From nobody Thu Sep 24 20:34:08 2026 Received: from mail-pl1-f197.google.com (mail-pl1-f197.google.com [209.85.214.197]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8FCDA286D5E for ; Mon, 21 Sep 2026 00:22:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.197 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789950143; cv=none; b=O4hKJ7o8Y8CJ6i2ML26boY19CdAAdQ/gYZYFRoKfZyYdAgf3uGnAM2yvwHRS6icj2U+Foa300Ul/pXUF/LSW83e+i2WkIgdbG8LaDbLJecdFqtjb78MlG7BNc5E+EdNvSpN0GM+Bq57D068EYds9YIPqZQONRBqiq9wYYTvSjjo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789950143; c=relaxed/simple; bh=9BoRwKdzMPqnuZFFmagCsFhvyZ8P2pSNyFQ7j3oK7v8=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=GfEfyTV1llduR0FywT+xoaWQk/ym8wbzVIvKaAgRFv+PmKsuXktjrtI7YuzAs73p1N4ZkvMjFPbLXvTvh7N78FgLvxIZJGCMNloqR0HFsn+sFYohlPJFX+xp9kR9BzgKTAxq4eH6jC8ESOHEATy9UIrYS4idI5Vrob40DQvNBQM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--tjmercier.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=AxyKShqP; arc=none smtp.client-ip=209.85.214.197 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--tjmercier.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="AxyKShqP" Received: by mail-pl1-f197.google.com with SMTP id d9443c01a7336-2d9336581a2so44945355ad.3 for ; Sun, 20 Sep 2026 17:22:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1789950140; x=1790554940; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=aVzoWdD3mq0g13l29+wCGPh2I8BfciJ7D7lfixCX2AM=; b=AxyKShqPa1BvC4v+WxvHoR9LJRx7v2Z+wJPBovkRw0jegm3R7nWzpLewKjlsMFdKm0 G7B+zswwp7pi19hZpCWTLnjDiU5xcvGq6+waIy6PXTqV177eVIkfXPNBhtDMJFOYlxCm BE/IcvbB8EVzIXtho8TPEBH4Q78S1uUngdhQFX+kp6M4aU3jK1sRPb/VVstXNMUg6Ebd TMq6bSD/yuiM+RHWcXITEexNZhzB8iACkKiBkni52Z9ExwrYbTQT28C7HWXsMiu8OfA/ oB309LXI0HpiSSkAz+GvOy5AGmPgZa78p9CZ5e8ZvuUoVAdSttge6gsW6W2hqQJnWKJv yByw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789950140; x=1790554940; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=aVzoWdD3mq0g13l29+wCGPh2I8BfciJ7D7lfixCX2AM=; b=FMRw76fSs0mbGKC1GQcIOf2606qhaws2l9URSjDL1QKaShY+R9RuNl6ikhS9SGP8xg v24VBbi0XG8cz7zCsWL7jrmDT3QatRy5Cn7UTm5miOaYe735e0S2EcqH/XOCcta+75cA +tiV8ud1GFJfTHr+nY57Kzhg/xw9woXDxUpEU2hB4kwLgkVxwWNt57PMWOC94Dm61/mN CTgJW6HP40JTyUZHnguY9IEbRtEUUzSE13VHWvbQma7wN1rrmSHJ72EkfxJ6yqy/ifrp +WA/yB2VGBS8c3SoSiPfWzYreafdtcBFEqNLzmTwtO5w7eeU/TQPRWMiTuKgzUwdYpeg 4EZw== X-Forwarded-Encrypted: i=1; AKwUvBx5zqSlcRjA9nX6O5iSP1m0bJHkE7u+agt/y/Om+X23M+CAmMNzCCo7uc50z8E1VxlA9uGRaK7M4YAffug=@vger.kernel.org X-Gm-Message-State: AFuF++nGHcNkWV3nI8x1+HWxuvgAHMIYB2EvN9zVsKRd6WCraRp+FVWY MBkLSQuQOO7TrXQ+/wdVDxXIlNVkDJmQfwIXWKzkq4B6qssS2dAK27nCxsGcjQ9LXpuEONeHOJI yo/p6zm/ZZ+Zr1tGqHA== X-Received: from plec2.prod.google.com ([2002:a17:902:f302:b0:2df:3be3:2545]) (user=tjmercier job=prod-delivery.src-stubby-dispatcher) by 2002:a17:903:1b08:b0:2dd:c100:9440 with SMTP id d9443c01a7336-2ddc1009c6bmr80310065ad.62.1789950139690; Sun, 20 Sep 2026 17:22:19 -0700 (PDT) Date: Sun, 20 Sep 2026 17:22:03 -0700 In-Reply-To: <20260921002206.184660-1-tjmercier@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260921002206.184660-1-tjmercier@google.com> X-Mailer: git-send-email 2.55.0.1082.g2b9226bbc0-goog Message-ID: <20260921002206.184660-2-tjmercier@google.com> Subject: [PATCH bpf-next v5 1/2] bpf: htab: Split htab_elem_lru and htab_elem_pcpu off of htab_elem From: "T.J. Mercier" To: ast@kernel.org, daniel@iogearbox.net, andrii@kernel.org, eddyz87@gmail.com, memxor@gmail.com, martin.lau@linux.dev, song@kernel.org, yonghong.song@linux.dev, jolsa@kernel.org, emil@etsalapatis.com, ihor.solodrai@linux.dev, mykyta.yatsenko5@gmail.com Cc: bpf@vger.kernel.org, linux-kernel@vger.kernel.org, "T.J. Mercier" Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The htab_elem struct is used as the per-element type for all BPF hash map types and includes bpf_lru_node in a union with a ptr_to_pptr pointer. For standard (non-LRU, non-PCPU) hash maps, the 24 byte union allocated for every element is entirely unused. For non-preallocated PCPU maps, ptr_to_pptr only requires 8 bytes, leaving 16 bytes of unused overhead in the union. For preallocated PCPU maps ptr_to_pptr is unused since elements are freed to the PCPU freelist. Eliminate this per-element memory overhead by splitting htab_elem into dedicated structures for each map type: - struct htab_elem: Minimal structure for standard hash maps and preallocated PCPU maps (saves 24 bytes per element). - struct htab_elem_pcpu: Structure for non-preallocated PCPU maps containing ptr_to_pptr (saves 16 bytes per element). - struct htab_elem_lru: Retains struct bpf_lru_node for LRU maps. Place lru_node and ptr_to_pptr before struct htab_elem in htab_elem_lru and htab_elem_pcpu respectively, and track the offset of htab_elem from the start of the element allocation in htab->elem_offset. This keeps key and value at constant compile-time offsets from struct htab_elem across all hash map types, avoiding dynamic key offset calculations on lookups. All element variants get added to the htab_elem_all union to support the element size rollover check in htab_map_alloc_check(). Signed-off-by: T.J. Mercier --- kernel/bpf/hashtab.c | 164 ++++++++++++------ .../selftests/bpf/progs/map_ptr_kern.c | 2 +- 2 files changed, 114 insertions(+), 52 deletions(-) diff --git a/kernel/bpf/hashtab.c b/kernel/bpf/hashtab.c index 6f331c80130d..905bddadf37f 100644 --- a/kernel/bpf/hashtab.c +++ b/kernel/bpf/hashtab.c @@ -102,6 +102,7 @@ struct bpf_htab { bool use_percpu_counter; u32 n_buckets; /* number of hash buckets */ u32 elem_size; /* size of each element in bytes */ + u32 elem_offset;/* offset of htab_elem in bytes */ u32 hashrnd; }; =20 @@ -117,15 +118,30 @@ struct htab_elem { }; }; }; - union { - /* pointer to per-cpu pointer */ - void *ptr_to_pptr; - struct bpf_lru_node lru_node; - }; - u32 hash; + u32 hash __aligned(8); char key[] __aligned(8); }; =20 +struct htab_elem_lru { + struct bpf_lru_node lru_node; + struct htab_elem elem; +}; + +/* + * Only for non-preallocated PCPU maps. Preallocated PCPU maps don't need + * ptr_to_pptr, and use htab_elem. + */ +struct htab_elem_pcpu { + void *ptr_to_pptr; + struct htab_elem elem; +}; + +union htab_elem_all { + struct htab_elem elem; + struct htab_elem_lru lru; + struct htab_elem_pcpu pcpu; +}; + struct htab_btf_record { struct btf_record *record; u32 key_size; @@ -183,6 +199,21 @@ static inline bool is_fd_htab(const struct bpf_htab *h= tab) return htab->map.map_type =3D=3D BPF_MAP_TYPE_HASH_OF_MAPS; } =20 +static void *htab_elem_container(const struct bpf_htab *htab, struct htab_= elem *l) +{ + return (void *)l - htab->elem_offset; +} + +static void *htab_elem_get_ptr_to_pptr(struct htab_elem *l) +{ + return container_of(l, struct htab_elem_pcpu, elem)->ptr_to_pptr; +} + +static void htab_elem_set_ptr_to_pptr(struct htab_elem *l, void *ptr) +{ + container_of(l, struct htab_elem_pcpu, elem)->ptr_to_pptr =3D ptr; +} + static inline void *htab_elem_value(struct htab_elem *l, u32 key_size) { return l->key + round_up(key_size, 8); @@ -206,7 +237,7 @@ static void *fd_htab_map_get_ptr(const struct bpf_map *= map, struct htab_elem *l) =20 static struct htab_elem *get_htab_elem(struct bpf_htab *htab, int i) { - return (struct htab_elem *) (htab->elems + i * (u64)htab->elem_size); + return htab->elems + i * (u64)htab->elem_size + htab->elem_offset; } =20 /* Both percpu and fd htab support in-place update, so no need for @@ -300,16 +331,16 @@ static void htab_free_elems(struct bpf_htab *htab) * bucket_lock followed by lru_lock is not allowed. In such cases, * bucket_lock needs to be released first before acquiring lru_lock. */ -static struct htab_elem *prealloc_lru_pop(struct bpf_htab *htab, void *key, - u32 hash) +static struct htab_elem_lru *prealloc_lru_pop(struct bpf_htab *htab, void = *key, + u32 hash) { struct bpf_lru_node *node =3D bpf_lru_pop_free(&htab->lru, hash); - struct htab_elem *l; + struct htab_elem_lru *l; =20 if (node) { bpf_map_inc_elem_count(&htab->map); - l =3D container_of(node, struct htab_elem, lru_node); - memcpy(l->key, key, htab->map.key_size); + l =3D container_of(node, struct htab_elem_lru, lru_node); + memcpy(l->elem.key, key, htab->map.key_size); return l; } =20 @@ -349,8 +380,8 @@ static int prealloc_init(struct bpf_htab *htab) if (htab_is_lru(htab)) err =3D bpf_lru_init(&htab->lru, htab->map.map_flags & BPF_F_NO_COMMON_LRU, - offsetof(struct htab_elem, hash) - - offsetof(struct htab_elem, lru_node), + offsetof(struct htab_elem_lru, elem.hash) - + offsetof(struct htab_elem_lru, lru_node), htab_lru_map_delete_node, htab); else @@ -361,11 +392,12 @@ static int prealloc_init(struct bpf_htab *htab) =20 if (htab_is_lru(htab)) bpf_lru_populate(&htab->lru, htab->elems, - offsetof(struct htab_elem, lru_node), + offsetof(struct htab_elem_lru, lru_node), htab->elem_size, num_entries); else pcpu_freelist_populate(&htab->freelist, - htab->elems + offsetof(struct htab_elem, fnode), + htab->elems + htab->elem_offset + + offsetof(struct htab_elem, fnode), htab->elem_size, num_entries); =20 return 0; @@ -452,8 +484,8 @@ static int htab_map_alloc_check(union bpf_attr *attr) attr->value_size =3D=3D 0) return -EINVAL; =20 - if ((u64)attr->key_size + attr->value_size >=3D KMALLOC_MAX_SIZE - - sizeof(struct htab_elem)) + if (round_up((u64)attr->key_size, 8) + round_up((u64)attr->value_size, 8)= >=3D + KMALLOC_MAX_SIZE - sizeof(union htab_elem_all)) /* if key_size + value_size is bigger, the user space won't be * able to access the elements via bpf syscall. This check * also makes sure that the elem_size doesn't overflow and it's @@ -556,6 +588,7 @@ static struct bpf_map *htab_map_alloc(union bpf_attr *a= ttr) */ bool percpu_lru =3D (attr->map_flags & BPF_F_NO_COMMON_LRU); bool prealloc =3D !