits map create, update, freeze and returns the index in fd_array for ld_imm64 BPF_PSEUDO_MAP_IDX_VALUE. - User space can set .rodata before loading the skeleton, see initial_value in bpf_map_desc. Copy it into the copy of the map as well and store the offsets of functions on top, since user space doesn't have them. - Light skeleton can be generated for a target of another endianness. Store the offsets in the byte order of the object. Signed-off-by: Alexei Starovoitov <ast@kernel.org> Link: https://patch.msgid.link/20260924031042.1690890-15-alexei.starovoitov@gmail.com
2026-09-24libbpf: Treat .data.rel.ro as read-only dataAlexei Starovoitov
PIC code keeps constants with pointers, e.g. vtables, in .data.rel.ro instead of .rodata. Nothing writes there after relocation. libbpf treats every .data* section as writable, while the kernel looks for pointers to functions in frozen read-only maps only. Make .data.rel.ro and .data.rel.ro.* maps read-only and frozen like .rodata and collect pointers to functions there. Signed-off-by: Alexei Starovoitov <ast@kernel.org> Link: https://patch.msgid.link/20260924031042.1690890-14-alexei.starovoitov@gmail.com
2026-09-24libbpf: Resolve pointers to functions in read-only dataAlexei Starovoitov
The kernel recognizes a pointer to a function in frozen read-only array map by value: byte offset of a static function in the program. Make it work for tables of functions, struct ops, vtables in .rodata: static const struct shape_ops square_ops = { 1, area, 10, perimeter }; ... return ops->area(x) * ops->scale; is compiled into r3 = *(u64 *)(r1 + 8) callx r3 where 'area' in .rodata is R_BPF_64_ABS64 relocation against .text. - Collect relocations in .rodata* that are aligned pointers to functions. Relocations in data were ignored. The rest still are. - Append all static functions that the section points to, since any of them can be called, if the prog refers to the section and has callx. callx cannot call global functions. Don't pull them in. Such pointer is NULL. - Functions have different offsets in different progs, so create a copy of the map per prog and store the offsets there. The kernel replaces them with addresses at load and the prog must be the only user of the map. The map of the section itself is left as-is. - Progs without callx cannot call them and the kernel doesn't look for pointers in their data. They keep using the map of the section and nothing is appended to them. - The kernel treats any aligned u64 that matches an offset of a static function as a pointer. Warn if data has one that isn't. Light skeleton is not supported yet. Signed-off-by: Alexei Starovoitov <ast@kernel.org> Link: https://patch.msgid.link/20260924031042.1690890-13-alexei.starovoitov@gmail.com
2026-09-24libbpf: Support pointers to static functions in data when linkingAlexei Starovoitov
A pointer to a static function in data, e.g. static int (* const handlers[])(void *ctx) = { foo, bar }; is R_BPF_64_ABS64 relocation against .text section symbol with the offset of the function stored in place. The linker rejects it: relocation against STT_SECTION in non-exec section is not supported! so an object with a table of static functions cannot go through 'bpftool gen object', which all selftests do. Functions move by the offset of input .text in the output section. Add it to the pointer. Swap bytes if the object is of foreign endianness, since data sections are kept in the byte order of the object. Signed-off-by: Alexei Starovoitov <ast@kernel.org> Link: https://patch.msgid.link/20260924031042.1690890-12-alexei.starovoitov@gmail.com
2026-09-21libbpf: Validate ELF symbol table entry sizeLuis Vieira
elf_sym_iter_new() calculates the number of symbols by dividing the symbol table data size by sh_entsize. A malformed ELF file with a zero sh_entsize causes a division by zero. Reject symbol table sections with a zero entry size before calculating the number of symbols. Signed-off-by: Luis Vieira <luisflavieira@gmail.com> Signed-off-by: Andrii Nakryiko <andrii@kernel.org> Link: https://lore.kernel.org/bpf/20260916-libbpf-elf-entsize-fix-v1-1-cf181da33eab@gmail.com
2026-09-21bpftool: Compute map size of light skeletons at runtimeLeon Hwang
bpftool rounds memory-mapped data map sizes to the host page size when generating a light skeleton. The generated code therefore uses a 64K mapping size when bpftool runs on a 64K-page host, even if the skeleton runs on a 4K-page target. The target rejects the oversized map mmap(), causing failure of loading the light skeleton. When try to run 64K-page selftests on 4K-page VM, the error message does not provide the reason about page size. test_atomics:PASS:atomics skeleton open 0 nsec test_atomics:FAIL:atomics skeleton load unexpected error: -12 (errno 22) #15 atomics:FAIL Pass the original map value size and max entries to the generated code and round mmap size to the runtime page size in the user-space light skeleton helpers. This keeps generated light skeletons independent of the build host page size. Fixes: d510296d331a ("bpftool: Use syscall/loader program in "prog load" and "gen skeleton" command.") Signed-off-by: Leon Hwang <leon.hwang@linux.dev> Signed-off-by: Andrii Nakryiko <andrii@kernel.org> Acked-by: Quentin Monnet <qmo@kernel.org> Link: https://lore.kernel.org/bpf/20260915161450.96249-1-leon.hwang@linux.dev
2026-09-21libbpf: Support selective kernel module BTF loading via bpf_object_open_optsFuyu Zhao
Add btf_module_allowlist and btf_module_allowlist_cnt fields to bpf_object_open_opts to limit which kernel module BTFs libbpf is allowed to load. When the option is not specified, the existing behavior remains unchanged. An explicitly specified empty allowlist prevents libbpf from consulting any kernel module BTFs. The allowlist limits which kernel module BTFs libbpf will consult wherever module BTF might be needed. Suggested-by: Andrii Nakryiko <andrii@kernel.org> Signed-off-by: Fuyu Zhao <zhaofuyu@vivo.com> Signed-off-by: Andrii Nakryiko <andrii@kernel.org> Link: https://lore.kernel.org/bpf/20260915124104.77287-2-zhaofuyu@vivo.com
