summaryrefslogtreecommitdiff
path: root/tools/testing/selftests/bpf
AgeCommit message (Collapse)Author
2026-09-21selftests/bpf: Guard link cleanup in fexit_bpf2bpfZhixing Chen
test_fexit_bpf2bpf_common() can jump to the common cleanup path before the link array is allocated, for example if bpf_prog_get_info_by_fd() fails. The cleanup loop still indexes link[i] unconditionally, which can dereference a NULL pointer and hide the original failure. Guard the loop so the test reports the original failure instead. Signed-off-by: Zhixing Chen <running910@gmail.com> Signed-off-by: Andrii Nakryiko <andrii@kernel.org> Link: https://lore.kernel.org/bpf/20260917093928.48495-1-running910@gmail.com
2026-09-21selftests/bpf: Cover helper memory access permissionsEduard Zingerman
Check that fixed-size and sized helper input/output buffers require both read and write permission. Cover the MTU and FIB helpers, including read-only and write-only rejection and read/write positive controls. Exercise the XDP prototypes and the sock_ops header-option input/output argument as well. Keep write-only maps usable as destinations for partial-output helpers bpf_snprintf() and bpf_sysctl_get_name(), while rejecting a read-only snprintf destination. Also retain a write-only-map destination for bpf_get_current_comm(), whose output is annotated MEM_UNINIT and fully initialized by the helper. Signed-off-by: Eduard Zingerman <eddyz87@gmail.com> Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com> Signed-off-by: Alexei Starovoitov <ast@kernel.org> Link: https://patch.msgid.link/20260921023843.411943-12-memxor@gmail.com
2026-09-21selftests/bpf: Cover generic output stack initializationKumar Kartikeya Dwivedi
Exercise generic output buffers with and without CAP_PERFMON, using both helpers and __uninit kfuncs. Check that initialized bytes stay readable and lose stale value information, while invalid bytes remain unreadable without permission to read uninitialized stack memory. Cover constant and variable sizes, scalar spills, pointer spills, special stack objects, and privileged variable offsets. Add a kfunc that writes only the first byte of its output. Its runtime tests read preinitialized bytes, checking both the written byte and an untouched tail byte across a liveness checkpoint. Verify that the sysctl name helper and uninitialized fixed and variable-sized kfunc outputs are accepted when their contents are not read back. Update existing __uninit readback expectations and exercise skb_load_bytes with reduced capabilities. Even fully-writing generic outputs now preserve invalid bytes in the verifier, so reading those bytes requires prior initialization by the BPF program. Use map_update_elem inputs for helper_arg_fallback_keeps_scanning. Its original snprintf argument no longer reads the buffer, and a privileged output with an unknown size does not trigger the whole-stack read fallback. A variable-offset key and parent-frame value retain the intended assertion. Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com> Signed-off-by: Alexei Starovoitov <ast@kernel.org> Link: https://patch.msgid.link/20260921023843.411943-10-memxor@gmail.com
2026-09-21selftests/bpf: Cover __uninit kfunc output argument slotsKumar Kartikeya Dwivedi
Keep coverage for per-slot output tracking separate from the immediate single-output regression tests. Check that both constant-size outputs are initialized, and that a variable-size output does not disable initialization of an independent constant-size output. Also exercise an output following a by-value parameter that occupies two argument slots, and an output pointer passed on the stack. Run each case with normal capabilities and with CAP_BPF and CAP_NET_ADMIN only. Leave the stack-passed output uninitialized so its reduced-capability case fails if the verifier treats it as an ordinary input buffer. Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com> Signed-off-by: Alexei Starovoitov <ast@kernel.org> Link: https://patch.msgid.link/20260921023843.411943-8-memxor@gmail.com
2026-09-21selftests/bpf: Cover generic __uninit output initializationKumar Kartikeya Dwivedi
Exercise the struct and sized-buffer cases where stack liveness poisons an output before a kfunc call. Check that the verifier accepts these outputs and that the kfunc initializes the memory read after the call. Verify that an uninitialized input aliasing an output is still rejected without CAP_PERFMON or CAP_SYS_ADMIN. Include an initialized alias as a positive control, using an int-width store so its value is independent of endianness. Use __prepare_priv to resolve the test module's BTF before dropping to CAP_BPF and CAP_NET_ADMIN for program loading. Keep multiple-output and argument-slot coverage separate from these immediate regression tests. Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com> Signed-off-by: Alexei Starovoitov <ast@kernel.org> Reviewed-by: Amery Hung <ameryhung@gmail.com> Link: https://patch.msgid.link/20260921023843.411943-6-memxor@gmail.com
2026-09-21selftests/bpf: Allow privileged preparation for capability testsKumar Kartikeya Dwivedi
The annotation-driven loader drops capabilities before libbpf prepares an object. Resolving bpf_testmod kfuncs requires CAP_SYS_ADMIN to enumerate and open module BTF, so tests without that capability fail before reaching the verifier. Add an opt-in __prepare_priv annotation. Call bpf_object__prepare() with the fixture's initial capabilities, then apply __caps_unpriv before loading the programs. This uses libbpf's explicit prepare/load boundary. In particular, CAP_SYS_ADMIN must be dropped along with CAP_PERFMON to test uninitialized stack checks, since CAP_SYS_ADMIN satisfies the verifier's CAP_PERFMON check. Preparation also creates maps and loads BTF. Keep it opt-in so existing tests continue checking those operations with reduced capabilities. The existing pre-execution callback runs after program loading and is too late for this. Allow tests retaining CAP_BPF to run when the unprivileged-BPF sysctl is set. Check CPU mitigations separately: disabled or undetectable mitigations must still skip these tests, because CAP_BPF does not restore speculative execution checks. Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com> Signed-off-by: Alexei Starovoitov <ast@kernel.org> Link: https://patch.msgid.link/20260921023843.411943-2-memxor@gmail.com
2026-09-21selftests/bpf: Add tests for selective module BTF loadingFuyu Zhao
Add selftests covering selective kernel module BTF loading through bpf_object_open_opts. The tests verify that: - the existing behavior is preserved when the allowlist is not specified; - loading succeeds when the required module BTF is specified in the allowlist; - module BTFs not in the allowlist are skipped; - an empty allowlist skips loading all module BTFs; - invalid allowlist and module name inputs are rejected. Signed-off-by: Fuyu Zhao <zhaofuyu@vivo.com> Signed-off-by: Andrii Nakryiko <andrii@kernel.org> Link: https://lore.kernel.org/bpf/20260915124104.77287-3-zhaofuyu@vivo.com
2026-09-21selftests/bpf: Build each test runner instance in its own sub-makeMykola Lysenko
