From nobody Fri Jul 24 22:54:57 2026 Received: from mail-wm1-f71.google.com (mail-wm1-f71.google.com [209.85.128.71]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CEEBC3DFC6B for ; Wed, 22 Jul 2026 11:41:40 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.71 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784720503; cv=none; b=uwiBIQjHRbdqC8WmwNyk90U0rZOtp6GQJneXTELk0AU83YGEDiCP7GK0QcwcKPS2KLgoYNzjHAtWMWc7T3PDGVaEwNmvqECGO327AkgzV/Utj4J045EqlAIbow50Ql9YjjygEbrS+fh/P5riofgGWcn1tOOSVlyqGYMq7i5xcRI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784720503; c=relaxed/simple; bh=oiqsiXH2auvvTcy+XpKqq3f+Cggs5IcjKSAEqS0H5jI=; h=Date:Mime-Version:Message-ID:Subject:From:To:Cc:Content-Type; b=GSIC/GH9cWi6WLBPfpFUMFns29uQAJpjhR7m3uC/NETPT6xmQ694bECgNm0Q2ccx4ql+UqD2W0IoOwcNJK4yDYYcQRqOt3DVNQ2RSGQ4PkKRTa/5Mqvmc0emx2e8G7pbaZBDQBYPe3pEiWItxb11FePBMQmZR6gbn3QftU/4mJo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--sidnayyar.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=Pru3Trle; arc=none smtp.client-ip=209.85.128.71 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--sidnayyar.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="Pru3Trle" Received: by mail-wm1-f71.google.com with SMTP id 5b1f17b1804b1-4955fd77c18so23901375e9.2 for ; Wed, 22 Jul 2026 04:41:40 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784720499; x=1785325299; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:mime-version:date:from :to:cc:subject:date:message-id:reply-to:content-type; bh=5EEdu2NtDKvJ6m5L7yD3u1hILhc3acdgjyOagawBBaU=; b=Pru3Trle65O6AmM9lDZgylvzE04eqtnMGLnAWwot+Zx5jMMHmWj9XT7gCLBJksQYpr 21kgRKzLu29m45NWXs2uYjOlCQvw61b983HZGilgjpiRmfbuxy7LXVx4tSepcWVHbyN4 Iobqf5a8vDQrFo1XJFHjGr3I+qieBM0McZw8pPNMfNFsmBaJRUK+O0XWXVeFg6APEAkl dbsVfNVfJjhI2u1pfMASnwsq1n9UOvRxsAC9QEIxomT8ZB9cd5GvrFjBTgOceCq5a6dp F+tvGVbHJJ7EKpDXuVkNX3rVt+w2qXUZGOPnq8b8WHUag7MqZHSPcsnKSsQkE/EI1Yvh ZtCw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784720499; x=1785325299; h=content-type:cc:to:from:subject:message-id:mime-version:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=5EEdu2NtDKvJ6m5L7yD3u1hILhc3acdgjyOagawBBaU=; b=hFRTEb7uQ5/PZv7m5wrEigKVkjHhVhheRZJi3ZX0H+CMt2hq6XrUShzWY/AW196alu s8aGmtDmEAS4aSIFnMgSRYULX1bW/sR2GNJNbrPArK6XcyLqDIuqFzPH6kQ6s59J+fcd 1B/t16vLpz1pJORIWOhT9ZNsIPSqp8ZFIW1BmwLhmo7Do1D+3kYuzlbH0Niy6TFAuiZh R9vkEj3EIk+rKOajohNiyuozh237SmRrGNim8pbKGafby27QFV7VImTWsTZZH50jkCK2 66aKxfIhjGK7nSWRR0Qc8f2zwu4oK+clHSXUi9/+m0z3o8zF+8PEOzE3MDHYkGWc/PNo oQYg== X-Forwarded-Encrypted: i=1; AHgh+RoEO28iwcuGistPrY5fSWqXwX8pNC7KD0vxYBhUI1DFtC4rKH89NaUvXJfF/ZInw8+aaSw9PEl3kkXdsNA=@vger.kernel.org X-Gm-Message-State: AOJu0YzrHEQZLI+iVKCsV8mE1aMivvTyZx+eEYGcIIkoA6R8J0Aru0vH nBoJZzSqSFbFgHrPa9XwC3joQdf16n6IinPHjm0dEJDGaApp7vByBjPsomjcg+hTkM/HTO1ydoO epra8BEnPTz0OvPUK3A== X-Received: from wrzf10.prod.google.com ([2002:a05:6000:1b0a:b0:46e:4b8:3001]) (user=sidnayyar job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:c84:b0:493:dcad:84da with SMTP id 5b1f17b1804b1-4954a3eec74mr269227495e9.1.1784720498761; Wed, 22 Jul 2026 04:41:38 -0700 (PDT) Date: Wed, 22 Jul 2026 11:41:31 +0000 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-B4-Tracking: v=1; b=H4sIAGqsYGoC/32NQQ6CMBBFr0Jm7Zh2lCKuvIdhUcpQGpGS1jQa0 rtbOYDL93/e/xtEDo4jXKsNAicXnV8K0KECM+nFMrqhMJAgJRQR9uuIc3zwjKN7c0TCpr6Ik9L ctlJC8dbAe1W0e1d4cvHlw2e/SPKX/ltLEiUKcR4aMr2uDd2s93bmo/FP6HLOX1YCZqqzAAAA X-Change-Id: 20260622-bpf-lskel-fixes-2-758036ae9911 X-Mailer: b4 0.14.3 Message-ID: <20260722-bpf-lskel-fixes-2-v2-1-1ec545c6861c@google.com> Subject: [PATCH v2] libbpf: poison unresolved weak kfuncs in light skeletons From: Siddharth Nayyar To: Alexei Starovoitov , Daniel Borkmann , Andrii Nakryiko , Eduard Zingerman , Kumar Kartikeya Dwivedi , Martin KaFai Lau , Song Liu , Yonghong Song , Jiri Olsa , Emil Tsalapatis Cc: bpf@vger.kernel.org, linux-kernel@vger.kernel.org, Giuliano Procida , Matthias Maennich , Tiffany Yang , Neill Kapron , Siddharth Nayyar Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable When the light skeleton generator (gen_loader) fails to find a BTF ID for a weak kfunc, it correctly clears the immediate value (imm =3D 0) to convert the pseudo kfunc call into an invalid instruction. However, the generator fails to clear src_reg (which is set to BPF_PSEUDO_KFUNC_CALL). This leaves the instruction looking like a valid pseudo kfunc call with a zero BTF ID. When the target verifier's add_subprog_and_kfunc encounters this, it unconditionally scans all BPF_PSEUDO_KFUNC_CALL instructions, sees imm =3D=3D 0, and panics or fails the load (e.g. bpf_unspec#0 or -EINVAL). This entirely breaks the verifier's dead-code elimination logic which expects to cleanly prune branches protected by bpf_ksym_exists(). Furthermore, when the generator processes subsequent references to the same unresolved weak kfunc, it copies the imm and off fields from the first occurrence but skips the src_reg field, meaning subsequent calls also retain the poisonous BPF_PSEUDO_KFUNC_CALL flag. This patch fixes the issue by explicitly clearing src_reg for both the initial occurrence and all subsequent occurrences of unresolved weak kfuncs, converting them into standard invalid helper calls that the verifier's dead-code eliminator can safely recognize and discard. Fixes: 18f4fccbf314 ("libbpf: Update gen_loader to emit BTF_KIND_FUNC reloc= ations") Signed-off-by: Siddharth Nayyar Acked-by: Yonghong Song --- Changes in v2: - Rebased and added Fixes and Acked-by tags - Link to v1: https://lore.kernel.org/r/20260622-bpf-lskel-fixes-2-v1-1-004= d72cba5c2@google.com --- tools/lib/bpf/gen_loader.c | 15 ++++++++++++--- 1 file changed, 12 insertions(+), 3 deletions(-) diff --git a/tools/lib/bpf/gen_loader.c b/tools/lib/bpf/gen_loader.c index d79695f01c87..a08071114347 100644 --- a/tools/lib/bpf/gen_loader.c +++ b/tools/lib/bpf/gen_loader.c @@ -783,10 +783,17 @@ static void emit_relo_kfunc_btf(struct bpf_gen *gen, = struct ksym_relo_desc *relo return; /* try to copy from existing bpf_insn */ if (kdesc->ref > 1) { - move_blob2blob(gen, insn + offsetof(struct bpf_insn, imm), 4, - kdesc->insn + offsetof(struct bpf_insn, imm)); move_blob2blob(gen, insn + offsetof(struct bpf_insn, off), 2, kdesc->insn + offsetof(struct bpf_insn, off)); + move_blob2blob(gen, insn + offsetof(struct bpf_insn, imm), 4, + kdesc->insn + offsetof(struct bpf_insn, imm)); + /* + * jump over src_reg adjustment if imm (btf_id) is not 0, reuse BPF_REG_= 0 from + * move_blob2blob. If btf_id is zero, clear BPF_PSEUDO_KFUNC_CALL flag i= n src_reg + * of call insn. + */ + emit(gen, BPF_JMP_IMM(BPF_JNE, BPF_REG_0, 0, 1)); + emit(gen, BPF_ST_MEM(BPF_B, BPF_REG_8, 1, 0)); goto log; } /* remember insn offset, so we can copy BTF ID and FD later */ @@ -804,10 +811,12 @@ static void emit_relo_kfunc_btf(struct bpf_gen *gen, = struct ksym_relo_desc *relo } kdesc->off =3D btf_fd_idx; /* jump to success case */ - emit(gen, BPF_JMP_IMM(BPF_JSGE, BPF_REG_7, 0, 3)); + emit(gen, BPF_JMP_IMM(BPF_JSGE, BPF_REG_7, 0, 4)); /* set value for imm, off as 0 */ emit(gen, BPF_ST_MEM(BPF_W, BPF_REG_8, offsetof(struct bpf_insn, imm), 0)= ); emit(gen, BPF_ST_MEM(BPF_H, BPF_REG_8, offsetof(struct bpf_insn, off), 0)= ); + /* clear src_reg (and dst_reg) to convert pseudo kfunc call into invalid = helper call */ + emit(gen, BPF_ST_MEM(BPF_B, BPF_REG_8, 1, 0)); /* skip success case for ret < 0 */ emit(gen, BPF_JMP_IMM(BPF_JA, 0, 0, 10)); /* store btf_id into insn[insn_idx].imm */ --- base-commit: 248951ddc14de84de3910f9b13f51491a8cd91df change-id: 20260622-bpf-lskel-fixes-2-758036ae9911 Best regards, --=20 Siddharth Nayyar