[PATCH bpf-next] bpf: sched_ext: Mark ops argument container pointer fields as trusted

Tejun Heo posted 1 patch 1 month, 1 week ago
kernel/bpf/verifier.c |   26 ++++++++++++++++++++++++++
1 file changed, 26 insertions(+)
[PATCH bpf-next] bpf: sched_ext: Mark ops argument container pointer fields as trusted
Posted by Tejun Heo 1 month, 1 week ago
Walking an unannotated pointer field of a trusted struct yields a bare
PTR_TO_BTF_ID in non-sleepable programs, which kfuncs and helpers accept,
but PTR_UNTRUSTED in sleepable programs, which they reject. This gets in the
way of making ops.init_task() sleepable, which schedulers want for
allocations. For example, passing args->cgroup into bpf_cgrp_storage_get()
then fails verification and the only recourse is round-tripping through the
cgroup ID with bpf_cgroup_from_id().

The pointer fields in the sched_ext ops argument containers are all pinned
by the callers for the duration of the ops calls and are never NULL. Add
them to the verifier's trusted-fields whitelist so that they are PTR_TRUSTED
in both sleepable and non-sleepable programs.

Signed-off-by: Tejun Heo <tj@kernel.org>
---
 kernel/bpf/verifier.c |   26 ++++++++++++++++++++++++++
 1 file changed, 26 insertions(+)

--- a/kernel/bpf/verifier.c
+++ b/kernel/bpf/verifier.c
@@ -5661,6 +5661,28 @@ BTF_TYPE_SAFE_TRUSTED(struct file) {
 	struct inode *f_inode;
 };
 
+/*
+ * The pointer fields in the sched_ext ops argument containers are pinned by the
+ * callers for the duration of the ops calls and are never NULL.
+ */
+BTF_TYPE_SAFE_TRUSTED(struct scx_init_task_args) {
+#ifdef CONFIG_EXT_GROUP_SCHED
+	struct cgroup *cgroup;
+#endif
+};
+
+BTF_TYPE_SAFE_TRUSTED(struct scx_cpu_release_args) {
+	struct task_struct *task;
+};
+
+BTF_TYPE_SAFE_TRUSTED(struct scx_sub_attach_args) {
+	struct sched_ext_ops *ops;
+};
+
+BTF_TYPE_SAFE_TRUSTED(struct scx_sub_detach_args) {
+	struct sched_ext_ops *ops;
+};
+
 BTF_TYPE_SAFE_TRUSTED_OR_NULL(struct dentry) {
 	struct inode *d_inode;
 };
@@ -5705,6 +5727,10 @@ static bool type_is_trusted(struct bpf_v
 	BTF_TYPE_EMIT(BTF_TYPE_SAFE_TRUSTED(struct bpf_iter__task));
 	BTF_TYPE_EMIT(BTF_TYPE_SAFE_TRUSTED(struct linux_binprm));
 	BTF_TYPE_EMIT(BTF_TYPE_SAFE_TRUSTED(struct file));
+	BTF_TYPE_EMIT(BTF_TYPE_SAFE_TRUSTED(struct scx_init_task_args));
+	BTF_TYPE_EMIT(BTF_TYPE_SAFE_TRUSTED(struct scx_cpu_release_args));
+	BTF_TYPE_EMIT(BTF_TYPE_SAFE_TRUSTED(struct scx_sub_attach_args));
+	BTF_TYPE_EMIT(BTF_TYPE_SAFE_TRUSTED(struct scx_sub_detach_args));
 