2026-09-19libbpf: Support attaching struct_ops to a cgroupMartin KaFai Lau
Add bpf_map__attach_cgroup_opts() to attach a struct_ops map to a cgroup through a BPF link. Also extend struct bpf_prog_query_opts with a type_id field so a BPF_STRUCT_OPS query on a cgroup can select the struct_ops type to enumerate. Signed-off-by: Martin KaFai Lau <martin.lau@kernel.org> Signed-off-by: Amery Hung <ameryhung@gmail.com> Signed-off-by: Alexei Starovoitov <ast@kernel.org> Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com> Link: https://patch.msgid.link/20260917200542.3689605-14-ameryhung@gmail.com
2026-09-17libbpf: Reject truncated ldimm64 CO-RE relocationsKumar Kartikeya Dwivedi
CO-RE relocation of an ldimm64 instruction operates on two instruction slots. A malformed BPF ELF can end a function after the first slot and attach a CO-RE relocation to it. libbpf allocates the instruction array according to the function symbol size, so the shared relocation code would then access beyond the allocation. Reject a terminal ldimm64 in libbpf's relocation loop, where the program length is available, before resolving or applying the relocation. Both resolved and unresolved relocations validate the absent second slot, and unresolved relocation poisoning would additionally write past the array. The in-kernel caller is protected by the verifier's early instruction-stream check before it applies CO-RE relocations. Fixes: eacaaed784e2 ("libbpf: Implement enum value-based CO-RE relocations") Reported-by: Sashiko <sashiko-bot@kernel.org> Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com> Link: https://lore.kernel.org/20260914140852.03DA21F0089B@smtp.kernel.org Link: https://patch.msgid.link/20260917233222.2542500-11-memxor@gmail.com Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
2026-09-17bpf: Restrict CO-RE poisoning to relocatable instructionsKumar Kartikeya Dwivedi
CO-RE relocation records can name any instruction offset. When a relocation cannot be resolved, bpf_core_patch_insn() currently poisons its target before checking whether that instruction is a valid relocation target. Malformed metadata can therefore replace jumps, calls, exits, register-source arithmetic, or non-immediate loads instead of failing at the relocation step. Handle poisoning only after the instruction has passed the same class and operand-form checks used for a resolved relocation. Route invalid forms through the existing diagnostic and return a hard error. Keep poisoning supported instructions, including both halves of a plain ldimm64, so an unresolved relocation in dead code remains valid. Extend bpf_core_poison_insn() to poison both halves of ldimm64, and return its status directly from each validated instruction case. This avoids routing the success path through a common label and leaves the helper free to report errors. The shared relocation code applies this restriction to both libbpf and in-kernel CO-RE. Fixes: d7a252708dbc ("libbpf: Improve handling of failed CO-RE relocations") Reported-by: Nicholas Carlini <npc@anthropic.com> Suggested-by: Nicholas Carlini <npc@anthropic.com> Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com> Acked-by: Eduard Zingerman <eddyz87@gmail.com> Link: https://patch.msgid.link/20260917233222.2542500-7-memxor@gmail.com Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
2026-09-17libbpf: Reject local struct_ops bitfields before data accessMingpei CAO
A local struct_ops type can contain a bitfield absent from the corresponding kernel BTF type. bpf_map__init_kern_struct_ops() checks whether data for an absent local member is zero. For a bitfield, member->offset contains the bit offset and field width. bpf_map__init_kern_struct_ops() used the encoded value to calculate the member data pointer before rejecting the bitfield. The zero-data check could therefore read outside st_ops->data and crash libbpf. Reject local bitfields before calculating the member data pointer. Keep the existing rejection for bitfields in the kernel type. Fixes: c911fc61a7ce ("libbpf: Skip zeroed or null fields if not found in the kernel type.") Signed-off-by: Mingpei CAO <caomingpei@gmail.com> Signed-off-by: Andrii Nakryiko <andrii@kernel.org> Reviewed-by: Amery Hung <ameryhung@gmail.com> Link: https://lore.kernel.org/bpf/20260915162252.473044-2-caomingpei@gmail.com
2026-09-17libbpf: Fix program log buffer size validationLuis Vieira
bpf_program__set_log_buf() checks the existing prog->log_size instead of the incoming log_size argument when enforcing the UINT_MAX limit. As a result, an oversized value can be accepted. The setter also accepts a non-NULL log_buf with a zero log_size, while bpf_prog_load() rejects mismatched log buffer and size values. Validate the log buffer and size pair consistently with bpf_prog_load(), and check the supplied log_size against UINT_MAX. Signed-off-by: Luis Vieira <luisflavieira@gmail.com> Signed-off-by: Andrii Nakryiko <andrii@kernel.org> Acked-by: Mykyta Yatsenko <yatsenko@meta.com> Link: https://lore.kernel.org/bpf/20260915-libbpf-log-buf-fix-v2-1-2feca3fa4842@gmail.com
2026-09-14libbpf: Add bpf_program__add_flags() and bpf_program__clear_flags()Toke Høiland-Jørgensen