(attr->map_flags & BPF_F_NO_PREALLOC); + u32 elem_offset =3D 0; struct bpf_htab *htab; int err; =20 @@ -586,7 +619,17 @@ static struct bpf_map *htab_map_alloc(union bpf_attr *= attr) =20 htab->n_buckets =3D roundup_pow_of_two(htab->map.max_entries); =20 - htab->elem_size =3D sizeof(struct htab_elem) + + if (htab_is_lru(htab)) + elem_offset =3D offsetof(struct htab_elem_lru, elem); + else if (percpu && !prealloc) + elem_offset =3D offsetof(struct htab_elem_pcpu, elem); + + BUILD_BUG_ON(elem_offset + sizeof(struct htab_elem) > + sizeof(union htab_elem_all)); + htab->elem_offset =3D elem_offset; + + htab->elem_size =3D htab->elem_offset + + sizeof(struct htab_elem) + round_up(htab->map.key_size, 8); if (percpu) htab->elem_size +=3D sizeof(void *); @@ -797,8 +840,12 @@ static __always_inline void *__htab_lru_map_lookup_ele= m(struct bpf_map *map, struct htab_elem *l =3D __htab_map_lookup_elem(map, key); =20 if (l) { - if (mark) - bpf_lru_node_set_ref(&l->lru_node); + if (mark) { + struct htab_elem_lru *l_lru =3D + container_of(l, struct htab_elem_lru, elem); + + bpf_lru_node_set_ref(&l_lru->lru_node); + } return htab_elem_value(l, map->key_size); } =20 @@ -821,19 +868,17 @@ static int htab_lru_map_gen_lookup(struct bpf_map *ma= p, struct bpf_insn *insn =3D insn_buf; const int ret =3D BPF_REG_0; const int ref_reg =3D BPF_REG_1; + const s16 ref_off =3D (int)offsetof(struct htab_elem_lru, lru_node) + + (int)offsetof(struct bpf_lru_node, ref) - + (int)offsetof(struct htab_elem_lru, elem); =20 BUILD_BUG_ON(!__same_type(&__htab_map_lookup_elem, (void *(*)(struct bpf_map *map, void *key))NULL)); *insn++ =3D BPF_EMIT_CALL(__htab_map_lookup_elem); *insn++ =3D BPF_JMP_IMM(BPF_JEQ, ret, 0, 4); - *insn++ =3D BPF_LDX_MEM(BPF_B, ref_reg, ret, - offsetof(struct htab_elem, lru_node) + - offsetof(struct bpf_lru_node, ref)); + *insn++ =3D BPF_LDX_MEM(BPF_B, ref_reg, ret, ref_off); *insn++ =3D BPF_JMP_IMM(BPF_JNE, ref_reg, 0, 1); - *insn++ =3D BPF_ST_MEM(BPF_B, ret, - offsetof(struct htab_elem, lru_node) + - offsetof(struct bpf_lru_node, ref), - 1); + *insn++ =3D BPF_ST_MEM(BPF_B, ret, ref_off, 1); *insn++ =3D BPF_ALU64_IMM(BPF_ADD, ret, offsetof(struct htab_elem, key) + round_up(map->key_size, 8)); @@ -865,15 +910,16 @@ static void check_and_cancel_fields(struct bpf_htab *= htab, static bool htab_lru_map_delete_node(void *arg, struct bpf_lru_node *node) { struct bpf_htab *htab =3D arg; - struct htab_elem *l =3D NULL, *tgt_l; + struct htab_elem_lru *tgt_l; + struct htab_elem *l =3D NULL; struct hlist_nulls_head *head; struct hlist_nulls_node *n; unsigned long flags; struct bucket *b; int ret; =20 - tgt_l =3D container_of(node, struct htab_elem, lru_node); - b =3D __select_bucket(htab, tgt_l->hash); + tgt_l =3D container_of(node, struct htab_elem_lru, lru_node); + b =3D __select_bucket(htab, tgt_l->elem.hash); head =3D &b->head; =20 ret =3D htab_lock_bucket(b, &flags); @@ -881,7 +927,7 @@ static bool htab_lru_map_delete_node(void *arg, struct = bpf_lru_node *node) return false; =20 hlist_nulls_for_each_entry_rcu(l, n, head, hash_node) - if (l =3D=3D tgt_l) { + if (l =3D=3D &tgt_l->elem) { hlist_nulls_del_rcu(&l->hash_node); bpf_map_dec_elem_count(&htab->map); break; @@ -889,9 +935,9 @@ static bool htab_lru_map_delete_node(void *arg, struct = bpf_lru_node *node) =20 htab_unlock_bucket(b, flags); =20 - if (l =3D=3D tgt_l) + if (l =3D=3D &tgt_l->elem) check_and_cancel_fields(htab, l); - return l =3D=3D tgt_l; + return l =3D=3D &tgt_l->elem; } =20 /* Called from syscall */ @@ -958,8 +1004,8 @@ static void htab_elem_free(struct bpf_htab *htab, stru= ct htab_elem *l) check_and_cancel_fields(htab, l); =20 if (htab->map.map_type =3D=3D BPF_MAP_TYPE_PERCPU_HASH) - bpf_mem_cache_free(&htab->pcpu_ma, l->ptr_to_pptr); - bpf_mem_cache_free(&htab->ma, l); + bpf_mem_cache_free(&htab->pcpu_ma, htab_elem_get_ptr_to_pptr(l)); + bpf_mem_cache_free(&htab->ma, htab_elem_container(htab, l)); } =20 static void htab_put_fd_value(struct bpf_htab *htab, struct htab_elem *l) @@ -1104,6 +1150,8 @@ static struct htab_elem *alloc_htab_elem(struct bpf_h= tab *htab, void *key, bpf_map_inc_elem_count(&htab->map); } } else { + void *container; + if (is_map_full(htab)) if (!old_elem) /* when map is full and update() is replacing @@ -1113,11 +1161,12 @@ static struct htab_elem *alloc_htab_elem(struct bpf= _htab *htab, void *key, */ return ERR_PTR(-E2BIG); inc_elem_count(htab); - l_new =3D bpf_mem_cache_alloc(&htab->ma); - if (!l_new) { + container =3D bpf_mem_cache_alloc(&htab->ma); + if (!container) { l_new =3D ERR_PTR(-ENOMEM); goto dec_count; } + l_new =3D container + htab->elem_offset; } =20 memcpy(l_new->key, key, key_size); @@ -1129,11 +1178,11 @@ static struct htab_elem *alloc_htab_elem(struct bpf= _htab *htab, void *key, void *ptr =3D bpf_mem_cache_alloc(&htab->pcpu_ma); =20 if (!ptr) { - bpf_mem_cache_free(&htab->ma, l_new); + bpf_mem_cache_free(&htab->ma, htab_elem_container(htab, l_new)); l_new =3D ERR_PTR(-ENOMEM); goto dec_count; } - l_new->ptr_to_pptr =3D ptr; + htab_elem_set_ptr_to_pptr(l_new, ptr); pptr =3D *(void __percpu **)ptr; } =20 @@ -1276,16 +1325,19 @@ static long htab_map_update_elem(struct bpf_map *ma= p, void *key, void *value, =20 static void htab_lru_push_free(struct bpf_htab *htab, struct htab_elem *el= em) { + struct htab_elem_lru *l =3D container_of(elem, struct htab_elem_lru, elem= ); + check_and_cancel_fields(htab, elem); bpf_map_dec_elem_count(&htab->map); - bpf_lru_push_free(&htab->lru, &elem->lru_node); + bpf_lru_push_free(&htab->lru, &l->lru_node); } =20 static long htab_lru_map_update_elem(struct bpf_map *map, void *key, void = *value, u64 map_flags) { struct bpf_htab *htab =3D container_of(map, struct bpf_htab, map); - struct htab_elem *l_new, *l_old =3D NULL; + struct