Replace DEFINE_TEST_RUNNER/DEFINE_TEST_RUNNER_RULES with Makefile.runner, invoked once per test runner instance. Each invocation uses ordinary make rules in a single-flavor namespace. The main Makefile owns shared build outputs and the kselftest run/install rules. Makefile.skel supplies the BPF object and skeleton rules used by both the main Makefile and the runners. The main Makefile builds the default flavor before invoking unflavored runners; flavored runners build in separate directories. Build shared userspace objects once and link them into every flavor. Order their compilation after the bpftool sub-build, which installs the libbpf-internal headers they include. Pass the assembled CFLAGS and LDFLAGS to runners on their command lines. Build and copy runtime fixtures alongside runner compilation so module builds do not delay runner startup. They are prerequisites of the test_progs, test_progs-<flavor> and all goals rather than of the runner binaries, so a goal spelled as a binary's path builds the binary alone. Installation copies the default flavor's BPF objects, preserving the previous result. Generate prog_tests/tests.h and map_tests/tests.h through ordinary recipes, avoiding generation during make -n. Signed skeletons explicitly depend on the private key. The flavored runners' objects and the test objects are targets of the sub-makes only, and the bare linked-object names (make linked_funcs1.bpf.o) are no longer targets. Build-log details change: skeleton messages adopt the common format and output stream, the shared objects log as CC, the fixture copy prints no EXT-COPY line and TEST-HDR carries no runner tag. Co-developed-by: Eduard Zingerman <eddyz87@gmail.com> Signed-off-by: Eduard Zingerman <eddyz87@gmail.com> Signed-off-by: Mykola Lysenko <nickolay.lysenko@gmail.com> Link: https://lore.kernel.org/bpf/20260921075855.2065871-10-nickolay.lysenko@gmail.com Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
2026-09-21selftests/bpf: Move shared build definitions into Makefile.buildvarsMykola Lysenko
Move shared build definitions into Makefile.buildvars, preserving their order, in preparation for separate runner sub-makes. Include it after ../lib.mk and before Makefile.feature, so the LLVM feature probe still sees srctree. Keep the CFLAGS and LDFLAGS additions before lib.mk to preserve flag ordering; their references to definitions below the include expand when used. Name the clang warning suppression CLANG_WARN_CFLAGS so it can be referenced there. The arena-ASAN probe moves below lib.mk, so it queries the CLANG the BPF objects are built with. The CPU-v4 probe, BPF_GCC and TEST_KMODS remain before lib.mk because they determine the target lists. Definitions no runner reads move too when they are declared beside ones a runner does. BPFTOOLDIR, HOST_BPFOBJ and BPF_TARGET_ENDIAN stay in the Makefile, which alone reads them, and follow the include because their := assignments read values it defines. Suggested-by: Eduard Zingerman <eddyz87@gmail.com> Signed-off-by: Mykola Lysenko <nickolay.lysenko@gmail.com> Link: https://lore.kernel.org/bpf/20260921075855.2065871-9-nickolay.lysenko@gmail.com Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
2026-09-21selftests/bpf: Extract BPF skeleton generation into a helper scriptMykola Lysenko
Four skeleton recipes duplicate the link, determinism-check and header-generation pipeline inside DEFINE_TEST_RUNNER_RULES. Extract it into gen_bpf_skel.sh, with options for light and signed skeletons. Intermediate names now derive from the output header, retaining separate linked/llinked infixes for regular and light skeletons. Keep the permissive-mode missing-input guards in a skip_if_missing helper, so a skipped skeleton still prints only SKIP-SKEL. On failure, the script removes intermediates and both output headers; previously, strict-mode recipes left intermediates behind and .DELETE_ON_ERROR covered only the target, not its subskeleton. The determinism check names the skeleton when it fails, and linked skeletons log GEN-SKEL before linking. Suggested-by: Eduard Zingerman <eddyz87@gmail.com> Signed-off-by: Mykola Lysenko <nickolay.lysenko@gmail.com> Acked-by: Eduard Zingerman <eddyz87@gmail.com> Link: https://lore.kernel.org/bpf/20260921075855.2065871-8-nickolay.lysenko@gmail.com Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
2026-09-21selftests/bpf: Derive the bench object list from the sourcesMykola Lysenko
bench links every benchs/bench_*.c object. Derive the object list with a wildcard so adding a benchmark no longer requires updating the link rule. Skeleton prerequisites remain explicit. The sorted list changes object link order and the binary's symbol layout; no benchmark behaves differently. Signed-off-by: Mykola Lysenko <nickolay.lysenko@gmail.com> Acked-by: Eduard Zingerman <eddyz87@gmail.com> Link: https://lore.kernel.org/bpf/20260921075855.2065871-7-nickolay.lysenko@gmail.com Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
2026-09-21selftests/bpf: Generate verifier/tests.h in a regular recipeMykola Lysenko
The verifier/tests.h recipe is a $(shell ...) expansion: the command runs while make expands the recipe line - including under make -n - its exit status is discarded, and the resulting (empty) expansion is what make actually executes. Signed-off-by: Mykola Lysenko <nickolay.lysenko@gmail.com> Acked-by: Eduard Zingerman <eddyz87@gmail.com> Link: https://lore.kernel.org/bpf/20260921075855.2065871-6-nickolay.lysenko@gmail.com Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
2026-09-21selftests/bpf: Generate the signing key and certificate onceMykola Lysenko
genkey produces the private key and certificate together, but an ordinary multi-target rule can run it twice concurrently when both outputs are required. Only the certificate is currently a prerequisite; the runner split will require both. Use an implicitly grouped pattern rule, as test_kmods already does, to support make versions before 4.3. Signed-off-by: Mykola Lysenko <nickolay.lysenko@gmail.com> Acked-by: Eduard Zingerman <eddyz87@gmail.com> Link: https://lore.kernel.org/bpf/20260921075855.2065871-5-nickolay.lysenko@gmail.com Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
2026-09-21selftests/bpf: Factor the permissive-mode skip suffix into a helperMykola Lysenko
With BPF_STRICT_BUILD=0, eleven recipes append the same "|| { remove the target, print a SKIP marker, report success }" tail, each spelled out inline. Factor the tail into skip_on_fail; every call site keeps its exact message and behavior. Signed-off-by: Mykola Lysenko <nickolay.lysenko@gmail.com> Acked-by: Eduard Zingerman <eddyz87@gmail.com> Link: https://lore.kernel.org/bpf/20260921075855.2065871-4-nickolay.lysenko@gmail.com Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
2026-09-21selftests/bpf: Drop stale lines, restore two header dependenciesMykola Lysenko