When changing BPF program flags, applications often need to just add or remove a single flag, without touching the existing ones. When using the bpf_program__set_flags() function, this requires reading the existing flags and doing bitwise manipulations before resetting the result, which is slightly awkward to do, and easy to forget. Add two new convenience helpers, bpf_program__add_flags() and bpf_program__clear_flags(), which wraps bpf_program__set_flags() in the bitwise operations required to modify flags without clobbering the existing ones. Suggested-by: Andrii Nakryiko <andrii.nakryiko@gmail.com> Signed-off-by: Toke Høiland-Jørgensen <toke@redhat.com> Signed-off-by: Andrii Nakryiko <andrii@kernel.org> Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev> Acked-by: Eduard Zingerman <eddyz87@gmail.com> Acked-by: Ihor Solodrai <ihor.solodrai@linux.dev> Link: https://lore.kernel.org/bpf/20260912084109.432834-1-toke@redhat.com
2026-09-13libbpf: fix log level propagation for light skeleton loadersMahe Tardy
bpftool's -d option is documented to enable bpf_trace_printk() messages from the generated syscall loader when used with -L as specified in commit d510296d331a ("bpftool: Use syscall/loader program in "prog load" and "gen skeleton" command.") However commit b59e4ce8bcaa ("bpftool: Switch bpf_object__load_xattr() to bpf_object__load()") changed bpftool to use bpf_object__load() which call the internal bpf_object_load with extra_log_level to 0 instead of bpf_object__load_xattr with the user request log_level. All the plumbing was still there to generate the bpf_trace_printk() instructions from the generator but was now unreachable because bpf_gen__init() was called with extra_log_level to 0, leaving gen->log_level at 0. This uses the obj->log_level field introduced in commit e0e3ea888c69 ("libbpf: Allow passing user log setting through bpf_object_open_opts") set from reading verifier_logs in do_skeleton(). This preserves both object-level and explicit load-time logging settings. Fixes: b59e4ce8bcaa ("bpftool: Switch bpf_object__load_xattr() to bpf_object__load()") Acked-by: Daniel Borkmann <daniel@iogearbox.net> Signed-off-by: Mahe Tardy <mahe.tardy@gmail.com> Link: https://lore.kernel.org/r/20260907170536.9996-1-mahe.tardy@gmail.com Signed-off-by: Alexei Starovoitov <ast@kernel.org>
2026-09-11libbpf: Defer arena map size check to load timeMykyta Yatsenko
init_arena_map_data() used the build-host page size while it opened an object. This could reject skeleton generation when the build host and target use different page sizes. Validate the size during load, before libbpf calculates the arena data offset. This uses the running kernel page size and rejects an undersized map before relocation. This problem manifested when cross compiling BPF selftests for arm64 (64K page) on x86 (4K page). In this setup skeleton generation fails. Signed-off-by: Mykyta Yatsenko <yatsenko@meta.com> Signed-off-by: Andrii Nakryiko <andrii@kernel.org> Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com> Link: https://lore.kernel.org/bpf/20260908-libbpf_arena_thing-v1-1-0092c0e0d91b@meta.com
2026-09-08libbpf: Fix array comparison in BTF dedupMingpei CAO
btf_dedup_identical_types() reads both array descriptors from t1, skipping comparisons of their referenced types. This can incorrectly merge distinct structs and corrupt CO-RE relocation metadata. Read the second descriptor from t2. Fixes: 62e23f183839 ("libbpf: Improve BTF dedup handling of "identical" BTF types") Closes: https://lore.kernel.org/bpf/CABzjXVz3iBuump-pXFkefZ5v+2uu4fG61zqRyWD4xmz3PuBycw@mail.gmail.com/ Signed-off-by: Mingpei CAO <caomingpei@gmail.com> Signed-off-by: Andrii Nakryiko <andrii@kernel.org> Link: https://lore.kernel.org/bpf/20260908164920.108074-2-caomingpei@gmail.com
2026-09-06Merge git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf 7.3-rc2Alexei Starovoitov
Cross-merge BPF and other fixes after downstream PR. Conflicts: kernel/bpf/backtrack.c include/linux/bpf_verifier.h Signed-off-by: Alexei Starovoitov <ast@kernel.org>
2026-09-02libbpf: Fix debian kernel version information parsingSudip Mukherjee
Currently get_debian_kernel_version() expects the version to be in the form of x.y.z but the Debian kernels uploaded to experimental are not always LTS kernels. Like the current Debian kernel in experimental is 7.2~rc7-1~exp1 and uname -v reported "Debian 7.2~rc7-1~exp1". Signed-off-by: Sudip Mukherjee <sudipm.mukherjee@gmail.com> Signed-off-by: Andrii Nakryiko <andrii@kernel.org> Link: https://lore.kernel.org/bpf/20260831134537.1227914-1-sudipm.mukherjee@gmail.com
2026-09-02libbpf: Move section-defined program flags to prog_flagsToke Høiland-Jørgensen
The libbpf section definition modifiers for XDP frags support and sleepable programs stores the flags bits only in the private section definition cookie from object open to load time. This has the unfortunate consequence that API consumers cannot see (or manipulate) the flag between object open and program load. In particular, libxdp has special handling of frags-enabled programs to make them compatible with the dispatcher. This doesn't work on XDP programs that enable frags through the 'xdp.frags' section definition because the flag is not visible through bpf_program__flags()[0]. Fix this by changing how libbpf loads the program flags from section definitions: instead of using the private section definition cookie, add a setup function to the default section definitions that stores the flags for sleepable and XDP frags programs in the prog_flags field of struct bpf_program. Exposing the flags this way means that any use of bpf_program__set_flags() will override the flags unless the caller takes care of updating flags in a non-destructive way. This is unavoidable with the set-only API, and any user setting flags unconditionally is already broken in the sense that they will also override any other current and future flags. In addition, prog_flags survives program type changes through bpf_program__set_type(). It is the responsibility of the caller to ensure the flags are cleared if they are incompatible with the new program type. [0] https://github.com/xdp-project/xdp-tools/issues/587 Fixes: 082c4bfba4f7 ("libbpf: Add SEC name for xdp frags programs") Signed-off-by: Toke Høiland-Jørgensen <toke@redhat.com> Signed-off-by: Andrii Nakryiko <andrii@kernel.org> Link: https://lore.kernel.org/bpf/20260901-libbpf-frags-flags-v3-3-4eb6f14968b0@redhat.com