htab_elem *l_old =3D NULL; + struct htab_elem_lru *l_new; struct hlist_nulls_head *head; unsigned long flags; struct bucket *b; @@ -1313,7 +1365,7 @@ static long htab_lru_map_update_elem(struct bpf_map *= map, void *key, void *value l_new =3D prealloc_lru_pop(htab, key, hash); if (!l_new) return -ENOMEM; - copy_map_value(&htab->map, htab_elem_value(l_new, map->key_size), value); + copy_map_value(&htab->map, htab_elem_value(&l_new->elem, map->key_size), = value); =20 ret =3D htab_lock_bucket(b, &flags); if (ret) @@ -1328,7 +1380,7 @@ static long htab_lru_map_update_elem(struct bpf_map *= map, void *key, void *value /* add new element to the head of the list, so that * concurrent search will find it before old elem */ - hlist_nulls_add_head_rcu(&l_new->hash_node, head); + hlist_nulls_add_head_rcu(&l_new->elem.hash_node, head); if (l_old) { bpf_lru_node_set_ref(&l_new->lru_node); hlist_nulls_del_rcu(&l_old->hash_node); @@ -1340,7 +1392,7 @@ static long htab_lru_map_update_elem(struct bpf_map *= map, void *key, void *value =20 err_lock_bucket: if (ret) - htab_lru_push_free(htab, l_new); + htab_lru_push_free(htab, &l_new->elem); else if (l_old) htab_lru_push_free(htab, l_old); =20 @@ -1424,7 +1476,8 @@ static long __htab_lru_percpu_map_update_elem(struct = bpf_map *map, void *key, bool onallcpus) { struct bpf_htab *htab =3D container_of(map, struct bpf_htab, map); - struct htab_elem *l_new =3D NULL, *l_old; + struct htab_elem_lru *l_new =3D NULL; + struct htab_elem *l_old; struct hlist_nulls_head *head; unsigned long flags; struct bucket *b; @@ -1466,15 +1519,18 @@ static long __htab_lru_percpu_map_update_elem(struc= t bpf_map *map, void *key, goto err; =20 if (l_old) { - bpf_lru_node_set_ref(&l_old->lru_node); + struct htab_elem_lru *l_old_lru =3D + container_of(l_old, struct htab_elem_lru, elem); + + bpf_lru_node_set_ref(&l_old_lru->lru_node); =20 /* per-cpu hash map can update value in-place */ pcpu_copy_value(htab, htab_elem_get_ptr(l_old, key_size), value, onallcpus, map_flags); } else { - pcpu_init_value(htab, htab_elem_get_ptr(l_new, key_size), + pcpu_init_value(htab, htab_elem_get_ptr(&l_new->elem, key_size), value, onallcpus, map_flags); - hlist_nulls_add_head_rcu(&l_new->hash_node, head); + hlist_nulls_add_head_rcu(&l_new->elem.hash_node, head); l_new =3D NULL; } ret =3D 0; @@ -2453,7 +2509,10 @@ static void *htab_lru_percpu_map_lookup_elem(struct = bpf_map *map, void *key) struct htab_elem *l =3D __htab_map_lookup_elem(map, key); =20 if (l) { - bpf_lru_node_set_ref(&l->lru_node); + struct htab_elem_lru *l_lru =3D + container_of(l, struct htab_elem_lru, elem); + + bpf_lru_node_set_ref(&l_lru->lru_node); return this_cpu_ptr(htab_elem_get_ptr(l, map->key_size)); } =20 @@ -2469,7 +2528,10 @@ static void *htab_lru_percpu_map_lookup_percpu_elem(= struct bpf_map *map, void *k =20 l =3D __htab_map_lookup_elem(map, key); if (l) { - bpf_lru_node_set_ref(&l->lru_node); + struct htab_elem_lru *l_lru =3D + container_of(l, struct htab_elem_lru, elem); + + bpf_lru_node_set_ref(&l_lru->lru_node); return per_cpu_ptr(htab_elem_get_ptr(l, map->key_size), cpu); } =20 diff --git a/tools/testing/selftests/bpf/progs/map_ptr_kern.c b/tools/testi= ng/selftests/bpf/progs/map_ptr_kern.c index 373c8d17ea55..f71be4fc8dd7 100644 --- a/tools/testing/selftests/bpf/progs/map_ptr_kern.c +++ b/tools/testing/selftests/bpf/progs/map_ptr_kern.c @@ -114,7 +114,7 @@ static inline int check_hash(void) VERIFY(check_default_noinline(&hash->map, map)); =20 VERIFY(hash->n_buckets =3D=3D MAX_ENTRIES); - VERIFY(hash->elem_size =3D=3D 64); + VERIFY(hash->elem_size =3D=3D 40); =20 VERIFY(hash->count.counter =3D=3D 0); VERIFY(bpf_map_sum_elem_count(map) =3D=3D 0); --=20 2.55.0.1082.g2b9226bbc0-goog From nobody Thu Sep 24 20:34:08 2026 Received: from mail-pl1-f198.google.com (mail-pl1-f198.google.com [209.85.214.198]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B2D2626ED46 for ; Mon, 21 Sep 2026 00:22:22 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.198 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789950144; cv=none; b=k/X4WNs/puBMEHAYjStLTgkpIKCMEQVZlrow2rl8X2tShuQJdD7uLOFs/5SmRk1kBTaJ4GTrI1LcuOlDLTE/X7rcW7cK/++9fGigViU+EuE0iMwPvxdRAZgbJAZmR5TOaV8lZgS2JG4sE6p3IgeromKRiFM8XjMMdXjHVyBejP0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789950144; c=relaxed/simple; bh=0U9q105QAinJ0FgOptzqZa4yP4E6e0fs6WD6rmMea5M=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=odmZz7AOxjPyXXMwAY9mv41ck6B/XHXGdRzAlM6djXVMwRdu2KZZAwpRpRG9Psj62trC+E4+9tjxaqOtWLp9+Y/qMTmmtDDktCl/+MTlFiUHnIeOIzMTsmWfB1DrwPE+xZJPwEbMwbWLEw0ctoSMrrHzkDN4VCTh9FBK5JPUOhM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--tjmercier.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=pYm2U821; arc=none smtp.client-ip=209.85.214.198 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--tjmercier.