Four target-specific lines name objects nothing builds. Commit afef88e65554 ("selftests/bpf: Store BPF object files with .bpf.o extension") left three naming the old BPF objects; flow_dissector_load.o names an intermediate the one-step compile and link rule does not produce. The xsk_xdp_progs, xdp_hw_metadata and xdp_features dependency-map entries are unused: none is listed in LINKED_SKELS, and the regular skeleton rule does not consult the map. The test_l4lb_noinline and test_xdp_noinline '-fno-inline' settings had already stopped taking effect with commit 74b5a5968fe8 ("selftests/bpf: Replace test_progs and test_maps w/ general rule"). The compile recipe uses TRUNNER_BPF_CFLAGS, a simply-expanded copy of BPF_CFLAGS that the target-specific additions cannot affect. The intended functions already carry noinline annotations; restoring the flag produces byte-identical objects. Restore flow_dissector_load.h as a prerequisite of the binary, which is compiled and linked directly from its .c file. Move cgroup_getset_retval_hooks.h under progs/, where the BPF rules' blanket header prerequisite tracks it. Its userspace consumer remains tracked by compiler-generated dependencies. Drop the redundant CURDIR assignment and the unused OBJCOPY definition. Signed-off-by: Mykola Lysenko <nickolay.lysenko@gmail.com> Acked-by: Eduard Zingerman <eddyz87@gmail.com> Link: https://lore.kernel.org/bpf/20260921075855.2065871-3-nickolay.lysenko@gmail.com Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
2026-09-21selftests/bpf: Keep headers off the generic link command lineMykola Lysenko
The generic '$(OUTPUT)/%:%.c' rule links with '$(LINK.c) $^', so every prerequisite reaches the compiler driver. A header argument makes clang fail with "cannot specify -o when generating multiple output files". Filter headers out of the link command while retaining them as prerequisites. Signed-off-by: Mykola Lysenko <nickolay.lysenko@gmail.com> Acked-by: Eduard Zingerman <eddyz87@gmail.com> Link: https://lore.kernel.org/bpf/20260921075855.2065871-2-nickolay.lysenko@gmail.com Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
2026-09-19selftests/bpf: Add tests for BPF LSM inode init labellingDaniel Borkmann
Exercise bpf_inode_init_xattr() in combination with a policy example via BPF LSM. A program on the inode_init_security hook labels new files and directories, inherits a zone label from the parent directory, and has claims refused for names outside the security.bpf. prefix and for a name that would exceed XATTR_NAME_MAX once the prefix is put back as well as other corner case tests that should get rejected. # LDLIBS=-static PKG_CONFIG='pkg-config --static' ./vmtest.sh -- ./test_progs -t lsm_inode_init_xattr [...] #226/1 lsm_inode_init_xattr/init_labels:OK #226/2 lsm_inode_init_xattr/inherit_from_parent:OK #226/3 lsm_inode_init_xattr/refused_claims:OK #226/4 lsm_inode_init_xattr/null_xattrs:OK #226/5 lsm_inode_init_xattr/shared_budget:OK #226/6 lsm_inode_init_xattr/value_shapes:OK #226 lsm_inode_init_xattr:OK Summary: 1/6 PASSED, 0 SKIPPED, 0/0 FAILED Co-developed-by: David Windsor <dwindsor@gmail.com> Signed-off-by: David Windsor <dwindsor@gmail.com> Signed-off-by: Daniel Borkmann <daniel@iogearbox.net> Signed-off-by: Alexei Starovoitov <ast@kernel.org> Link: https://patch.msgid.link/20260915150739.284189-9-daniel@iogearbox.net
2026-09-19selftests/bpf: Add verifier tests for the __ctx_out plumbingDaniel Borkmann
Add BPF selftests to cover what a BPF program may and may not hand to bpf_inode_init_xattr() as the inode_init_security hook's args. # LDLIBS=-static PKG_CONFIG='pkg-config --static' ./vmtest.sh -- ./test_progs -t verifier_lsm_init_xattr [...] #649/1 verifier_lsm_init_xattr/reject_count_write:OK #649/2 verifier_lsm_init_xattr/allow_count_read:OK #649/3 verifier_lsm_init_xattr/reject_unchecked_xattrs:OK #649/4 verifier_lsm_init_xattr/reject_unchecked_qstr:OK #649/5 verifier_lsm_init_xattr/allow_spilled_count:OK #649/6 verifier_lsm_init_xattr/reject_forged_count:OK #649/7 verifier_lsm_init_xattr/reject_stack_count:OK #649/8 verifier_lsm_init_xattr/reject_other_ctx_arg:OK #649/9 verifier_lsm_init_xattr/reject_null_count:OK #649/10 verifier_lsm_init_xattr/reject_shifted_count:OK #649/11 verifier_lsm_init_xattr/reject_var_shifted_count:OK #649/12 verifier_lsm_init_xattr/reject_ctx_forged_count:OK #649/13 verifier_lsm_init_xattr/allow_count_via_subprog:OK #649/14 verifier_lsm_init_xattr/reject_shifted_xattrs:OK #649/15 verifier_lsm_init_xattr/reject_sleepable:OK #649/16 verifier_lsm_init_xattr/reject_lsm_cgroup:OK #649/17 verifier_lsm_init_xattr/reject_wrong_hook:OK #649 verifier_lsm_init_xattr:OK Summary: 1/17 PASSED, 0 SKIPPED, 0/0 FAILED Co-developed-by: David Windsor <dwindsor@gmail.com> Signed-off-by: David Windsor <dwindsor@gmail.com> Signed-off-by: Daniel Borkmann <daniel@iogearbox.net> Signed-off-by: Alexei Starovoitov <ast@kernel.org> Link: https://patch.msgid.link/20260915150739.284189-8-daniel@iogearbox.net
2026-09-19selftests/bpf: Test that the BPF LSM context is read-onlyDaniel Borkmann
Add a new BPF selftest asserting that a store into the context of an LSM program must be rejected. # LDLIBS=-static PKG_CONFIG='pkg-config --static' ./vmtest.sh -- ./test_progs -a verifier_lsm [...] #648/1 verifier_lsm/lsm bpf prog with -4095~0 retval. test 1:OK #648/2 verifier_lsm/lsm bpf prog with -4095~0 retval. test 2:OK #648/3 verifier_lsm/lsm bpf prog with -4095~0 retval. test 4:OK #648/4 verifier_lsm/lsm bpf prog with -4095~0 retval. test 5:OK #648/5 verifier_lsm/lsm bpf prog with -4095~0 retval. test 6:OK #648/6 verifier_lsm/lsm retval load must reset stale register bounds:OK #648/7 verifier_lsm/lsm ctx is read-only:OK #648/8 verifier_lsm/lsm bpf prog with bool retval. test 1:OK #648/9 verifier_lsm/lsm bpf prog with bool retval. test 2:OK #648/10 verifier_lsm/lsm bpf prog with bool retval. test 3:OK #648/11 verifier_lsm/lsm bpf prog with bool retval. test 4:OK #648/12 verifier_lsm/lsm bpf prog with void retval. test 1:OK #648/13 verifier_lsm/lsm bpf prog with void retval. test 2:OK #648/14 verifier_lsm/lsm disabled hook: getprocattr:OK #648/15 verifier_lsm/lsm disabled hook: setprocattr:OK #648/16 verifier_lsm/lsm disabled hook: ismaclabel:OK #648/17 verifier_lsm/not null checking nullable pointer in bpf_lsm_mmap_file:OK #648/18 verifier_lsm/null checking nullable pointer in bpf_lsm_mmap_file:OK #648/19 verifier_lsm/sleepable lsm_cgroup program is rejected:OK #648 verifier_lsm:OK Summary: 1/19 PASSED, 0 SKIPPED, 0/0 FAILED Signed-off-by: Daniel Borkmann <daniel@iogearbox.net> Signed-off-by: Alexei Starovoitov <ast@kernel.org> Link: https://patch.msgid.link/20260915150739.284189-7-daniel@iogearbox.net
2026-09-19selftests/bpf: Add test for bpf_tcp_ops header option hooksAmery Hung
Add a test exercising the bpf_tcp_ops parse_hdr, hdr_opt_len and write_hdr_opt members together with the header option helpers. The struct_ops program (progs/bpf_tcp_ops_hdr.c) reserves space in hdr_opt_len via bpf_reserve_hdr_opt(), writes an experimental option in write_hdr_opt via bpf_store_hdr_opt(), and recovers it in parse_hdr via bpf_load_hdr_opt() on the incoming skb. Each hook bumps a counter and the parse hook records the option payload, so the three callbacks and all three overloaded helpers are covered. Signed-off-by: Amery Hung <ameryhung@gmail.com> Signed-off-by: Alexei Starovoitov <ast@kernel.org> Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com> Link: https://patch.msgid.link/20260917200542.3689605-16-ameryhung@gmail.com