2026-08-28libbpf: Fix for the potential undefined behavior due to shiftingTw
When compiling libbpf with sanitation, ubsan will report the following: ``` left shift of 1 by 31 places cannot be represented in type 'int' ``` This may lead to undefined behavior according to the compiler implementation, let's fix it by casting to unsigned counterpart before shifting. Signed-off-by: Tan Wei <tw19881113@gmail.com> Signed-off-by: Andrii Nakryiko <andrii@kernel.org> Link: https://lore.kernel.org/bpf/20260828003448.1684064-1-tw19881113@gmail.com
2026-08-25libbpf: Fix usdt attach failure when nop10 crosses page boundaryJiayuan Chen
The kernel refuses to attach to a nop10 that crosses a page boundary, since it can't be atomically rewritten: /* can_optimize(), arch/x86/kernel/uprobes.c */ /* We can't do cross page atomic writes yet. */ return PAGE_SIZE - (vaddr & ~PAGE_MASK) >= OPT_INSN_SIZE; Whether the nop10 crosses a page is purely up to the binary layout, so this does happen in practice. libbpf doesn't check for it and blindly shifts the uprobe onto the nop10, and the attach then fails with -ENOTSUPP. Just keep the uprobe on the preceding 1-byte nop in that case, it works everywhere as a regular int3 uprobe. Fixes: ee2862439e5c ("libbpf: Change has_nop_combo to work on top of nop10") Signed-off-by: Jiayuan Chen <jiayuan.chen@linux.dev> Signed-off-by: Andrii Nakryiko <andrii@kernel.org> Link: https://lore.kernel.org/bpf/20260825150444.31603-1-jiayuan.chen@linux.dev
2026-08-22Merge tag 'perf-tools-for-v7.3-2026-08-21' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/perf/perf-tools Pull perf tools updates from Namhyung Kim: "perf c2c: - Add 'function view' in perf c2c report TUI (switched by pressing 'TAB' in the cacheline view) to organize samples around functions rather than cachelines in 3-level hierarchy: Level 1: Read-side function (sorted by estimated Cycles %) Level 2: Contending writer functions (sorted by Store count) Level 3: Shared cacheline addresses Users can navigate the entries and fold/unfold using 'e' key. An example output would look like below: Shared Data Functions Table (19 entries, sorted on Cycles %) Cycles Store % count Function / Contending function / Cacheline ---------------------------------------------------------------------- + 35.67% 876 + [k] cpupri_set + 24.31% 424 + [k] pull_rt_task - 16.53% 555 - [k] dequeue_pushable_task 145 - [k] pull_rt_task 145 0xff2d0082809da080 139 - [k] enqueue_pushable_task 70 0xff2d00a2071f9640 69 0xff2d0082809da000 python module support: - Extend "perf" python module so that it can be fully functional. The goal is to run scripts directly, not by 'perf script' command. This would give better performance as well as more control to build standalone programs with UI. - Add LiveSession helper (perf_live.py) to enable live event collection directly from Python using perf.evlist and perf.parse_events. perf stat: - Add --hide-zero-events option to suppress zero-count events - Reject conflicting --field-separator and --json-output options - Fix duplicate event output with --for-each-cgroup perf sched latency: - Add -H/--histogram and --hist-mode (log|linear) options to show scheduler wait latency histograms - Add --time option to filter analysis by time span in 'perf sched latency' ARM CoreSight: - Synthesize callchains for instruction samples from CoreSight trace using thread stack ('--itrace=g...') - Support call indentation ('perf script -F +callindent') to display call depth hierarchy on branch samples - Decode ETE (Embedded Trace Extension) exception packets Build system: - Add 'make install-build-deps' target to install required packages - Parallelize JSON and metric pre-computation in jevents.py for faster builds Vendor event/metric updates: - Add Intel Nova Lake events and update tables for existing models - Update AMD Zen 5 and Zen 6 core events - Update Arm64 Tegra410 metrics and PowerPC hcalls Internal changes and fixes: - Harden trace-event and synthetic event parsing against corrupted data - Fix unwinding of multi-threaded processes in libdw unwinder - Fix memory leaks in various commands and python bindings - Speed up 'perf test' shell tests" * tag 'perf-tools-for-v7.3-2026-08-21' of git://git.kernel.org/pub/scm/linux/kernel/git/perf/perf-tools: (232 commits) perf vendor events arm64: Fix Tegra410 Olympus event 0x0197 perf vendor events arm64: fix swapped MetricGroup for Tegra410 L1 prefetcher metrics perf evlist: Warn when 'sleep' workload is used without system-wide (-a) option perf c2c: document function view in perf-c2c man page perf c2c: add function view browser UI and cacheline detail perf c2c: build and finalize the function view hierarchy perf c2c: add function view hierarchy entry creation perf c2c: add function view stats merge and memory management perf c2c: add HPP list parsing for function view columns perf c2c: add column rendering for function view perf c2c: add function view model skeleton perf c2c: extract shared data structures into util/c2c.h perf test sample-parsing: Validate PERF_FORMAT_GROUP values without LOST perf dso: Replace assert with runtime check in dso__read_symbol() perf dso: Guard against cache underflow on short reads in dso_cache__memcpy() perf dso: Use stored fd error instead of stale errno in file_read() and file_size() perf dso: Guard close() against invalid fd in dso__decompress_kmodule_path() perf dso: Guard against errno==0 when dso__get_filename() returns NULL perf build: install-build-deps: add RHEL family devel package mapping perf build: Remove leftover feature tests for removed cxx and clang support ...