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="pYm2U821" Received: by mail-pl1-f198.google.com with SMTP id d9443c01a7336-2d7443e0f0bso47533045ad.1 for ; Sun, 20 Sep 2026 17:22:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1789950142; x=1790554942; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=agijlrmp35jubqCojdz0yntMhx9bktHHpfPZPPCv7PU=; b=pYm2U821UYxeyYig8vZX3VqG5eLp/fvZbQrf5nCGRLXtvN1/irVfbJG0uKCA6TwvK1 Ov5BktKkkJ6jfNYWjGsD/GBrljTpOewj39dEOAIi/8wxZLF8g4icGVvQ2TILgo49bSmB N/NEcy390F9mrahD051fo8WhuwW+OoHDndXiX/rsNrOJMXTcTNUqqJ5NUpvIa2BHW1nS UaMcNscWO7UmtmZu6tOn3UKNXznnsF3r3XNbRlDws0Irjc1KOuVTVgWMW4KaIr977+vt EcrkYFzCYl44fR/Kgy1mAnCDKloYDOE8zYoG/Sf2G6w/oqtOtewrlL7BRjy1PtD25+Wf LNWw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789950142; x=1790554942; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=agijlrmp35jubqCojdz0yntMhx9bktHHpfPZPPCv7PU=; b=QzRo75m0eiNKsRcQmWqH0/nG3/RaFI5thRjKR0l5SKu0kOwRMYft3y37vSw9N0JK4W 19iESRElzUEdEkl9fUNdaflALT/hUsII9skSTSuS+KSGPlex6tfBXrtL44l5XRS10wDL 8C6YvvIMm8E4PrfOCi/VEF4WnIv36Ul/CgH85TK+ZZZMSiuMFbF2/vEAUrXU/GAVcisI 0/+1HrY9CwvAks1rcFqGt2mzY9tlaUeJk0dOWVVkmgldVY+ipIrgF6J32tOxO7CrazVC wJxhtbllPjJTX9I+WEUrhbQpJbVPmz/z0gdTL8aPUys9LG8xtmBb3QUkbvZYtx76BJOI Pt1g== X-Forwarded-Encrypted: i=1; AKwUvBzpN8RlsaFklkLy3lRY7SJCW1lcfXFeEbWiQyTC2g+q3HUTCyYPI3yF+5Uw2GDeLNHnXQdxluzJ7OoickM=@vger.kernel.org X-Gm-Message-State: AFuF++kmdvFMjejIAswtZjxzGqpR8saAVfYz7IQXjR1YdiYF0NeZOTkv 6LstfhecF1w6CZhz7YPl92iIhhzw/FBO5od3nE58y8R9WA7BZMyrUcw5jFg4BsjrYnQTJ1pmA5o /VUNsmVXxx9473TTjCQ== X-Received: from ploc3.prod.google.com ([2002:a17:902:8483:b0:2dd:fc2:99fe]) (user=tjmercier job=prod-delivery.src-stubby-dispatcher) by 2002:a17:902:8496:b0:2dd:c053:a6f6 with SMTP id d9443c01a7336-2ddc053a766mr54092725ad.40.1789950141702; Sun, 20 Sep 2026 17:22:21 -0700 (PDT) Date: Sun, 20 Sep 2026 17:22:04 -0700 In-Reply-To: <20260921002206.184660-1-tjmercier@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260921002206.184660-1-tjmercier@google.com> X-Mailer: git-send-email 2.55.0.1082.g2b9226bbc0-goog Message-ID: <20260921002206.184660-3-tjmercier@google.com> Subject: [PATCH bpf-next v5 2/2] bpf: htab: Reduce elem_size by 8 bytes for small key sizes From: "T.J. Mercier" To: ast@kernel.org, daniel@iogearbox.net, andrii@kernel.org, eddyz87@gmail.com, memxor@gmail.com, martin.lau@linux.dev, song@kernel.org, yonghong.song@linux.dev, jolsa@kernel.org, emil@etsalapatis.com, ihor.solodrai@linux.dev, mykyta.yatsenko5@gmail.com Cc: bpf@vger.kernel.org, linux-kernel@vger.kernel.org, "T.J. Mercier" Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" For standard and PCPU (non-LRU) hash maps with small key sizes (less than or equal to the word size), comparing keys requires only a single instruction. Storing a cached 32-bit hash value to shortcut full key comparisons provides no performance advantage for small keys, and consumes memory for every element. This memory can be saved by removing hash from struct htab_elem and placing it directly before struct htab_elem only for the new htab_elem_hashed type which is used only when keys are larger than the word size or for LRU maps. This reduces elem_size by 8 bytes for small keys while keeping key and hash at constant compile-time offsets from struct htab_elem across all map types and key sizes. All element variants requiring hashes get an anonymous htab_elem_hashed embedding, ensuring that the -8 byte hash offset is guaranteed for all element types by composition. Elements can be recycled without a RCU grace period. Before this commit, alloc_htab_elem() overwrote the key before initializing the value/pptr and wrote the hash last, so during value assignment on a recycled element, the new key was paired with the old hash preventing lockless readers from matching either the old key or the new key except when there was also a hash collision. When hashes are omitted for small keys, only the key field guards lookups. Writing the new key before value/pptr initialization would allow a concurrent lookup of the new key to match an uninitialized value or dereference a stale or freed pptr. So move the new key assignment to the end of alloc_htab_elem() (where the hash assignment was done) behind a write memory barrier. For recycled elements, keeping the old key until the new value is written slightly widens the existing window where a lockless lookup racing with a deletion of the old key can observe the recycled element's new value. Before this commit htab_mem_dtor() was invoked with the start of the allocation, which is no longer always the address of struct htab_elem now that elem_offset can be nonzero for non-preallocated, non-per-CPU maps. So the key_size field of struct htab_btf_record has been replaced with a value_offset computed at map creation and passed through bpf_ma_set_dtor(). That reduces the destructor to a call to bpf_obj_free_fields() at a fixed offset, which is exactly what rhtab_mem_dtor() did, so rhtab_mem_dtor() has been removed and replaced with the new implementation of htab_mem_dtor() for BPF_MAP_TYPE_RHASH. Together with the previous patch, this reduces the minimum standard and preallocated hash map element size from 64 bytes down to 32 bytes, and non-preallocated per-CPU element size from 64 bytes down to 40 bytes. Signed-off-by: T.J. Mercier --- kernel/bpf/hashtab.c | 209 +++++++++++++----- .../selftests/bpf/progs/map_ptr_kern.c | 2 +- 2 files changed, 153 insertions(+), 58 deletions(-) diff --git a/kernel/bpf/hashtab.c