2026-09-19selftests/bpf: Test attaching struct_ops to a cgroupMartin KaFai Lau
Exercise attaching the bpf_tcp_ops struct_ops to cgroups via the generic cgroup link infrastructure. The struct_ops instances record their execution order and the previous return value to validate correctness. Subtests: - query: BPF_F_QUERY_EFFECTIVE and attached query return the maps - order: BPF_F_PREORDER vs attach order within a cgroup - before_after: BPF_F_BEFORE/BPF_F_AFTER relative positioning - update: bpf_link__update_map swaps a link's map, keeping its slot - retval: int return value chained across timeout_init progs of multiple bpf_tcp_ops attached to a cgroup - hierarchy: parent and child attachments merge in the child's effective array (descendant before ancestor) - inherit: a child created after the attach inherits the parent's prog Signed-off-by: Martin KaFai Lau <martin.lau@kernel.org> Signed-off-by: Amery Hung <ameryhung@gmail.com> Signed-off-by: Alexei Starovoitov <ast@kernel.org> Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com> Link: https://patch.msgid.link/20260917200542.3689605-15-ameryhung@gmail.com
2026-09-19selftests/bpf: Check local object ownership depthKumar Kartikeya Dwivedi
Build raw program BTF records to exercise local object ownership without constructing a runtime chain deep enough to threaten the kernel stack. Cover referenced-kptr and percpu-kptr self-cycles, a two-type cycle, and a cycle mixing a graph root with a referenced kptr. The existing graph-only check accepts these local-kptr cycles and over-limit kptr chains; the fix rejects them with -ELOOP. Pin the eight-record depth boundary with a terminal plain object. Exercise both parent-first and child-first BTF orders, and a shared suffix reached first through a shorter path. These cases require cached suffix depths to be checked against the remaining depth budget on each path. Check list and rbtree chains of three, four, eight, and nine types. This covers the old graph-only depth boundary and the new explicit bound. The existing linked-list BTF tests still reject pure graph cycles and now accept the longer acyclic layouts previously rejected by the conservative rule. Although bpf_percpu_obj_new() currently rejects types with special fields, require the percpu cycle to fail at BTF load so future support cannot bypass the ownership bound. Keep a positive control for a non-owning kptr, which remains outside the ownership graph. Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com> Signed-off-by: Alexei Starovoitov <ast@kernel.org> Link: https://patch.msgid.link/20260914132444.2564218-3-memxor@gmail.com
2026-09-19bpf: Bound ownership depth through local kptrs and graph rootsKumar Kartikeya Dwivedi
Program-allocated objects can own other local objects through referenced kptrs. bpf_obj_free_fields() follows those pointers through __bpf_obj_drop_impl() synchronously, before the object storage is freed through RCU. A self-referential local kptr type therefore permits arbitrarily deep object chains, and dropping the head can exhaust the kernel stack. Long acyclic type chains have the same problem. btf_check_and_fixup_fields() still assumes referenced kptrs only point to kernel types and checks ownership through list and rbtree roots only. Its existing rule is sufficient for graph-only cycles: the target of each graph edge must contain a node, so every type in a cycle has both a root and a node. The rule rejects such a type owning another root, breaking every cycle. It also limits graph-only chains to three types, or two if the first type contains a node, and conservatively rejects longer acyclic chains. The missing local-kptr edges, rather than a missed graph-only cycle, are the bug introduced by support for bpf_kptr_xchg() into local kptrs. Replace that restriction with one bounded ownership walk covering graph roots and local referenced kptrs. Run it after all BTF records have been fixed up, reject cycles and paths deeper than eight record-bearing types, and cache each type's suffix depth while checking it against the remaining budget. This also permits the longer acyclic graph-only layouts rejected by the old rule; update their existing BTF tests accordingly. Keep the bound independent of MAX_CALL_FRAMES because recursive destruction can run below a BPF call chain. A plain local pointee without special-field metadata adds only a final non-recursing drop. Non-owning kptrs and kernel-BTF kptrs do not recurse through local records and remain outside the walk. Include local percpu-kptr edges too, although allocation of percpu objects with special fields is currently forbidden, so that relaxing that restriction cannot bypass the ownership bound. btf_check_and_fixup_fields() continues to initialize graph_root.value_rec, including for separately allocated map records. The ownership relationships belong to immutable program BTF and only need validation at BTF load time. Fixes: b0966c724584 ("bpf: Support bpf_kptr_xchg into local kptr") Reported-by: Nicholas Carlini <npc@anthropic.com> Suggested-by: Nicholas Carlini <npc@anthropic.com> Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com> Signed-off-by: Alexei Starovoitov <ast@kernel.org> Link: https://patch.msgid.link/20260914132444.2564218-2-memxor@gmail.com
2026-09-19selftests/bpf: Cover frame changes in bounded loopsKumar Kartikeya Dwivedi
Add a finite loop whose progress is represented only by changing the frame number of a stack pointer. The loop first reads zero from the caller's stack, switches to the same offset in the callee's stack, and exits after reading one on its next iteration. Force frequent checkpoints so the test exercises infinite-loop detection, and check that the program returns one when run. Without the frameno comparison in regs_exact(), the program is rejected with an "infinite loop detected" diagnostic instead of loading successfully. Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com> Signed-off-by: Alexei Starovoitov <ast@kernel.org> Tested-by: Eduard Zingerman <eddyz87@gmail.com> Link: https://patch.msgid.link/20260919014213.1840880-3-memxor@gmail.com
2026-09-18selftests/bpf: Test mm_struct user memory kfuncs with linux_binprmAnastasios Papagiannis
Add a sleepable BPF LSM program attached to bprm_check_security to test bpf_copy_from_user_mm() and bpf_copy_from_user_mm_str(). Starting at bprm->p, verify that bpf_copy_from_user_mm() can copy the contiguous NUL-separated argument and environment data. Then use bpf_copy_from_user_mm_str() to read each argument and environment string separately, advancing the offset by the length returned from each call. Signed-off-by: Anastasios Papagiannis <tasos.papagiannnis@gmail.com> Signed-off-by: Alexei Starovoitov <ast@kernel.org> Link: https://patch.msgid.link/20260918131757.42802-6-tasos.papagiannnis@gmail.com
2026-09-18bpf: Mark linux_binprm->mm as trusted-or-nullAnastasios Papagiannis