2026-08-21libbpf: Avoid overflow in BTF.ext bounds checkDarren Carreras
A malformed BTF.ext subsection length in an ELF input can wrap the pointer addition used by btf_ext_parse_sec_info() on 32-bit builds. The wrapped pointer passes the bounds check and parsing then reads beyond the copied BTF.ext data. Ensure the header fits in the copied data, then validate the subsection offset and length with subtraction before forming its pointer. Fixes: ae4ab4b4117d ("btf: expose API to work with raw btf_ext data") Closes: https://issues.oss-fuzz.com/issues/477315119 Signed-off-by: Darren Carreras <carrerasdarren@gmail.com> Signed-off-by: Andrii Nakryiko <andrii@kernel.org> Link: https://lore.kernel.org/bpf/20260813-b4-libbpf-v6-send-20260813-v6-1-56be61c52758@gmail.com
2026-08-20Merge tag 'bpf-next-7.3' of ↵Linus Torvalds
git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next Pull bpf updates from Daniel Borkmann: "Major changes: - Redesign the verifier error reporting: failures now carry source and instruction annotations along with the causal event history that led to them, making program rejections far easier to debug and repair (Kumar Kartikeya Dwivedi) - Add arena argument support to kfuncs and struct_ops through the new __arena and __arena__nullable suffixes (Tejun Heo, Puranjay Mohan, Kumar Kartikeya Dwivedi, Ihor Solodrai) - Signed BPF program loader rework to accommodate both BPF and security community needs where the kernel runs the signature verification at BPF_PROG_LOAD time before the LSM admission hook (Daniel Borkmann) - Add a set of ksock kfuncs which let BPF LSM and syscall programs create, connect and send on UDP sockets in order to emit telemetry data (Mahe Tardy) - Unify helper and kfunc call argument verification and classify kfunc arguments purely from BTF into a generated bpf_func_proto which is computed once at add-call time (Amery Hung) Other features and fixes: - Enable EXECMEM_ROX_CACHE for BPF allocations on x86 (Mike Rapoport) - Add bidirectional VLAN support to bpf_fib_lookup() through the new BPF_FIB_LOOKUP_VLAN and BPF_FIB_LOOKUP_VLAN_INPUT flags (Avinash Duduskar) - Infer zext_dst from static register liveness analysis to fix 32-bit zero-extension semantics, and remove the artificial limitations on pointer types eligible for spilling (Eduard Zingerman) - Inline the numeric open-coded iterator kfuncs so that bpf_for() loops no longer pay a kfunc call on every iteration (Puranjay Mohan) - Add an arena-based bitmap data structure to libarena along with serial and parallel selftests (Emil Tsalapatis) - Teach resolve_btfids to discover kfuncs from the kernel's BTF ID sets and to emit kfunc BTF decl tags, reducing the kernel build's dependency on pahole features (Ihor Solodrai) - Add BPF_F_ADJ_ROOM_DECAP_* flags to bpf_skb_adjust_room() so that tunnel decapsulation can update the GSO and encapsulation state of the skb (Nick Hudson) - Fix the ring buffer pending_pos walk and the available-data accounting on 32-bit position wrap (Israel Téllez García) - Add memory usage accounting for arena maps and fix an mmap_lock deadlock on arena lock failure (Jiayuan Chen) - Add tracing_multi link info support to the kernel UAPI and bpftool, and refactor the stack map code to run with preemption disabled (Jiri Olsa) - Support BPF_F_EGRESS in bpf_redirect_peer() to emit the skb in the egress direction of the target's peer device (Jordan Rife) - Add a KF_SPINLOCK_SAFE kfunc flag so that providers, in particular modules, can declare kfuncs safe to call under bpf_spin_lock instead of relying on the verifier's hard-coded allowlist (Kaitao Cheng) - Introduce global percpu data for BPF programs with libbpf probing and bpftool skeleton support, and stop exposing uninitialized kernel heap memory when copying per-CPU map values (Leon Hwang) - Add s390 JIT support for load-acquire and store-release instructions (Maxim Khmelevskii) - Fix a CFI mismatch in the task work callback and an arm64 KASAN false positive after bpf_throw() (Mykyta Yatsenko) - Reject writes through untrusted BTF pointers and bound the rdonly/rdwr_buf_size kfunc arguments (Nicholas Dudar) - Invalidate RCU pointers only after the final spin unlock and account for preempt and IRQ disabled regions as overlapping RCU protection (Ning Ding) - Support mixing bpf2bpf calls and tail calls on RV64, add signed operations and 32-bit atomics to the RV32 JIT, and add timed may_goto support (Pu Lehui, Kuan-Wei Chiu, Feng Jiang) - Fix a use-after-free on mm_struct in bpf_find_vma() for foreign tasks and an mmap_lock leak in the irq_work path (Sanghyun Park) - Populate mmap-able BPF array map memory lazily which makes mmap() O(1) instead of proportional to the map size (Song Liu) - Introduce a jit_required flag and reject programs with inlined helpers when no JIT is available, where the interpreter would otherwise jump into an invalid address (Tiezhu Yang) - Fix the x86 JIT per-CPU address resolution into an extended register where the REX prefix dropped the high destination register bit (Vineet Gupta) - Reject MEM_ALLOC BTF accesses past object bounds, arena frees below the arena base, and mixed arena and ordinary atomic paths (Yiyang Chen) - Fix the trampoline handling of 128-bit arguments and of return values larger than 8 bytes (Yonghong Song) - Ensure that any fault prone load is rewritten with exception table handling, and fix the arena load-acquire and atomic fetch handling in the x86, arm64, riscv and s390 JITs (Daniel Borkmann) - Many more fixes and cleanups across the verifier, arena, trampolines, sockmap, cgroup, ring buffer, x86/arm64/riscv/s390 JITs, libbpf, bpftool, resolve_btfids and selftests" * tag 'bpf-next-7.3' of git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next: (373 commits) selftests/bpf: Add tests for a store on a fault prone qdisc pointer selftests/bpf: Add tests for fault prone loads out of RCU pointers selftests/bpf: Add tests for pointer type merge at a shared load selftests/bpf: Remove duplicate copies of the arena spinlock qnodes selftests/bpf: Retry stat generation in cgroup_iter_memcg selftests/bpf: Test pseudo-function policy diagnostics bpf: Distinguish function references in policy diagnostics bpf: Preserve source attribution without source text selftests/bpf: Test kfunc argument diagnostics bpf: Correct kfunc argument diagnostics bpf: Use canonical stack argument names in diagnostics bpf: Preserve R0 lineage across helper calls selftests/bpf: Exercise negative optlen in cgroup getsockopt hook bpf: Reject negative optlen in cgroup getsockopt hook selftests/bpf: tc_tunnel - validate decap GSO and encapsulation state bpf: Clear decap state on skb_adjust_room shrink path bpf: Allow new DECAP flags and add guard rails bpf: Add BPF_F_ADJ_ROOM_DECAP_* flags for tunnel decapsulation bpf: Refactor masks for ADJ_ROOM flags and encap validation bpf: Name the enum for BPF_FUNC_skb_adjust_room flags ...