b/kernel/bpf/hashtab.c index 905bddadf37f..5e916ccb53e0 100644 --- a/kernel/bpf/hashtab.c +++ b/kernel/bpf/hashtab.c @@ -100,6 +100,7 @@ struct bpf_htab { struct percpu_counter pcount; atomic_t count; bool use_percpu_counter; + bool has_hash; u32 n_buckets; /* number of hash buckets */ u32 elem_size; /* size of each element in bytes */ u32 elem_offset;/* offset of htab_elem in bytes */ @@ -118,13 +119,17 @@ struct htab_elem { }; }; }; - u32 hash __aligned(8); char key[] __aligned(8); }; =20 +struct htab_elem_hashed { + u32 hash __aligned(8); + struct htab_elem elem; +}; + struct htab_elem_lru { struct bpf_lru_node lru_node; - struct htab_elem elem; + struct htab_elem_hashed; }; =20 /* @@ -136,15 +141,29 @@ struct htab_elem_pcpu { struct htab_elem elem; }; =20 +/* + * Only for non-preallocated PCPU maps. Preallocated PCPU maps don't need + * ptr_to_pptr, and use htab_elem_hashed. + */ +struct htab_elem_pcpu_hashed { + void *ptr_to_pptr; + struct htab_elem_hashed; +}; + +static_assert(offsetof(struct htab_elem_pcpu_hashed, ptr_to_pptr) =3D=3D + offsetof(struct htab_elem_pcpu, ptr_to_pptr)); + union htab_elem_all { struct htab_elem elem; + struct htab_elem_hashed hashed; struct htab_elem_lru lru; struct htab_elem_pcpu pcpu; + struct htab_elem_pcpu_hashed pcpu_hashed; }; =20 struct htab_btf_record { struct btf_record *record; - u32 key_size; + u32 value_offset; }; =20 static inline bool htab_is_prealloc(const struct bpf_htab *htab) @@ -199,19 +218,40 @@ static inline bool is_fd_htab(const struct bpf_htab *= htab) return htab->map.map_type =3D=3D BPF_MAP_TYPE_HASH_OF_MAPS; } =20 +static bool htab_has_hash(const struct bpf_htab *htab) +{ + return htab->has_hash; +} + +static u32 htab_elem_hash(struct htab_elem *l) +{ + return READ_ONCE(container_of(l, struct htab_elem_hashed, elem)->hash); +} + +static void htab_elem_set_hash(struct bpf_htab *htab, struct htab_elem *l,= u32 hash) +{ + if (htab_has_hash(htab)) + WRITE_ONCE(container_of(l, struct htab_elem_hashed, elem)->hash, hash); +} + static void *htab_elem_container(const struct bpf_htab *htab, struct htab_= elem *l) { return (void *)l - htab->elem_offset; } =20 -static void *htab_elem_get_ptr_to_pptr(struct htab_elem *l) +static void *htab_elem_get_ptr_to_pptr(const struct bpf_htab *htab, struct= htab_elem *l) { - return container_of(l, struct htab_elem_pcpu, elem)->ptr_to_pptr; + struct htab_elem_pcpu *pcpu_elem =3D htab_elem_container(htab, l); + + return pcpu_elem->ptr_to_pptr; } =20 -static void htab_elem_set_ptr_to_pptr(struct htab_elem *l, void *ptr) +static void htab_elem_set_ptr_to_pptr(const struct bpf_htab *htab, struct = htab_elem *l, + void *ptr) { - container_of(l, struct htab_elem_pcpu, elem)->ptr_to_pptr =3D ptr; + struct htab_elem_pcpu *pcpu_elem =3D htab_elem_container(htab, l); + + pcpu_elem->ptr_to_pptr =3D ptr; } =20 static inline void *htab_elem_value(struct htab_elem *l, u32 key_size) @@ -380,7 +420,7 @@ static int prealloc_init(struct bpf_htab *htab) if (htab_is_lru(htab)) err =3D bpf_lru_init(&htab->lru, htab->map.map_flags & BPF_F_NO_COMMON_LRU, - offsetof(struct htab_elem_lru, elem.hash) - + offsetof(struct htab_elem_lru, hash) - offsetof(struct htab_elem_lru, lru_node), htab_lru_map_delete_node, htab); @@ -502,14 +542,11 @@ static int htab_map_alloc_check(union bpf_attr *attr) static void htab_mem_dtor(void *obj, void *ctx) { struct htab_btf_record *hrec =3D ctx; - struct htab_elem *elem =3D obj; - void *map_value; =20 if (IS_ERR_OR_NULL(hrec->record)) return; =20 - map_value =3D htab_elem_value(elem, hrec->key_size); - bpf_obj_free_fields(hrec->record, map_value); + bpf_obj_free_fields(hrec->record, obj + hrec->value_offset); } =20 static void htab_pcpu_mem_dtor(void *obj, void *ctx) @@ -534,7 +571,7 @@ static void htab_dtor_ctx_free(void *ctx) } =20 static int bpf_ma_set_dtor(struct bpf_map *map, struct bpf_mem_alloc *ma, - void (*dtor)(void *, void *)) + void (*dtor)(void *, void *), u32 value_offset) { struct htab_btf_record *hrec; int err; @@ -546,7 +583,7 @@ static int bpf_ma_set_dtor(struct bpf_map *map, struct = bpf_mem_alloc *ma, hrec =3D kzalloc_obj(*hrec); if (!hrec) return -ENOMEM; - hrec->key_size =3D map->key_size; + hrec->value_offset =3D value_offset; hrec->record =3D btf_record_dup(map->record); if (IS_ERR(hrec->record)) { err =3D PTR_ERR(hrec->record); @@ -572,9 +609,12 @@ static int htab_map_check_btf(struct bpf_map *map, con= st struct btf *btf, * populated in htab_map_alloc(), so it will always appear as NULL. */ if (htab_is_percpu(htab)) - return bpf_ma_set_dtor(map, &htab->pcpu_ma, htab_pcpu_mem_dtor); + return bpf_ma_set_dtor(map, &htab->pcpu_ma, htab_pcpu_mem_dtor, 0); else - return bpf_ma_set_dtor(map, &htab->ma, htab_mem_dtor); + return bpf_ma_set_dtor(map, &htab->ma, htab_mem_dtor, + htab->elem_offset + + offsetof(struct htab_elem, key) + + round_up(map->key_size, 8)); } =20 static struct bpf_map *htab_map_alloc(union bpf_attr *attr) @@ -598,6 +638,14 @@ static struct bpf_map *htab_map_alloc(union bpf_attr *= attr) =20 bpf_map_init_from_attr(&htab->map, attr); =20 + /* + * Avoid hash memory use and comparisons where unnecessary. + * u32 hash reads are always atomic. If we