Mark linux_binprm->mm as a trusted-or-null nested pointer so BPF programs can pass it to kfuncs after a NULL check. The field is either NULL or points to a live mm_struct whenever BPF can access a linux_binprm. On successful exec, exec_mmap() installs the new address space before begin_new_exec() clears bprm->mm. The bprm_mm_init() error path clears the field before mmdrop(), and free_bprm() clears it before mmput(), as ensured by an earlier patch in this series. Update the existing LSM selftest to check bprm->mm for NULL before dereferencing it, as required for trusted-or-null pointers. Signed-off-by: Anastasios Papagiannis <tasos.papagiannnis@gmail.com> Signed-off-by: Alexei Starovoitov <ast@kernel.org> Reviewed-by: Sun Jian <sun.jian.kdev@gmail.com> Reviewed-by: Matt Bobrowski <matt@bobrowski.net> Link: https://patch.msgid.link/20260918131757.42802-5-tasos.papagiannnis@gmail.com
2026-09-17selftests/bpf: Check callback map value lock identityKumar Kartikeya Dwivedi
Add a verifier test which retains a map value from an outer callback and then acquires a lock through an inner callback value before attempting to release the outer callback value. Both values can denote different elements, so the verifier must reject the mismatched unlock. Also exercise callbacks reached through two inner-map lookups. The lookup results share inner_map_meta but may refer to different one-element arrays, so their callback values must retain distinct lock identities. Extend the existing spin_lock failure table and reuse its array and inner-map fixtures to keep these cases alongside the other lock identity tests. Update the nested callback reference-leak expectation for the extra callback value ID. Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com> Link: https://patch.msgid.link/20260917233222.2542500-10-memxor@gmail.com Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
2026-09-17selftests/bpf: Test CO-RE instruction poisoning restrictionsKumar Kartikeya Dwivedi
Add raw CO-RE relocations that fail to resolve their target enum value. Place each supported and unsupported instruction form in dead code. Unsupported targets must fail relocation with a diagnostic even when they are unreachable. Supported ALU immediates, memory accesses, and ldimm64 instructions must still be poisoned and removed as dead code, allowing the program to load. Check that both halves of ldimm64 are poisoned. Load every instruction stream without relocations first to ensure that rejection is caused by the relocation rather than the original program. Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com> Acked-by: Eduard Zingerman <eddyz87@gmail.com> Link: https://patch.msgid.link/20260917233222.2542500-8-memxor@gmail.com Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
2026-09-17selftests/bpf: Test early in-kernel CO-RE relocationKumar Kartikeya Dwivedi
Add a raw program load with CO-RE relocation metadata but no func_info or line_info. Place the relocation in dead code and require the poisoning log, proving that the kernel processes standalone CO-RE metadata instead of silently skipping it. Also give a subprogram a relocatable immediate as its terminal instruction. Require the relocation's poisoning log before check_subprogs() rejects the resulting fall-through. With the old ordering, check_subprogs() rejects the original terminal instruction before CO-RE can emit the substitution log, so the test continues to distinguish the ordering after relocation target validation is tightened. Submit a trailing ldimm64 first slot with CO-RE metadata and require the early structural diagnostic. This exercises the check that protects relocation processing instead of the later regular instruction validation. Load the standalone instruction stream without relocation metadata first to ensure that CO-RE processing causes its poisoning diagnostic. Encode the fixed BTF metadata directly with the selftest BTF helpers. Suggested-by: Eduard Zingerman <eddyz87@gmail.com> Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com> Acked-by: Eduard Zingerman <eddyz87@gmail.com> Link: https://patch.msgid.link/20260917233222.2542500-6-memxor@gmail.com Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
2026-09-17selftests/bpf: Test packet pointer class displacement pruningKumar Kartikeya Dwivedi
Add two paths whose packet pointer ranges are individually compatible at a join but whose members have different relative displacements. The first path proves an eight-byte access through one member. On the second path, the same guard only proves that the access starts before data_end. An affected verifier prunes the second path and accepts the program. With packet pointer class displacement preserved, it explores that path and rejects the out-of-bounds access. Read the unknown offset and branch selector directly from XDP context fields, and force state checkpoints so the pruning attempt does not depend on the verifier checkpoint heuristics. Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com> Link: https://patch.msgid.link/20260917233222.2542500-4-memxor@gmail.com Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
2026-09-17selftests/bpf: Test global subprog callback contextsKumar Kartikeya Dwivedi
Exercise global subprogram verification from workqueue callbacks, which can run in a sleepable context even when the containing program is not sleepable. An unprotected callback must not let the global subprogram use implicit RCU protection inherited from the program. Add a negative case which loads an RCU-protected task kptr in a global subprogram reached from a workqueue callback. It fails on an unfixed kernel because the program is incorrectly accepted. Also cover a workqueue callback protected by an explicit RCU read-side critical section, where the same global subprogram remains valid. Call the same harmless global subprogram directly from the main program and from an unprotected callback. Mark it __weak __noinline so both calls survive optimization, and check that its instruction statistics account for both verification contexts. This also verifies that global calls from callbacks are not rejected wholesale. Workqueue callbacks return zero explicitly after the global call, as required by their contract. Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com> Acked-by: Eduard Zingerman <eddyz87@gmail.com> Link: https://patch.msgid.link/20260914131923.2544250-3-memxor@gmail.com Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
2026-09-17selftests/bpf: Wait for links to come up in lwt_ip_encapAlexei Starovoitov