2026-08-14libbpf: Fix ring buffer consumer loop on 32-bit position wrapIsrael Téllez García
ringbuf_process_ring() walks the records between the consumer and the producer with an ordering comparison: while (cons_pos < prod_pos) { cons_pos and prod_pos mirror the kernel's ring positions and are unsigned long here too, so on 32-bit they wrap at 2^32 bytes of traffic. When producer_pos has wrapped and consumer_pos has not, prod_pos is the smaller of the two, the loop body never runs and no record is consumed. Since consumer_pos only advances inside that loop, it never wraps either and the consumer stops delivering samples for good, with no error returned to the caller: ring_buffer__poll() keeps reporting zero records while the kernel side fills up and starts dropping. Compare the distance instead. The consumer never runs ahead of the producer, so prod_pos - cons_pos is the amount of unconsumed data and stays correct across the wrap. 64-bit hosts are unaffected in practice: the counters would need 16 EiB to wrap. This is the userspace counterpart of the kernel-side walk fixed in "bpf: Fix pending_pos walk on 32-bit ring position wrap"; a 32-bit consumer hits whichever of the two comes first. Signed-off-by: Israel Téllez García <i.tellez@btesa.com> Signed-off-by: Andrii Nakryiko <andrii@kernel.org> Link: https://lore.kernel.org/bpf/20260814124843.22041-5-i.tellez@btesa.com
2026-08-14libbpf: Avoid unnecessary mmap resize for percpu data mapsLeon Hwang
Use array_map_mmap_sz() for PERCPU_ARRAY like ARRAY in bpf_map_mmap_sz(). This lets bpf_map__set_value_size() skip mmap(), memcpy(), and munmap() when the old and new value sizes occupy the same number of pages. Fix some typos btw: * mmapble -> mmapable * satisified -> satisfied * relocatin -> relocation * atach_btf_obj_fd -> attach_btf_obj_fd * len_secnd -> len_second * precendence -> precedence Signed-off-by: Leon Hwang <leon.hwang@linux.dev> Signed-off-by: Andrii Nakryiko <andrii@kernel.org> Link: https://lore.kernel.org/bpf/20260814173206.93082-3-leon.hwang@linux.dev
2026-08-13bpftool: Generate skeleton for global percpu dataLeon Hwang
Enhance bpftool to generate skeletons that properly handle global percpu variables. The generated skeleton now includes a dedicated structure for percpu data, allowing users to initialize and access percpu variables more efficiently. For global percpu variables, the skeleton now includes a nested structure, e.g.: struct test_global_percpu_data { struct bpf_object_skeleton *skeleton; struct bpf_object *obj; struct { struct bpf_map *percpu; } maps; // ... struct test_global_percpu_data__percpu { int data; char run; struct { char set; int i; int nums[7]; } struct_data; int nums[7]; } *percpu; // ... }; * The "struct test_global_percpu_data__percpu *percpu" points to initialized data, which is actually "maps.percpu->mmaped". * Before loading the skeleton, updating the "struct test_global_percpu_data__percpu *percpu" modifies the initial value of the corresponding global percpu variables. * After loading the skeleton, "maps.percpu->mmaped" has been marked as read-only in libbpf. If users want to update the global percpu variables, they have to update the "maps.percpu" map instead. * For lightweight skeleton, "lskel->percpu" will be protected by "mprotect(p, sz, PROT_READ)". * For subskeleton, those variables of global percpu data will be skipped. Assisted-by: Codex:gpt-5.5-xhigh Signed-off-by: Leon Hwang <leon.hwang@linux.dev> Signed-off-by: Andrii Nakryiko <andrii@kernel.org> Acked-by: Quentin Monnet <qmo@kernel.org> Link: https://lore.kernel.org/bpf/20260813152324.97937-7-leon.hwang@linux.dev
2026-08-13libbpf: Add support for global percpu dataLeon Hwang
Add support for global percpu data in libbpf by adding a new ".percpu" section, similar to ".data". It enables efficient handling of percpu global variables in bpf programs. When generating loader for lightweight skeleton, update the percpu_array map used for global percpu data using BPF_F_ALL_CPUS, in order to update values across all CPUs using one value slot. Unlike global data, the mmaped data for global percpu data will be marked as read-only after populating the percpu_array map. Thereafter, users can read those initialized percpu data after loading prog. If they want to update the percpu data after loading prog, they have to update the percpu_array map using key=0 instead. Signed-off-by: Leon Hwang <leon.hwang@linux.dev> Signed-off-by: Andrii Nakryiko <andrii@kernel.org> Link: https://lore.kernel.org/bpf/20260813152324.97937-6-leon.hwang@linux.dev
2026-08-13libbpf: Probe percpu data featureLeon Hwang
libbpf needs a reliable way to distinguish kernels that can support global percpu data from those that cannot. Add a dedicated feature probe, so libbpf can make capability decisions early and fail predictably when global percpu data is unavailable. Signed-off-by: Leon Hwang <leon.hwang@linux.dev> Signed-off-by: Andrii Nakryiko <andrii@kernel.org> Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com> Acked-by: Andrii Nakryiko <andrii@kernel.org> Link: https://lore.kernel.org/bpf/20260813152324.97937-5-leon.hwang@linux.dev
2026-07-30libbpf: Export btf__find_by_name_kind_own()Ihor Solodrai
btf__find_by_name_kind() searches the base BTF before the split BTF, so in case of a name collision between base and split it always returns a base type. Tools that process split BTF may need to restrict a lookup to the split's own types. The internal helper btf__find_by_name_kind_own() already does exactly that. Make it a public API. Signed-off-by: Ihor Solodrai <ihor.solodrai@linux.dev> Signed-off-by: Andrii Nakryiko <andrii@kernel.org> Reviewed-by: Eduard Zingerman <eddyz87@gmail.com> Link: https://lore.kernel.org/bpf/20260722233518.778854-5-ihor.solodrai@linux.dev