elide them, key comparisons mu= st also be atomic + * to avoid false positive key matches due to torn key reads / writes. Th= is is only possible + * when the key fits within a word, so check key_size. + */ + htab->has_hash =3D htab_is_lru(htab) || htab->map.key_size > sizeof(unsig= ned long); + if (percpu_lru) { /* ensure each CPU's lru list has >=3D1 elements. * since we are at it, make each lru list has the same @@ -622,7 +670,11 @@ static struct bpf_map *htab_map_alloc(union bpf_attr *= attr) if (htab_is_lru(htab)) elem_offset =3D offsetof(struct htab_elem_lru, elem); else if (percpu && !prealloc) - elem_offset =3D offsetof(struct htab_elem_pcpu, elem); + elem_offset =3D htab_has_hash(htab) ? + offsetof(struct htab_elem_pcpu_hashed, elem) : + offsetof(struct htab_elem_pcpu, elem); + else if (htab_has_hash(htab)) + elem_offset =3D offsetof(struct htab_elem_hashed, elem); =20 BUILD_BUG_ON(elem_offset + sizeof(struct htab_elem) > sizeof(union htab_elem_all)); @@ -737,35 +789,67 @@ static inline struct hlist_nulls_head *select_bucket(= struct bpf_htab *htab, u32 return &__select_bucket(htab, hash)->head; } =20 -/* this lookup function can only be called with bucket lock taken */ -static struct htab_elem *lookup_elem_raw(struct hlist_nulls_head *head, u3= 2 hash, - void *key, u32 key_size) +static __always_inline struct htab_elem * +__lookup_elem_raw(struct bpf_htab *htab, struct hlist_nulls_head *head, + u32 hash, void *key, u32 key_size, + struct hlist_nulls_node **out_n) { struct hlist_nulls_node *n; struct htab_elem *l; =20 - hlist_nulls_for_each_entry_rcu(l, n, head, hash_node) - if (l->hash =3D=3D hash && !memcmp(&l->key, key, key_size)) - return l; + if (htab_has_hash(htab)) { + hlist_nulls_for_each_entry_rcu(l, n, head, hash_node) + if (htab_elem_hash(l) =3D=3D hash && + !memcmp(&l->key, key, key_size)) + return l; + } else { + /* + * When hash is omitted, key comparisons must be atomic. Zero extend + * the caller's key to the word size to support an atomic compare. + */ + unsigned long k =3D 0; + + memcpy(&k, key, key_size); + hlist_nulls_for_each_entry_rcu(l, n, head, hash_node) + if (READ_ONCE(*(unsigned long *)l->key) =3D=3D k) + return l; + } =20 + if (out_n) + *out_n =3D n; return NULL; } =20 +/* this lookup function can only be called with bucket lock taken */ +static __always_inline struct htab_elem * +lookup_elem_raw(struct bpf_htab *htab, struct hlist_nulls_head *head, u32 = hash, + void *key, u32 key_size) +{ + return __lookup_elem_raw(htab, head, hash, key, key_size, NULL); +} + /* can be called without bucket lock. it will repeat the loop in * the unlikely event when elements moved from one bucket into another * while link list is being walked */ -static struct htab_elem *lookup_nulls_elem_raw(struct hlist_nulls_head *he= ad, - u32 hash, void *key, - u32 key_size, u32 n_buckets) +static __always_inline struct htab_elem * +lookup_nulls_elem_raw(struct bpf_htab *htab, struct hlist_nulls_head *head, + u32 hash, void *key, u32 key_size, u32 n_buckets) { struct hlist_nulls_node *n; struct htab_elem *l; =20 again: - hlist_nulls_for_each_entry_rcu(l, n, head, hash_node) - if (l->hash =3D=3D hash && !memcmp(&l->key, key, key_size)) - return l; + l =3D __lookup_elem_raw(htab, head, hash, key, key_size, &n); + if (l) { + /* + * Pairs with smp_wmb() in alloc_htab_elem() to ensure + * value/pptr reads happen after key/hash match on + * recycled elements. + */ + smp_rmb(); + return l; + } =20 if (unlikely(get_nulls_value(n) !=3D (hash & (n_buckets - 1)))) goto again; @@ -793,7 +877,7 @@ static void *__htab_map_lookup_elem(struct bpf_map *map= , void *key) =20 head =3D select_bucket(htab, hash); =20 - l =3D lookup_nulls_elem_raw(head, hash, key, key_size, htab->n_buckets); + l =3D lookup_nulls_elem_raw(htab, head, hash, key, key_size, htab->n_buck= ets); =20 return l; } @@ -919,7 +1003,7 @@ static bool htab_lru_map_delete_node(void *arg, struct= bpf_lru_node *node) int ret; =20 tgt_l =3D container_of(node, struct htab_elem_lru, lru_node); - b =3D __select_bucket(htab, tgt_l->elem.hash); + b =3D __select_bucket(htab, READ_ONCE(tgt_l->hash)); head =3D &b->head; =20 ret =3D htab_lock_bucket(b, &flags); @@ -961,7 +1045,7 @@ static int htab_map_get_next_key(struct bpf_map *map, = void *key, void *next_key) head =3D select_bucket(htab, hash); =20 /* lookup the key */ - l =3D lookup_nulls_elem_raw(head, hash, key, key_size, htab->n_buckets); + l =3D lookup_nulls_elem_raw(htab, head, hash, key, key_size, htab->n_buck= ets); =20 if (!l) goto find_first_elem; @@ -1004,7 +1088,7 @@ static void htab_elem_free(struct bpf_htab *htab, str= uct htab_elem *l) check_and_cancel_fields(htab, l); =20 if (htab->map.map_type =3D=3D BPF_MAP_TYPE_PERCPU_HASH) - bpf_mem_cache_free(&htab->pcpu_ma, htab_elem_get_ptr_to_pptr(l)); + bpf_mem_cache_free(&htab->pcpu_ma, htab_elem_get_ptr_to_pptr(htab, l)); bpf_mem_cache_free(&htab->ma, htab_elem_container(htab, l)); } =20 @@ -1169,7 +1253,9 @@ static struct htab_elem *alloc_htab_elem(struct bpf_h= tab *htab, void *key, l_new =3D container + htab->elem_offset; } =20 - memcpy(l_new->key, key, key_size); + if (htab_has_hash(htab)) + memcpy(l_new->key, key, key_size); + if (percpu) { if (prealloc) { pptr =3D htab_elem_get_ptr(l_new, key_size); @@ -1182,7 +1268,7 @@ static struct htab_elem *alloc_htab_elem(struct bpf_h= tab *htab, void *key, l_new =3D ERR_PTR(-ENOMEM); goto dec_count; } - htab_elem_set_ptr_to_pptr(l_new, ptr); + htab_elem_set_ptr_to_pptr(htab, l_new, ptr); pptr =3D *(void __percpu **)ptr; } =20 @@ -1201,7 +1287,26 @@ static struct htab_elem *alloc_htab_elem(struct bpf_= htab *htab, void *key, copy_map_value(&htab->map, htab_elem_value(l_new, key_size), value); } =20 - l_new->hash =3D hash; + /* + * Order value/pptr initialization before publishing the new hash + * (or the new key when hash is omitted) so lockless RCU readers + * matching the new element never observe uninitialized data or + * a stale pptr. + * Pairs with smp_rmb() in lookup_nulls_elem_raw(). + */ + smp_wmb(); + if (htab_has_hash(htab)) { + htab_elem_set_hash(htab, l_new, hash); + } else { + /* + * Zero-extend key into k for an atomic write to support + * lockless RCU readers. + */ + unsigned long k =3D 0; + + memcpy(&k, key, key_size); + WRITE_ONCE(*(unsigned long *)l_new->key, k); + } return l_new; dec_count: dec_elem_count(htab); @@ -1251,7 +1356,7 @@ static long htab_map_update_elem(struct bpf_map *map,= void *key, void *value, if (unlikely(!btf_record_has_field(map->record, BPF_SPIN_LOCK))) return -EINVAL; /* find an element without taking the bucket lock */ - l_old =3D lookup_nulls_elem_raw(head, hash, key, key_size, + l_old =3D lookup_nulls_elem_raw(htab, head, hash, key, key_size, htab->n_buckets); ret =3D check_flags(htab, l_old, map_flags); if (ret) @@ -1273,7 +1378,7 @@ static long htab_map_update_elem(struct bpf_map *map,= void *key, void *value, if (ret) return ret; =20 - l_old =3D lookup_elem_raw(head, hash, key, key_size); + l_old =3D lookup_elem_raw(htab, head, hash, key, key_size); =20 ret =3D check_flags(htab, l_old, map_flags); if (ret) @@ -1371,7 +1476,7 @@ static long htab_lru_map_update_elem(struct bpf_map *= map, void *key, void *value if (ret) goto err_lock_bucket; =20 - l_old =3D lookup_elem_raw(head, hash, key, key_size); + l_old =3D lookup_elem_raw(htab, head, hash, key, key_size); =20 ret =3D check_flags(htab, l_old, map_flags); if (ret) @@ -1438,7 +1543,7 @@ static long htab_map_update_elem_in_place(struct bpf_= map *map, void *key, if (ret) return ret; =20 - l_old =3D lookup_elem_raw(head, hash, key, key_size); + l_old =3D lookup_elem_raw(htab, head, hash, key, key_size); =20 ret =3D check_flags(htab, l_old, map_flags); if (ret) @@ -1512,7 +1617,7 @@ static long __htab_lru_percpu_map_update_elem(struct = bpf_map *map, void *key, if (ret) goto err_lock_bucket; =20 - l_old =3D lookup_elem_raw(head, hash, key, key_size); + l_old =3D lookup_elem_raw(htab, head, hash, key, key_size); =20 ret =3D check_flags(htab, l_old, map_flags); if (ret) @@ -1580,7 +1685,7 @@ static long htab_map_delete_elem(struct bpf_map *map,= void *key) if (ret) return ret; =20 - l =3D lookup_elem_raw(head, hash, key, key_size); + l =3D lookup_elem_raw(htab, head, hash, key, key_size); if (l) hlist_nulls_del_rcu(&l->hash_node); else @@ -1615,7 +1720,7 @@ static long htab_lru_map_delete_elem(struct bpf_map *= map, void *key) if (ret) return ret; =20 - l =3D lookup_elem_raw(head, hash, key, key_size); + l =3D lookup_elem_raw(htab, head, hash, key, key_size); =20 if (l) hlist_nulls_del_rcu(&l->hash_node); @@ -1756,7 +1861,7 @@ static int __htab_map_lookup_and_delete_elem(struct b= pf_map *map, void *key, if (ret) return ret; =20 - l =3D lookup_elem_raw(head, hash, key, key_size); + l =3D lookup_elem_raw(htab, head, hash, key, key_size); if (!l) { ret =3D -ENOENT; goto out_unlock; @@ -2930,18 +3035,6 @@ static int rhtab_map_alloc_check(union bpf_attr *att= r) return htab_map_alloc_check(attr); } =20 -static void rhtab_mem_dtor(void *obj, void *ctx) -{ - struct htab_btf_record *hrec =3D ctx; - struct rhtab_elem *elem =3D obj; - - if (IS_ERR_OR_NULL(hrec->record)) - return; - - bpf_obj_free_fields(hrec->record, - rhtab_elem_value(elem, hrec->key_size)); -} - static void rhtab_free_elem(void *ptr, void *arg) { struct bpf_rhtab *rhtab =3D arg; @@ -3167,7 +3260,9 @@ static int rhtab_map_check_btf(struct bpf_map *map, c= onst struct btf *btf, if (btf_type_is_void(key_type)) return -EINVAL; =20 - return bpf_ma_set_dtor(map, &rhtab->ma, rhtab_mem_dtor); + return bpf_ma_set_dtor(map, &rhtab->ma, htab_mem_dtor, + offsetof(struct rhtab_elem, data) + + round_up(map->key_size, 8)); } =20 static void rhtab_map_free_internal_structs(struct bpf_map *map) diff --git a/tools/testing/selftests/bpf/progs/map_ptr_kern.c b/tools/testi= ng/selftests/bpf/progs/map_ptr_kern.c index f71be4fc8dd7..6bd4cb68c20c 100644 --- a/tools/testing/selftests/bpf/progs/map_ptr_kern.c +++ b/tools/testing/selftests/bpf/progs/map_ptr_kern.c @@ -114,7 +114,7 @@ static inline int check_hash(void) VERIFY(check_default_noinline(&hash->map, map)); =20 VERIFY(hash->n_buckets =3D=3D MAX_ENTRIES); - VERIFY(hash->elem_size =3D=3D 40); + VERIFY(hash->elem_size =3D=3D 32); =20 VERIFY(hash->count.counter =3D=3D 0); VERIFY(bpf_map_sum_elem_count(map) =3D=3D 0); --=20 2.55.0.1082.g2b9226bbc0-goog