 	return btf_nested_type_is_trusted(&env->log, reg, field_name, btf_id, "__safe_trusted");
 }
Re: [PATCH bpf-next] bpf: sched_ext: Mark ops argument container pointer fields as trusted
Posted by Kumar Kartikeya Dwivedi 1 month, 1 week ago
On Thu Aug 20, 2026 at 7:20 AM CEST, Tejun Heo wrote:
> Walking an unannotated pointer field of a trusted struct yields a bare
> PTR_TO_BTF_ID in non-sleepable programs, which kfuncs and helpers accept,
> but PTR_UNTRUSTED in sleepable programs, which they reject. This gets in the
> way of making ops.init_task() sleepable, which schedulers want for
> allocations. For example, passing args->cgroup into bpf_cgrp_storage_get()
> then fails verification and the only recourse is round-tripping through the
> cgroup ID with bpf_cgroup_from_id().
>
> The pointer fields in the sched_ext ops argument containers are all pinned
> by the callers for the duration of the ops calls and are never NULL. Add
> them to the verifier's trusted-fields whitelist so that they are PTR_TRUSTED
> in both sleepable and non-sleepable programs.
>
> Signed-off-by: Tejun Heo <tj@kernel.org>
> ---

Acked-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>

I (or others) will add Fixes tag when applying, no need to respin.

> [...]
Re: [PATCH bpf-next] bpf: sched_ext: Mark ops argument container pointer fields as trusted
Posted by bot+bpf-ci@kernel.org 1 month, 1 week ago
>     bpf: sched_ext: Mark ops argument container pointer fields as trusted
>
>     Walking an unannotated pointer field of a trusted struct yields a bare
>     PTR_TO_BTF_ID in non-sleepable programs, which kfuncs and helpers accept,
>     but PTR_UNTRUSTED in sleepable programs, which they reject. This gets in the
>     way of making ops.init_task() sleepable, which schedulers want for
>     allocations. For example, passing args->cgroup into bpf_cgrp_storage_get()
>     then fails verification and the only recourse is round-tripping through the
>     cgroup ID with bpf_cgroup_from_id().
>
>     The pointer fields in the sched_ext ops argument containers are all pinned
>     by the callers for the duration of the ops calls and are never NULL. Add
>     them to the verifier's trusted-fields whitelist so that they are PTR_TRUSTED
>     in both sleepable and non-sleepable programs.
>
>     Signed-off-by: Tejun Heo <tj@kernel.org>

This looks like a bug fix for verification failures in sleepable programs.
Should this include:

  Fixes: 8195136669661 ("sched_ext: Add cgroup support")


---
AI reviewed your patch. Please fix the bug or email reply why it's not a bug.
See: https://github.com/kernel-patches/vmtest/blob/master/ci/claude/README.md

CI run summary: https://github.com/kernel-patches/bpf/actions/runs/32336047878
Re: [PATCH bpf-next] bpf: sched_ext: Mark ops argument container pointer fields as trusted
Posted by Tejun Heo 1 month, 1 week ago
On Thu, Aug 20, 2026 at 06:16:48AM +0000, bot+bpf-ci@kernel.org wrote:
> >     bpf: sched_ext: Mark ops argument container pointer fields as trusted
> >
> >     Walking an unannotated pointer field of a trusted struct yields a bare
> >     PTR_TO_BTF_ID in non-sleepable programs, which kfuncs and helpers accept,
> >     but PTR_UNTRUSTED in sleepable programs, which they reject. This gets in the
> >     way of making ops.init_task() sleepable, which schedulers want for
> >     allocations. For example, passing args->cgroup into bpf_cgrp_storage_get()
> >     then fails verification and the only recourse is round-tripping through the
> >     cgroup ID with bpf_cgroup_from_id().
> >
> >     The pointer fields in the sched_ext ops argument containers are all pinned
> >     by the callers for the duration of the ops calls and are never NULL. Add
> >     them to the verifier's trusted-fields whitelist so that they are PTR_TRUSTED
> >     in both sleepable and non-sleepable programs.
> >
> >     Signed-off-by: Tejun Heo <tj@kernel.org>
> 
> This looks like a bug fix for verification failures in sleepable programs.
> Should this include:
> 
>   Fixes: 8195136669661 ("sched_ext: Add cgroup support")

Nothing has been using it, so not strictly necessary but yeah I don't see
why not.

Thanks.

-- 
tejun