2026-07-25tools/build: Allow versioning LLVM readelfJames Clark
Documentation/kbuild/llvm.rst mentions that readelf is included in the LLVM toolchain, but it's not currently included in this block. Add it so that LLVM=... options also apply to readelf. Users in tools/ were Perf which was hardcoding it, and another was the BPF makefile. Both already include Makefile.include so convert them to use the new variables. Where readelf wasn't doing anything arch specific, use HOSTREADELF because it's more likely to be installed. Reviewed-by: Ian Rogers <irogers@google.com> Signed-off-by: James Clark <james.clark@linaro.org> Acked-by: Ihor Solodrai <ihor.solodrai@linux.dev> Acked-by: Kumar Kartikeya Dwivedi <memxor@gmail.com> Signed-off-by: Namhyung Kim <namhyung@kernel.org>
2026-07-21libbpf: Search /lib64 and /lib in resolve_full_path()Ricardo B. Marlière
attach_probe/uprobe-lib and uprobe_autoattach selftests fail with "failed to resolve full path for libc.so.6" on older non-usrmerged distros, where libc.so.6 lives under a top-level /lib64 or /lib rather than /usr/lib64 or /usr/lib. Add /lib64:/lib to the search paths, alongside the existing /usr/lib64:/usr/lib and Debian multiarch entries. Fixes: 1ce3a60e3c28 ("libbpf: auto-resolve programs/libraries when necessary for uprobes") Signed-off-by: Ricardo B. Marlière <rbm@suse.com> Acked-by: Ihor Solodrai <ihor.solodrai@linux.dev> Link: https://lore.kernel.org/bpf/20260720-selftests-bpf_fixes-v2-3-b450eda93dfe@suse.com Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
2026-07-10libbpf: Fix double-free of distilled base BTF on .BTF.ext parse errorNaveed Khan
When btf_parse_elf() is called without a caller-supplied base_btf (i.e. via the public btf__parse_elf()) and the object file carries a .BTF.base (distilled base) section, a dist_base_btf object is created and used as the base of the split BTF built from the .BTF section. Because base_btf is NULL, the relocation block that would otherwise free and clear dist_base_btf is skipped, and ownership of dist_base_btf is instead transferred to the split btf by setting btf->owns_base = true. That ownership transfer was performed before the fallible btf_ext__new() call that parses the .BTF.ext section. If .BTF.ext is malformed, btf_ext__new() fails and the function jumps to the error path, which frees dist_base_btf directly and then frees btf. Since owns_base is already set, btf__free(btf) also frees btf->base_btf, which is the same dist_base_btf object. The result is a use-after-free read followed by a double free of the base BTF, driven entirely by a crafted object file (a .BTF + .BTF.base + malformed .BTF.ext combination) passed to btf__parse_elf(), as used by bpftool, pahole and similar tools. Transfer ownership only after .BTF.ext has been parsed successfully, so that any earlier failure leaves dist_base_btf owned solely by the local cleanup path and it is freed exactly once. Signed-off-by: Naveed Khan <naveed@digiscrypt.com> Signed-off-by: Andrii Nakryiko <andrii@kernel.org> Link: https://lore.kernel.org/bpf/178345549172.94179.7948304165383170781@digiscrypt.com
2026-07-08libbpf: Drop in-loader metadata check for load-time verificationDaniel Borkmann
The signed gen_loader used to police its own metadata map from within BPF: emit_signature_match() read the kernel-cached map->sha[] back through hardcoded struct bpf_map offsets and compared it against a hash that compute_sha_update_offsets() baked into the signed instructions, after a BPF_OBJ_GET_INFO_BY_FD round-trip to populate map->sha[]. The kernel now verifies the metadata at BPF_PROG_LOAD time by folding the frozen contents of the loader's exclusive fd_array maps into the signature, so the loader no longer checks anything itself. Generated loaders thus carry no verification logic of their own anymore: Nothing in the signing chain depends on emitted loader bytecode doing the right thing. On the loading side, skel_internal.h now sets fd_array_cnt for a signed load so the kernel scans fd_array for the exclusive metadata map - still frozen, as the kernel requires - and the BPF_OBJ_GET_INFO_BY_FD round-trip to populate map->sha[] is gone. The struct bpf_map layout BUILD_BUG_ON()s on the kernel side are removed as well: they only pinned the ABI for the in-BPF read of map->sha[] that is no longer needed. Same for the map->excl member. Note: gen_hash is retained; it still marks a loader as signed so an untrusted host cannot re-dimension maps or override initial values now covered by the signature. Signed-off-by: Daniel Borkmann <daniel@iogearbox.net> Link: https://lore.kernel.org/bpf/20260708075343.358712-4-daniel@iogearbox.net Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
2026-07-04libbpf: Detect uprobe syscall with new errorJiri Olsa
In the previous optimized uprobe fix we changed the syscall error used for its detection from ENXIO to EPROTO. Changing related probe_uprobe_syscall detection check. Fixes: 05738da0efa1 ("libbpf: Add uprobe syscall feature detection") Fixes: 554ba38456da ("uprobes/x86: Move optimized uprobe from nop5 to nop10") Signed-off-by: Jiri Olsa <jolsa@kernel.org> Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org> Signed-off-by: Ingo Molnar <mingo@kernel.org> Acked-by: Andrii Nakryiko <andrii@kernel.org> Link: https://patch.msgid.link/20260703114917.238144-8-jolsa@kernel.org
2026-07-04libbpf: Change has_nop_combo to work on top of nop10Jiri Olsa