lwt_ip_encap creates three fresh netns with veth pairs across them and then immediately pings over IPv6. The peer ends of the first veth pair end up with the same ifindex in their respective netns, so linkwatch does not treat the carrier-on as urgent and may deliver NETDEV_CHANGE up to one second later. Until that happens addrconf considers the link not ready: no ff00::/8 multicast route and no link-local address are installed, and the neighbour solicitation for the next hop is dropped as a no-route packet. The NS retransmit a second later succeeds, but ping -W1 has already given up: check_ping_ok:FAIL:ip netns exec ns-lwt-ip-encap-1-... ping -6 -c 1 -W1 -I veth1 fb04::1 > /dev/null unexpected error: 256 (errno 2) lwt_ip_encap:FAIL:ping OK unexpected error: -1 (errno 2) #226/1 lwt_ip_encap_ipv4/egress:FAIL This reproduces reliably when the test is run standalone on an idle system where setup completes well within a second. The original shell script had a "sleep 1 # reduce flakiness" after setup which was lost in the conversion to test_progs. Instead of sleeping, poll SIOCGIFFLAGS for IFF_RUNNING on all veths at the end of setup_network() so traffic is only sent once every link is operationally up. Fixes: f5e288943e2c ("selftests/bpf: Move test_lwt_ip_encap to test_progs") Signed-off-by: Alexei Starovoitov <ast@kernel.org> Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com> Link: https://patch.msgid.link/20260916232407.764886-1-alexei.starovoitov@gmail.com
2026-09-14selftests/bpf: Adopt bpf_program__add_flags() helperToke Høiland-Jørgensen
Adopt the newly added bpf_program__add_flags() helper everywhere the selftests adds program flags (replacing all uses of bpf_program__set_flags() in the tests). Signed-off-by: Toke Høiland-Jørgensen <toke@redhat.com> Signed-off-by: Andrii Nakryiko <andrii@kernel.org> Reviewed-by: Jiayuan Chen <jiayuan.chen@linux.dev> Acked-by: Ihor Solodrai <ihor.solodrai@linux.dev> Link: https://lore.kernel.org/bpf/20260912084109.432834-3-toke@redhat.com
2026-09-14selftests/bpf: Add assertions for bpf_program__{add,clear}_flags()Toke Høiland-Jørgensen
Add assertions that round-tripping through bpf_program__add_flags() and bpf_program__clear_flags() ends up with the original flags value. Arbitrarily add these to the kernel_flag test prog since that's where we're already checking for the bpf_program__flags() value (and the test name contains "flag"). Signed-off-by: Toke Høiland-Jørgensen <toke@redhat.com> Signed-off-by: Andrii Nakryiko <andrii@kernel.org> Acked-by: Ihor Solodrai <ihor.solodrai@linux.dev> Link: https://lore.kernel.org/bpf/20260912084109.432834-2-toke@redhat.com
2026-09-13selftests/bpf: cover the exception callback using its own BPF stackDonggeun Yoo
The existing exception tests do not reach a callback that materializes BPF_REG_FP into a register. They either throw from the main program, where BPF_REG_FP already holds the value the callback needs, or use a callback whose only stack accesses are frame pointer relative, which the arm64 JIT rewrites to be stack pointer relative. Add a test that throws from a subprogram using its own BPF stack, with a callback that hands the address of a local variable to bpf_probe_read_kernel(). The helper and the callback have to name the same slot for the value read back to be the one the helper stored. Signed-off-by: Donggeun Yoo <donggeunyoo.kernel@gmail.com> Link: https://lore.kernel.org/r/20260907130624.611942-3-donggeunyoo.kernel@gmail.com Signed-off-by: Alexei Starovoitov <ast@kernel.org>
2026-09-13selftests/bpf: Add test for indirect struct_ops trampolineTiezhu Yang
Add a test case to verify that arguments passed on the stack are correctly read by an indirect struct_ops trampoline. This test ensures the correctness of stack offsets across various architectures. It is particularly critical for architectures like LoongArch, RISC-V, ARM64, and PowerPC where arguments beyond the first 8 registers are passed on the stack, as well as x86_64 and s390x which have lower register argument limits. Signed-off-by: Tiezhu Yang <yangtiezhu@loongson.cn> Link: https://lore.kernel.org/r/20260908073506.29734-1-yangtiezhu@loongson.cn Signed-off-by: Alexei Starovoitov <ast@kernel.org>
2026-09-12selftests/bpf: Add tests for by-value kfunc argumentsYonghong Song
Add kfuncs taking a 16-byte struct and an __int128 by value, with combinations of <= 8 byte arguments and '> 8 && <= 16' byte arguments. Each kfunc weighs its parameters by argument slot, the first by one, the second by two and so on, and every test checks the value it returns. A plain sum would be the same whichever slot each value reached, so an argument that lands in the wrong one, or a 16-byte argument whose halves arrive the other way round, would pass quietly; a weighted one differs. An __int128 takes two argument slots. One test passes it in registers and one past them, where both conventions pad the stack to align it although the BPF convention does not, so both JITs move it up an eightbyte. Two more cover a rejection. An aggregate holding a pointer is refused everywhere, and in arena_kfunc.c a two-slot struct pushes an arena pointer past the argument registers, which is refused too. An aggregate too large to pass by value is already covered in aggregate_arg_func.c. test_stack_arg_big() in stack_arg_fail.c passed a 16-byte struct as the sixth argument and asserted the unrecognized stack argument type it used to be reported as. The JIT places that argument now, so the test is removed. Signed-off-by: Yonghong Song <yonghong.song@linux.dev> Link: https://lore.kernel.org/r/20260912195313.992803-1-yonghong.song@linux.dev Signed-off-by: Alexei Starovoitov <ast@kernel.org>
2026-09-12selftests/bpf: Add inline-asm tests for by-value argumentsYonghong Song
The tests cover a struct passed in a register pair, a pointer in one half of it refused at the call site, a struct too large to pass by value, and four placements a global function cannot have: six scalars, a struct split between the last argument register and the stack, one wholly past the registers, and an __int128 whose two slots push the last parameter out. The six-scalar case is the one whose slot count is known from the parameters alone, so it takes the check btf_prepare_func_args() makes before it walks them, while the other three take the one it makes after. Both report the same way. GCC passes an aggregate by invisible reference, so a callee it compiles expects a pointer where BTF says the halves of the struct are, and those tests are left to clang. Signed-off-by: Yonghong Song <yonghong.song@linux.dev> Link: https://lore.kernel.org/r/20260912195308.992139-1-yonghong.song@linux.dev Signed-off-by: Alexei Starovoitov <ast@kernel.org>
2026-09-12selftests/bpf: Add C tests for by-value arguments up to 16 bytesYonghong Song
Extend the by-value argument test with the aggregate cases, written in C so that they depend on the compiler lowering the argument into a pair of argument registers rather than on a hand-written register layout. The programs cover a struct and a union that fill two registers, a smaller struct that fills one, and two struct arguments in a row, alongside the __int128 already there. Each has an int argument around it so that a wrong slot count shows up as a wrong value in the parameters beside it; two pairs leave room for only one, which follows them. A global function taking a struct with a pointer member is rejected: the callee would receive the pointer as an opaque scalar. A struct the argument registers cannot hold reaches the callee partly on the stack, which the interpreter does not implement, so that case is loaded only when the JIT is on. Signed-off-by: Yonghong Song <yonghong.song@linux.dev> Link: https://lore.kernel.org/r/20260912195302.991273-1-yonghong.song@linux.dev Signed-off-by: Alexei Starovoitov <ast@kernel.org>
