Major changes:

- Redesign the verifier error reporting: failures now carry source and
  instruction annotations along with the causal event history that led
  to them, making program rejections far easier to debug and repair
  (Kumar Kartikeya Dwivedi)

- Add arena argument support to kfuncs and struct_ops through the new
  __arena and __arena__nullable suffixes (Tejun Heo, Puranjay Mohan,
  Kumar Kartikeya Dwivedi, Ihor Solodrai)

- Signed BPF program loader rework to accommodate both BPF and security
  community needs where the kernel runs the signature verification at
  BPF_PROG_LOAD time before the LSM admission hook (Daniel Borkmann)

- Add a set of ksock kfuncs which let BPF LSM and syscall programs
  create, connect and send on UDP sockets in order to emit telemetry
  data (Mahe Tardy)

- Unify helper and kfunc call argument verification and classify kfunc
  arguments purely from BTF into a generated bpf_func_proto which is
  computed once at add-call time (Amery Hung)

Other features and fixes:

- Enable EXECMEM_ROX_CACHE for BPF allocations on x86 (Mike Rapoport)

- Add bidirectional VLAN support to bpf_fib_lookup() through the new
  BPF_FIB_LOOKUP_VLAN and BPF_FIB_LOOKUP_VLAN_INPUT flags
  (Avinash Duduskar)

- Infer zext_dst from static register liveness analysis to fix 32-bit
  zero-extension semantics, and remove the artificial limitations on
  pointer types eligible for spilling (Eduard Zingerman)

- Inline the numeric open-coded iterator kfuncs so that bpf_for() loops
  no longer pay a kfunc call on every iteration (Puranjay Mohan)

- Add an arena-based bitmap data structure to libarena along with
  serial and parallel selftests (Emil Tsalapatis)

- Teach resolve_btfids to discover kfuncs from the kernel's BTF ID sets
  and to emit kfunc BTF decl tags, reducing the kernel build's
  dependency on pahole features (Ihor Solodrai)

- Add BPF_F_ADJ_ROOM_DECAP_* flags to bpf_skb_adjust_room() so that
  tunnel decapsulation can update the GSO and encapsulation state of
  the skb (Nick Hudson)

- Fix the ring buffer pending_pos walk and the available-data
  accounting on 32-bit position wrap (Israel Téllez García)

- Add memory usage accounting for arena maps and fix an mmap_lock
  deadlock on arena lock failure (Jiayuan Chen)

- Add tracing_multi link info support to the kernel UAPI and bpftool,
  and refactor the stack map code to run with preemption disabled
  (Jiri Olsa)

- Support BPF_F_EGRESS in bpf_redirect_peer() to emit the skb in the
  egress direction of the target's peer device (Jordan Rife)

- Add a KF_SPINLOCK_SAFE kfunc flag so that providers, in particular
  modules, can declare kfuncs safe to call under bpf_spin_lock instead
  of relying on the verifier's hard-coded allowlist (Kaitao Cheng)

- Introduce global percpu data for BPF programs with libbpf probing
  and bpftool skeleton support, and stop exposing uninitialized kernel
  heap memory when copying per-CPU map values (Leon Hwang)

- Add s390 JIT support for load-acquire and store-release instructions
  (Maxim Khmelevskii)

- Fix a CFI mismatch in the task work callback and an arm64 KASAN
  false positive after bpf_throw() (Mykyta Yatsenko)

- Reject writes through untrusted BTF pointers and bound the
  rdonly/rdwr_buf_size kfunc arguments (Nicholas Dudar)

- Invalidate RCU pointers only after the final spin unlock and account
  for preempt and IRQ disabled regions as overlapping RCU protection
  (Ning Ding)

- Support mixing bpf2bpf calls and tail calls on RV64, add signed
  operations and 32-bit atomics to the RV32 JIT, and add timed may_goto
  support (Pu Lehui, Kuan-Wei Chiu, Feng Jiang)

- Fix a use-after-free on mm_struct in bpf_find_vma() for foreign tasks
  and an mmap_lock leak in the irq_work path (Sanghyun Park)

- Populate mmap-able BPF array map memory lazily which makes mmap() O(1)
  instead of proportional to the map size (Song Liu)

- Introduce a jit_required flag and reject programs with inlined
  helpers when no JIT is available, where the interpreter would
  otherwise jump into an invalid address (Tiezhu Yang)

- Fix the x86 JIT per-CPU address resolution into an extended register
  where the REX prefix dropped the high destination register bit
  (Vineet Gupta)

- Reject MEM_ALLOC BTF accesses past object bounds, arena frees below
  the arena base, and mixed arena and ordinary atomic paths
  (Yiyang Chen)

- Fix the trampoline handling of 128-bit arguments and of return values
  larger than 8 bytes (Yonghong Song)

- Ensure that any fault prone load is rewritten with exception table
  handling, and fix the arena load-acquire and atomic fetch handling
  in the x86, arm64, riscv and s390 JITs (Daniel Borkmann)

- Many more fixes and cleanups across the verifier, arena, trampolines,
  sockmap, cgroup, ring buffer, x86/arm64/riscv/s390 JITs, libbpf,
  bpftool, resolve_btfids and selftests.

Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
selftests/bpf: Add tests for a store on a fault prone qdisc pointer

Cover the store which used to be left as a plain BPF_STX without an
exception table entry:

  1: R1=trusted_ptr_Qdisc()
  ; struct Qdisc *next = sch->next_sched;
  1: (79) r1 = *(u64 *)(r1 +216)        ; R1=ptr_Qdisc()
  ; next->limit = 1000;
  3: (63) *(u32 *)(r1 +20) = r2         ; R1=ptr_Qdisc() R2=1000

Assert that it is rejected now.

  # LDLIBS=-static PKG_CONFIG='pkg-config --static' ./vmtest.sh -- ./test_progs -t ns_bpf_qdisc
  [...]
  #257/1   ns_bpf_qdisc/fifo:OK
  #257/2   ns_bpf_qdisc/fq:OK
  #257/3   ns_bpf_qdisc/attach to mq:OK
  #257/4   ns_bpf_qdisc/attach to non root:OK
  #257/5   ns_bpf_qdisc/incompl_ops:OK
  #257/6   ns_bpf_qdisc/invalid_dynptr:OK
  #257/7   ns_bpf_qdisc/invalid_dynptr_cross_frame:OK
  #257/8   ns_bpf_qdisc/invalid_dynptr_slice:OK
  #257/9   ns_bpf_qdisc/untrusted_write:OK
  #257/10  ns_bpf_qdisc/dynptr_use_after_invalidate_clone:OK
  #257     ns_bpf_qdisc:OK
  Summary: 1/10 PASSED, 0 SKIPPED, 0/0 FAILED

Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/bpf/20260817141015.878071-3-daniel@iogearbox.net
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
2 files changed