We now expect nop combo with 10 bytes nop instead of 5 bytes nop, fixing has_nop_combo to reflect that. Fixes: 41a5c7df4466 ("libbpf: Add support to detect nop,nop5 instructions combo for usdt probe") Fixes: 554ba38456da ("uprobes/x86: Move optimized uprobe from nop5 to nop10") Signed-off-by: Jiri Olsa <jolsa@kernel.org> Signed-off-by: Peter Zijlstra (Intel) <peterz@infradead.org> Signed-off-by: Ingo Molnar <mingo@kernel.org> Reviewed-by: Jakub Sitnicki <jakub@cloudflare.com> Acked-by: Andrii Nakryiko <andrii@kernel.org> Link: https://patch.msgid.link/20260703114917.238144-7-jolsa@kernel.org
2026-07-01libbpf: Skip bpf_object__probe_loading() when BPF token is in useYuan Chen
bpf_object__probe_loading() tries to load trivial SOCKET_FILTER and TRACEPOINT programs to verify the BPF environment works. When a BPF token is in use with restricted program type permissions, these probe loads may fail because the token does not allow the specific program types, even though BPF loading is perfectly functional. Fix by skipping the probe when a token FD is present: BPF token creation itself proves the kernel has a working BPF subsystem. Real BPF issues will be caught during actual program and map loading. Signed-off-by: Yuan Chen <chenyuan@kylinos.cn> Signed-off-by: Andrii Nakryiko <andrii@kernel.org> Link: https://lore.kernel.org/bpf/20260610145059.113412-2-chenyuan_fl@163.com
2026-06-25libbpf: fix -Wformat warnings from format/argument type mismatchesAndrii Nakryiko
Building libbpf with -Wall (as happens via bpftool's bootstrap build) surfaces ~120 -Wformat warnings where pr_warn/pr_debug format specifiers don't match their argument types: %d for __u32/Elf64_Word, %u for signed ints, %zd for size_t, %ld for unsigned long, and %x/%lx/%llx applied to signed values. Match each specifier to its argument's type where a correctly-signed specifier exists (%d<->%u, %ld->%lu, %zd->%zu). For hex conversions, which have no signed form, cast the argument instead (%x->(unsigned), %lx->(unsigned long), %llx->(unsigned long long)). No functional change. Note, the fdinfo map_flags sscanf used %i into a __u32 *, which warns. The kernel prints map_flags as hex ("map_flags:\t%#x\n" in bpf_map_show_fdinfo(), unchanged since the field was added to fdinfo), so switch the conversion to %x: it parses the 0x-prefixed value and expects unsigned int *, matching the destination, so the warning is gone with no cast. Signed-off-by: Andrii Nakryiko <andrii@kernel.org> Link: https://lore.kernel.org/r/20260624204946.2901178-1-andrii@kernel.org Signed-off-by: Alexei Starovoitov <ast@kernel.org>
2026-06-14libbpf: Initialize CFLAGS before including Makefile.includeLeo Yan
tools/scripts/Makefile.include may expand EXTRA_CFLAGS in a future change. This could alter the initialization of CFLAGS, as the default options "-g -O2" would never be set once EXTRA_CFLAGS is expanded. Prepare for this by moving the CFLAGS initialization before including tools/scripts/Makefile.include, so it is not affected by the extended EXTRA_CFLAGS. Append EXTRA_CFLAGS to CFLAGS only after including Makefile.include and place it last so that the extra flags propagate properly and can override the default options. tools/scripts/Makefile.include already appends $(CLANG_CROSS_FLAGS) to CFLAGS, the Makefile appends $(CLANG_CROSS_FLAGS) again, remove the redundant append. Signed-off-by: Leo Yan <leo.yan@arm.com> Acked-by: Ihor Solodrai <ihor.solodrai@linux.dev> Link: https://lore.kernel.org/r/20260602-tools_build_fix_zero_init_bpf_only-v2-4-c76e5250ea1c@arm.com Signed-off-by: Alexei Starovoitov <ast@kernel.org>
2026-06-14libbpf: Add path_fd to struct bpf_link_create_optsJiri Olsa
Adding the path_fd field to struct bpf_link_create_opts and passing it through kernel attr interface. Assisted-by: Codex:GPT-5.4 Signed-off-by: Jiri Olsa <jolsa@kernel.org> Link: https://lore.kernel.org/r/20260611114230.950379-5-jolsa@kernel.org Signed-off-by: Alexei Starovoitov <ast@kernel.org>
2026-06-07libbpf: Add support to create tracing multi linkJiri Olsa
Adding bpf_program__attach_tracing_multi function for attaching tracing program to multiple functions. struct bpf_link * bpf_program__attach_tracing_multi(const struct bpf_program *prog, const char *pattern, const struct bpf_tracing_multi_opts *opts); User can specify functions to attach with 'pattern' argument that allows wildcards (*?' supported) or provide BTF ids of functions in array directly via opts argument. These options are mutually exclusive. When using BTF ids, user can also provide cookie value for each provided id/function, that can be retrieved later in bpf program with bpf_get_attach_cookie helper. Each cookie value is paired with provided BTF id with the same array index. Adding support to auto attach programs with following sections: fsession.multi/<pattern> fsession.multi.s/<pattern> fentry.multi/<pattern> fexit.multi/<pattern> fentry.multi.s/<pattern> fexit.multi.s/<pattern> The provided <pattern> is used as 'pattern' argument in bpf_program__attach_kprobe_multi_opts function. The <pattern> allows to specify optional kernel module name with following syntax: <module>:<function_pattern> In order to attach tracing_multi link to a module functions: - program must be loaded with 'module' btf fd (in attr::attach_btf_obj_fd) - bpf_program__attach_tracing_multi must either have pattern with module spec or BTF ids from the module Signed-off-by: Jiri Olsa <jolsa@kernel.org> Link: https://lore.kernel.org/r/20260606123955.345967-21-jolsa@kernel.org Signed-off-by: Alexei Starovoitov <ast@kernel.org>