2026-09-12bpf: Support __int128 as a by-value function argumentYonghong Song
A 128-bit integer follows the same calling convention as a 16-byte by-value struct: LLVM emits it as a 16-byte BTF_KIND_INT and passes it in two consecutive argument registers. So a __int128 gets its two slots. The test added at the start of the series, which recorded the wrong register map as an R4 !read_ok rejection, now passes and is flipped to __success. Signed-off-by: Yonghong Song <yonghong.song@linux.dev> Link: https://lore.kernel.org/r/20260912195227.987991-1-yonghong.song@linux.dev Signed-off-by: Alexei Starovoitov <ast@kernel.org>
2026-09-12bpf: Rename bpf_subprog_info::arg_cnt to arg_slot_cntYonghong Song
Rename arg_cnt to arg_slot_cnt, as a later patch gives a parameter that takes two argument registers, an __int128 or a 16-byte aggregate, two slots. No functional change. Signed-off-by: Yonghong Song <yonghong.song@linux.dev> Link: https://lore.kernel.org/r/20260912195211.986081-1-yonghong.song@linux.dev Signed-off-by: Alexei Starovoitov <ast@kernel.org>
2026-09-12selftests/bpf: Add a test for an __int128 by-value argumentYonghong Song
A 128-bit integer is passed in two consecutive argument registers, but the verifier counts one argument register per parameter whatever its size. For __u64 take_i128_global(int a, u128 v, int c) the compiler passes a in R1, v in R2:R3 and c in R4, while the verifier marks only R1 through R3 at the entry of the global function. The callee then reads its own third parameter out of a register the verifier considers uninitialized, and the program is rejected for a register the source never names: Validating take_i128_global() func#1... 20: R1=scalar() R2=scalar() R3=scalar() R10=fp0 ; __noinline __u64 take_i128_global(int a, u128 v, int c) @ verifier_aggregate_arg.c:12 20: (bf) r0 = r2 ; R0=scalar(id=4) R2=scalar(id=4) ; return (__u64)a + (__u64)(v >> 64) + (__u64)v + c; @ verifier_aggregate_arg.c:14 21: (bc) w1 = w1 ; R1=scalar(smin=0,smax=umax=0xffffffff,var_off=(0x0; 0xffffffff)) 22: (67) r1 <<= 32 ; R1=scalar(smax=0x7fffffff00000000,smin32=0,smax32=umax32=0,var_off=(0x0; 0xffffffff00000000)) 23: (c7) r1 s>>= 32 ; R1=scalar(smin=0xffffffff80000000,smax=0x7fffffff) 24: (0f) r0 += r1 ; R0=scalar() R1=scalar(smin=0xffffffff80000000,smax=0x7fffffff) 25: (0f) r0 += r3 ; R0=scalar() R3=scalar() 26: (bc) w1 = w4 R4 !read_ok The log is from clang 23. LLVM 21/22 place the argument in the same registers. Add the test with the failure it produces now. A later patch, "bpf: Support __int128 as a by-value function argument", places the two slots and flips this test to __success. Signed-off-by: Yonghong Song <yonghong.song@linux.dev> Link: https://lore.kernel.org/r/20260912195206.984633-1-yonghong.song@linux.dev Signed-off-by: Alexei Starovoitov <ast@kernel.org>
2026-09-12selftests/bpf: Test terminal gotox instructionsSiddharth Chintamaneni
Add tests that place gotox at the end of the main program and a subprogram, with each jump-table target preceding the gotox instruction. This tests gotox as a valid non-fallthrough terminal instruction. Signed-off-by: Siddharth Chintamaneni <sidchintamaneni@gmail.com> Reviewed-by: Anton Protopopov <a.s.protopopov@gmail.com> Link: https://lore.kernel.org/r/20260902171414.96165-2-sidchintamaneni@gmail.com Signed-off-by: Alexei Starovoitov <ast@kernel.org>
2026-09-11bpf: Check helper and kfunc arguments in one pathAmery Hung
Generated kfunc prototypes now carry the argument kinds and metadata needed by the helper argument checker, but kfunc calls still duplicate the per-argument loop and switch. Add check_func_args() to determine the argument count, validate outgoing kfunc stack arguments, and drive check_func_arg() for both call kinds. Move the remaining kfunc-only argument handlers, including the dynptr clone runtime refinement, into check_func_arg(), derive each kfunc BTF referent there once, and skip check_reg_arg() for stack-passed arguments that check_outgoing_stack_args() already validated. Keep special-kfunc ID checks behind small helpers so their table can remain in place. Keep the intentional differences selected by call metadata: helpers retain their privileged ARG_ANYTHING pointer-leak behavior, while kfunc scalars use strict ARG_SCALAR register admission. The shared ARG_PTR_TO_BTF_ID case retains helper-only compatible-ID and bpf_kptr_xchg() handling, performs kfunc trusted/RCU provenance checks, and selects the expected BTF based on call kind. Helper and kfunc memory arguments likewise retain their access modes and share fixed-memory and memory/size diagnostics. Treat an accepted nullable NULL as a completed argument check, matching the former kfunc continue path. The skipped helper-specific processing is either a no-op for NULL or deferred to the paired size argument. Signed-off-by: Amery Hung <ameryhung@gmail.com> Link: https://lore.kernel.org/r/20260911220415.1396439-24-ameryhung@gmail.com Signed-off-by: Alexei Starovoitov <ast@kernel.org>
2026-09-11selftests/bpf: Test nullable per-CPU kptr identity after exchangeAmery Hung
Pass two unchecked bpf_percpu_obj_new() results to bpf_kptr_xchg() inside an RCU critical section. The exchanges consume ownership and leave nullable RCU-protected aliases. Checking the first alias must not make the second non-NULL. Verify that bpf_this_cpu_ptr() still rejects the unchecked second alias. Signed-off-by: Amery Hung <ameryhung@gmail.com> Link: https://lore.kernel.org/r/20260911220415.1396439-23-ameryhung@gmail.com Signed-off-by: Alexei Starovoitov <ast@kernel.org>
2026-09-11bpf: Consolidate release argument validationAmery Hung
Helper and kfunc argument verification both require a live owning reference for non-dynptr release arguments. Whether that reference may be NULL is expressed by PTR_MAYBE_NULL in helper prototypes and the __nullable BTF suffix for kfuncs. Factor the shared ownership policy into check_func_arg_release(). Drop the helper-only rejection of maybe-null owning references. This allows bpf_kptr_xchg() to accept its explicitly nullable source directly, matching nullable kfunc release arguments. The verifier consumes the reference regardless of its runtime nullness. Update the tests so an owned nullable source succeeds while a nullable non-owning source remains rejected for lacking ownership. Preserve the identity of a nullable per-CPU allocation when bpf_kptr_xchg() transfers its ownership inside an RCU critical section. The converted MEM_RCU aliases no longer own a reference, but still need a non-zero ID so a NULL check on one allocation cannot refine another unrelated allocation. Use common legacy and structured diagnostic text for both call kinds. Tailor the structured suggestion to describe a pointer for helpers and include the expected BTF type for kfuncs. Resolve that type lazily from the kfunc BTF parameter only when reporting an ownership failure. The kfunc path now keys the check directly on the cached OBJ_RELEASE argument flag instead of comparing the argument register against meta->release_regno, and uses the cached argument kind for the dynptr exemption. This is another prerequisite for routing both call types through check_func_arg(). Signed-off-by: Amery Hung <ameryhung@gmail.com> Link: https://lore.kernel.org/r/20260911220415.1396439-22-ameryhung@gmail.com Signed-off-by: Alexei Starovoitov <ast@kernel.org>
