linux/kernel/bpf
Leon Hwang 61aaa8782b
bpf: Fix WARNING in bpf_tracing_link_release
The trampoline could be corrupted by the blindly
'tr->flags = BPF_TRAMP_F_TAIL_CALL_CTX' in verifier.

1. A fexit attached to a tail_call_reachable prog. 'tr->flags' became
   'BPF_TRAMP_F_CALL_ORIG | BPF_TRAMP_F_TAIL_CALL_CTX'. And, the
   trampoline would poke the target prog's nop insn using jmp insn instead
   of call insn.
2. Another fexit loaded with the same tail_call_reachable prog target.
   'tr->flags' became 'BPF_TRAMP_F_TAIL_CALL_CTX'.
3. Close the first fexit link. Due to no BPF_TRAMP_F_CALL_ORIG in
   'tr->flags', the trampoline will fail to restore the prog's nop insn
   using call insn.

[    3.410719] WARNING: kernel/bpf/syscall.c:3551 at bpf_tracing_link_release+0x53/0x60, CPU#1: test_progs/98
...
[    3.428793]  bpf_link_free+0x58/0x130
[    3.429293]  bpf_link_release+0x23/0x30

Fix the warning by updating 'tr->flags' with '|=' and lock.

Fixes: 2b5dcb31a1 ("bpf, x64: Fix tailcall infinite loop")
Signed-off-by: Leon Hwang <leon.hwang@linux.dev>
Reviewed-by: Pu Lehui <pulehui@huawei.com>
Acked-by: Jiri Olsa <jolsa@kernel.org>
Link: https://lore.kernel.org/bpf/20260722151909.69142-2-leon.hwang@linux.dev
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
2026-07-24 22:34:44 +02:00
..
preload umd: Remove usermode driver framework 2025-07-26 21:03:04 +02:00
arena.c bpf: Reject arena frees below the arena base 2026-07-19 18:15:35 +02:00
arraymap.c bpf: Cancel special fields on map value recycle 2026-06-09 21:23:11 -07:00
backtrack.c bpf: Add precision marking and backtracking for stack argument slots 2026-05-13 09:27:30 -07:00
bloom_filter.c bpf: Lose const-ness of map in map_check_btf() 2026-02-27 15:39:00 -08:00
bpf_cgrp_storage.c bpf: Remove gfp_flags plumbing from bpf_local_storage_update() 2026-04-10 21:22:32 -07:00
bpf_inode_storage.c bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized 2026-06-30 16:31:56 +02:00
bpf_insn_array.c bpf: Lose const-ness of map in map_check_btf() 2026-02-27 15:39:00 -08:00
bpf_iter.c Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
bpf_local_storage.c bpf: Remove gfp_flags plumbing from bpf_local_storage_update() 2026-04-10 21:22:32 -07:00
bpf_lru_list.c bpf: Fix NMI/tracepoint re-entry deadlock on lru locks 2026-06-07 18:46:13 -07:00
bpf_lru_list.h bpf: Fix NMI/tracepoint re-entry deadlock on lru locks 2026-06-07 18:46:13 -07:00
bpf_lsm_proto.c bpf: annotate file argument as __nullable in bpf_lsm_mmap_file 2025-12-21 10:56:33 -08:00
bpf_lsm.c bpf,lsm: Drop bpf_prog_free from sleepable_lsm_hooks 2026-07-01 13:10:20 -07:00
bpf_struct_ops.c bpf: Add struct bpf_tramp_node object 2026-06-07 10:03:01 -07:00
bpf_task_storage.c bpf: Remove gfp_flags plumbing from bpf_local_storage_update() 2026-04-10 21:22:32 -07:00
btf_iter.c bpf: Remove custom build rule 2024-08-30 08:55:26 -07:00
btf_relocate.c bpf: Remove custom build rule 2024-08-30 08:55:26 -07:00
btf.c bpf: Mark bpf_refcount field as unique 2026-07-21 16:32:37 -07:00
cfg.c bpf: Unify helper and kfunc call argument meta 2026-07-15 11:00:48 +02:00
cgroup_iter.c bpf: add new BPF_CGROUP_ITER_CHILDREN control option 2026-01-27 09:05:54 -08:00
cgroup.c bpf: Fix effective prog array index with BPF_F_PREORDER 2026-06-21 18:10:04 -07:00
check_btf.c bpf: Move BTF checking logic into check_btf.c 2026-04-12 12:37:04 -07:00
cnum_defs.h bpf: Export cnum_umin/umax() helpers for netronome driver 2026-04-27 10:09:48 -07:00
cnum.c bpf: representation and basic operations on circular numbers 2026-04-24 18:14:17 -07:00
const_fold.c bpf: Extend liveness analysis to track stack argument slots 2026-05-13 09:27:31 -07:00
core.c bpf, x86: Make sure allocation in arch_bpf_trampoline_size() is writable 2026-07-22 17:27:10 +02:00
cpumap.c bpf: Add missing XDP_ABORTED handling in cpumap 2026-03-03 08:37:21 -08:00
cpumask.c bpf: Require a BPF cpumask for bpf_cpumask_populate() 2026-07-12 01:52:36 +02:00
