Merge branch 'fixes-for-tailcall-with-subprog-and-callback'

Pu Lehui says:

====================
Fixes for tailcall with subprog and callback

From: Pu Lehui <pulehui@huawei.com>

This series fix two issues related to tailcall:

patch 1: Fix tail_call_reachable state leak across call branches.
patch 2: Reject callback subprogs invoke tailcall.
patch 3: testcases for patch 1 and 2.

v3:
- Fix tail_call_reachable state leak across call branches. (Sashiko)
- Add testcase for the above issue.

v2:
https://lore.kernel.org/bpf/20260714024459.420075-1-pulehui@huaweicloud.com
- Remove redantant testcase.
- Add ACK tag by Eduard.

v1:
https://lore.kernel.org/bpf/20260711104727.4023420-1-pulehui@huaweicloud.com
====================

Link: https://patch.msgid.link/20260716120157.835937-1-pulehui@huaweicloud.com
Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
This commit is contained in:
Eduard Zingerman 2026-07-16 17:46:26 -07:00
commit ba6cb45969
3 changed files with 92 additions and 8 deletions

View File

@ -5237,10 +5237,6 @@ static int check_max_stack_depth_subprog(struct bpf_verifier_env *env, int idx,
if (verifier_bug_if(sidx < 0, env, "callee not found at insn %d", next_insn))
return -EFAULT;
if (subprog[sidx].is_async_cb) {
if (subprog[sidx].has_tail_call) {
verifier_bug(env, "subprog has tail_call and async cb");
return -EFAULT;
}
/* async callbacks don't increase bpf prog stack size unless called directly */
if (!bpf_pseudo_call(insn + i))
continue;
@ -5263,8 +5259,8 @@ static int check_max_stack_depth_subprog(struct bpf_verifier_env *env, int idx,
if (!priv_stack_supported)
subprog[idx].priv_stack_mode = NO_PRIV_STACK;
if (subprog[idx].has_tail_call)
tail_call_reachable = true;
/* sync tail_call_reachable with callee state on entry */
tail_call_reachable = subprog[idx].has_tail_call;
frame = bpf_subprog_is_global(env, idx) ? 0 : frame + 1;
if (frame >= MAX_CALL_FRAMES) {
@ -5281,8 +5277,8 @@ static int check_max_stack_depth_subprog(struct bpf_verifier_env *env, int idx,
*/
if (tail_call_reachable) {
for (tmp = idx; tmp >= 0; tmp = dinfo[tmp].caller) {
if (subprog[tmp].is_exception_cb) {
verbose(env, "cannot tail call within exception cb\n");
if (subprog[tmp].is_cb) {
verbose(env, "cannot tail call within callback\n");
return -EINVAL;
}
if (subprog[tmp].stack_arg_cnt) {

View File

@ -12,6 +12,7 @@
#include "tailcall_cgrp_storage_no_storage.skel.h"
#include "tailcall_cgrp_storage.skel.h"
#include "tailcall_sleepable.skel.h"
#include "tailcall_callback.skel.h"
/* test_tailcall_1 checks basic functionality by patching multiple locations
* in a single program for a single tail call slot with nop->jmp, jmp->nop
@ -1901,6 +1902,11 @@ static void test_tailcall_sleepable(void)
tailcall_sleepable__destroy(skel);
}
static void test_tailcall_callback(void)
{
RUN_TESTS(tailcall_callback);
}
void test_tailcalls(void)
{
if (test__start_subtest("tailcall_1"))
@ -1967,4 +1973,5 @@ void test_tailcalls(void)
test_tailcall_cgrp_storage_no_storage_leaf();
if (test__start_subtest("tailcall_cgrp_storage_no_storage_bridge"))
test_tailcall_cgrp_storage_no_storage_bridge();
test_tailcall_callback();
}

View File

@ -0,0 +1,81 @@
// SPDX-License-Identifier: GPL-2.0
#include <linux/bpf.h>
#include <bpf/bpf_helpers.h>
#include "bpf_misc.h"
#include "bpf_test_utils.h"
int classifier_0(struct __sk_buff *skb);
struct {
__uint(type, BPF_MAP_TYPE_PROG_ARRAY);
__uint(max_entries, 1);
__uint(key_size, sizeof(__u32));
__array(values, void (void));
} jmp_table SEC(".maps") = {
.values = {
[0] = (void *) &classifier_0,
},
};
__auxiliary
SEC("tc")
int classifier_0(struct __sk_buff *skb)
{
return 0;
}
static __noinline
int subprog_tail0(struct __sk_buff *skb)
{
int ret = 0;
bpf_tail_call_static(skb, &jmp_table, 0);
barrier_var(ret);
return ret;
}
static __noinline
int callback_loop(int index, void **cb_ctx)
{
int ret;
ret = subprog_tail0(*cb_ctx);
barrier_var(ret);
return ret ? 1 : 0;
}
static __noinline
int callback_empty(int index, void *data)
{
return 0;
}
/* callback involving subprog with tail call is rejected */
SEC("tc")
__failure __msg("cannot tail call within callback")
int tailcall_callback_1(struct __sk_buff *skb)
{
clobber_regs_stack();
bpf_loop(1, callback_loop, &skb, 0);
return 0;
}
/* subprogs with tailcall do not affect no-tailcall callback */
SEC("tc")
__success
__retval(0)
int tailcall_callback_2(struct __sk_buff *skb)
{
int ret;
clobber_regs_stack();
ret = subprog_tail0(skb);
__sink(ret);
bpf_loop(1, callback_empty, NULL, 0);
return 0;
}
char __license[] SEC("license") = "GPL";