2026-09-11selftests/bpf: Test kfunc packet memory direct writesAmery Hung
A kfunc memory argument may be backed by packet data. Exercise this with bpf_skb_ct_lookup(), which writes errors through its opts memory argument. Verify that the verifier marks the program as directly writing packet data, causing TC to emit its writable-skb prologue. Match the semantic prologue sequence while allowing architecture-specific zero extensions and the endian-specific cloned-bit mask. Signed-off-by: Amery Hung <ameryhung@gmail.com> Link: https://lore.kernel.org/r/20260911220415.1396439-21-ameryhung@gmail.com Signed-off-by: Alexei Starovoitov <ast@kernel.org>
2026-09-11bpf: Consolidate function call pkt_access validationAmery Hung
check_func_arg() checks whether a helper permits packet pointers before dispatching argument-specific memory validation. check_kfunc_args() has no equivalent check, even though kfunc memory arguments may be backed by packet data. Move packet-access validation to check_helper_mem_access(), where the access direction is known and helper, kfunc, and global-subprogram memory arguments converge. Pass call metadata there so helpers continue to require bpf_func_proto::pkt_access, while writes through kfunc and global subprogram arguments use the program-type policy and set env->seen_direct_write. Keep call metadata when variable-size memory disables raw mode by clearing arg_raw_mem.regno instead, and pass it through the map-key path as well. This also makes kfunc and global-subprogram packet writes request the required writable-packet prologue and rejects them for program types that only support direct packet reads. Signed-off-by: Amery Hung <ameryhung@gmail.com> Link: https://lore.kernel.org/r/20260911220415.1396439-20-ameryhung@gmail.com Signed-off-by: Alexei Starovoitov <ast@kernel.org>
2026-09-11bpf: Admit kfunc argument registers through check_reg_type()Amery Hung
check_kfunc_args() open-codes exact register-type tests in most of its per-argument cases, duplicating what compatible_reg_types[] already expresses for helpers. This leaves two admission paths and prevents the helper and kfunc loops from converging. Runtime argument resolution now converts a scalar-struct BTF argument to fixed-size memory before register admission. Give the remaining kfunc-only argument kinds compatibility entries and run check_reg_type() once before the per-kind switch. Kfunc memory arguments already accept BPF-allocated objects. Normalize only the local comparison type to PTR_TO_MEM; subsequent memory checks still inspect the original register type. Keep allocated-object forms out of mem_types so helper calls continue through the existing type-mismatch path and retain its diagnostic. For ARG_PTR_TO_BTF_ID, let check_reg_type() admit BTF-backed register types and reject incompatible register classes with its standard diagnostic. Remove the now-unused lookup_reg2btf_ids(). Exact BTF identity and trust requirements remain checked later by process_arg_ptr_to_btf_id(). ARG_IGNORE and ARG_PTR_TO_PROG_AUX remain skipped because the verifier does not read those arguments from the program. Iterator arguments use the stack-pointer table. Graph nodes and ARG_PTR_TO_REFCOUNTED_KPTR share an allocated-object table. It admits owning and borrowed objects, including RCU-protected forms. Their switch cases retain API-specific ownership and BTF-record validation. ARG_PTR_TO_ALLOC_BTF_ID uses a separate table for object-drop arguments. Rename timer_types to map_value_types now that ARG_PTR_TO_WORKQUEUE and ARG_PTR_TO_TASK_WORK share it. Similarly, rename spin_lock_types to map_value_or_alloc_obj_types because graph roots and resource spin locks share its map-value-or-allocated-object admission. Moving admission checks into check_reg_type() must not discard the structured call-argument diagnostics emitted by the individual cases. Add bpf_diag_arg_type_plain() alongside bpf_diag_reg_type_plain() and use it to preserve the existing per-kind Pass suggestions where available. Other argument kinds retain the generic suggestion. The reason continues to report the actual register type and all accepted register types. Two behavior changes fall out of running admission first: - ARG_CONST_MEM_SIZE reaches process_const_arg(), and through it mark_chain_precision(), only after the register is known to be a scalar. Passing a pointer as a __szk argument used to reach backtrack_insn() with a non-scalar and trip the backtracking-misuse verifier bug. - ARG_CONST_MAP_PTR no longer needs its own type_may_be_null() test, because check_reg_type() compares whole register types. Every kfunc argument that is not explicitly ignored now passes through check_reg_type(), followed by the common register-offset check in the same order as a helper argument. Signed-off-by: Amery Hung <ameryhung@gmail.com> Link: https://lore.kernel.org/r/20260911220415.1396439-19-ameryhung@gmail.com Signed-off-by: Alexei Starovoitov <ast@kernel.org>
2026-09-11bpf: Consolidate helper and kfunc PTR_TO_BTF_ID argument matchingAmery Hung
Keep check_reg_type() focused on register admission. Helpers currently match BTF-ID arguments there, while kfuncs use process_kf_arg_ptr_to_btf_id(). Both paths ultimately call btf_struct_ids_match(). Introduce process_arg_ptr_to_btf_id() for helpers, kfuncs, and global subprograms. Callers provide the expected BTF and ID and retain their call-specific metadata handling. Group the helper compatible-ID, poison, and bpf_kptr_xchg() handling in a helper-only block in the ARG_PTR_TO_BTF_ID case, leaving the common matcher outside it. Derive strict matching from the generated argument type. This limits KF_RELEASE strictness to the argument marked OBJ_RELEASE while preserving the bpf_sk_release() exception and kfunc no-cast-alias rule. Remove the post-admission BTF and nullability switch from check_reg_type(), leaving it responsible for register admission. The compatibility tables already limit helper MEM_ALLOC inputs to ARG_PTR_TO_SPIN_LOCK and ARG_KPTR_XCHG_DEST, while the kptr source is admitted only for bpf_kptr_xchg(). Drop the redundant helper-ID whitelist, pointer-offset check, and constant-offset assertion. The bpf_kptr_xchg() source match now follows offset validation, so a source within a referenced object reports the release zero-offset error before the kptr type error. Update the affected selftests and use call-neutral wording for BTF mismatch diagnostics. Signed-off-by: Amery Hung <ameryhung@gmail.com> Link: https://lore.kernel.org/r/20260911220415.1396439-18-ameryhung@gmail.com Signed-off-by: Alexei Starovoitov <ast@kernel.org>