On Tue, Aug 4, 2026 at 7:57 AM Leon Hwang <[email protected]> wrote: > > When CONFIG_FUNCTION_ERROR_INJECTION is disabled, a sleepable tracing prog > is allowed to attach to '__x64_'-alike prefix symbols. > > It is because the verifier does not verify whether the symbol is a kernel > function or a bpf prog. That said, a sleepable tracing prog is allowed to > attach to a bpf prog target whose name has '__x64_'-alike prefix. > > For example, a sleepable fentry prog attaches to a '__x64_sys_nop' XDP > prog, and copies buffer from a user pointer with bpf_copy_from_user() > helper. After attaching the XDP prog to lo interface, the kernel BUG > could be triggered by 'ping -c 1 -W 1 127.0.0.1': > > [ 3.460756] BUG: sleeping function called from invalid context at > kernel/bpf/trampoline.c:1324 > > Fix it by disallowing sleepable tracing prog always when its target btf > is not kernel's btf. > > Fixes: 16d9c5660692 ("bpf: Always allow sleepable programs on syscalls") > Acked-by: Viktor Malik <[email protected]> > Signed-off-by: Leon Hwang <[email protected]> > --- > kernel/bpf/verifier.c | 3 +++ > 1 file changed, 3 insertions(+) > > diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c > index b274004fccfd..7bb541e343b2 100644 > --- a/kernel/bpf/verifier.c > +++ b/kernel/bpf/verifier.c > @@ -19019,6 +19019,9 @@ static int btf_id_allow_sleepable(u32 btf_id, > unsigned long addr, const struct b > > switch (prog->type) { > case BPF_PROG_TYPE_TRACING: > + if (!btf_is_kernel(btf)) > + return -EINVAL; > +
see sashiko reply, just move it outside of switch and disallow sleepable for anything that is not kernel/module BTF, regardless of program type pw-bot: cr > t = btf_type_by_id(btf, btf_id); > if (!t) > return -EINVAL; > -- > 2.55.0 >