crypto.c Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
devmap.c bpf: Run generic devmap egress prog on private skb 2026-06-12 18:21:01 -07:00
disasm.c bpf: Mask pseudo pointer values in verifier logs 2026-06-25 17:59:04 -07:00
disasm.h
dispatcher.c bpf: dispatcher: Allocate bpf_dispatcher->rw_image with vzalloc() 2026-07-22 17:26:39 +02:00
dmabuf_iter.c bpf: Fix truncated dmabuf iterator reads 2025-12-09 23:48:34 -08:00
fixups.c bpf: Disallow interpreter fallback for BPF_ADDR_PERCPU insn 2026-07-19 18:26:40 +02:00
hashtab.c bpf: Cancel special fields on map value recycle 2026-06-09 21:23:11 -07:00
helpers.c bpf: Fix CFI mismatch in task work callback 2026-07-24 22:23:17 +02:00
inode.c bpf-next-7.2 2026-06-17 09:18:14 +01:00
Kconfig bpf: Update the bpf_prog_calc_tag to use SHA256 2025-09-18 19:10:20 -07:00
kmem_cache_iter.c bpf: Add open coded version of kmem_cache iterator 2024-11-01 11:08:32 -07:00
link_iter.c bpf: Clean up individual BTF_ID code 2025-07-16 18:34:42 -07:00
liveness.c bpf: Fix arg_track_join log to use sa prefix for stack arg slots 2026-05-16 17:46:16 -07:00
local_storage.c bpf: fix end-of-list detection in cgroup_storage_get_next_key() 2026-04-05 18:45:05 -07:00
log.c bpf: Refactor object relationship tracking and fix dynptr UAF bug 2026-06-01 18:31:41 -07:00
lpm_trie.c bpf: Allow LPM map access from sleepable BPF programs 2026-06-09 12:42:22 -07:00
Makefile bpf: representation and basic operations on circular numbers 2026-04-24 18:14:17 -07:00
map_in_map.c bpf: Reject exclusive maps as inner maps in map-in-map 2026-06-01 18:36:40 -07:00
map_in_map.h bpf: Add map and need_defer parameters to .map_fd_put_ptr() 2023-12-04 17:50:26 -08:00
map_iter.c bpf: Implement iteration ops for resizable hashtab 2026-06-05 08:00:08 -07:00
memalloc.c bpf: Retire rcu_trace_implies_rcu_gp() 2026-04-07 12:24:49 -07:00
mmap_unlock_work.h
mprog.c
net_namespace.c treewide: Replace kmalloc with kmalloc_obj for non-scalar types 2026-02-21 01:02:28 -08:00
offload.c bpf: Fix use-after-free in offloaded map/prog info fill 2026-04-09 13:24:32 -07:00
percpu_freelist.c bpf: Convert percpu_freelist.c to rqspinlock 2025-03-19 08:03:05 -07:00
percpu_freelist.h bpf: Convert percpu_freelist.c to rqspinlock 2025-03-19 08:03:05 -07:00
prog_iter.c bpf: Clean up individual BTF_ID code 2025-07-16 18:34:42 -07:00
queue_stack_maps.c bpf: Zero queue and stack outputs on lock failure 2026-07-21 18:55:48 +02:00
range_tree.c bpf: arena: Reintroduce memcg accounting 2026-01-02 14:31:59 -08:00
range_tree.h bpf: Introduce range_tree data structure and use it in bpf arena 2024-11-13 13:52:45 -08:00
relo_core.c bpf: Remove custom build rule 2024-08-30 08:55:26 -07:00
reuseport_array.c bpf: Use sockfd_put() helper 2024-08-30 08:57:47 -07:00
ringbuf.c bpf: Add SPDX license identifiers to a few files 2026-01-16 14:50:00 -08:00
rqspinlock.c mm.git review status for linus..mm-nonmm-stable 2026-02-12 12:13:01 -08:00
rqspinlock.h rqspinlock: Protect waiters in queue from stalls 2025-03-19 08:03:05 -07:00
stackmap.c bpf: Fix build_id caching in stack_map_get_build_id_offset() 2026-06-21 17:58:14 -07:00
states.c bpf: Preserve pointer spill metadata during half-slot cleanup 2026-06-22 13:39:34 -07:00
stream.c bpf: Add bpf_stream_print_stack stack dumping kfunc 2026-02-03 10:41:16 -08:00
syscall.c bpf: Fix security_bpf_map_create error handling 2026-07-09 10:16:34 +02:00
sysfs_btf.c Driver core changes for 6.17-rc1 2025-07-29 12:15:39 -07:00
task_iter.c bpf: Fix use-after-free on mm_struct in bpf_find_vma() 2026-07-09 07:59:41 +02:00
tcx.c treewide: Replace kmalloc with kmalloc_obj for non-scalar types 2026-02-21 01:02:28 -08:00
tnum.c bpf: Simplify tnum_step() 2026-03-24 08:45:29 -07:00
token.c treewide: Replace kmalloc with kmalloc_obj for non-scalar types 2026-02-21 01:02:28 -08:00
trampoline.c bpf: Fix WARNING in bpf_tracing_link_release 2026-07-24 22:34:44 +02:00
verifier.c bpf: Fix WARNING in bpf_tracing_link_release 2026-07-24 22:34:44 +02:00