From patchwork Tue Apr 11 04:16:31 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: David Vernet X-Patchwork-Id: 81718 Return-Path: Delivered-To: ouuuleilei@gmail.com Received: by 2002:a59:b0ea:0:b0:3b6:4342:cba0 with SMTP id b10csp2327643vqo; Mon, 10 Apr 2023 21:41:09 -0700 (PDT) X-Google-Smtp-Source: AKy350Z6mGi+7P+hKn+o11BvIoKw13Mc0Qc7P+uAQUCbA3I2ZppAsyEhzRbPiuh9PnmSE2Jo7PdF X-Received: by 2002:aa7:9d0c:0:b0:63a:ea04:634a with SMTP id k12-20020aa79d0c000000b0063aea04634amr2125579pfp.21.1681188068988; Mon, 10 Apr 2023 21:41:08 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1681188068; cv=none; d=google.com; s=arc-20160816; b=CTd9rx3RVwWOyMNB79Rb2Mieb2BsrhpiW7kl9p/Tr4ZjnWf/vneHdopZYBIexv+onl nbfYfPKG/t4kr7hZRJh+ntOiaSPzDvU64FXwaQFBzF20ekYZ5+DUM4yOJ76D/AgF6UVx yI0aHP/JFKS6WokUEeUA/CsItpRc5itT+aGWQupwewpTwSVtwbNlhbbvI+iB43RruDlX CwqCBiJC/GnfEKtcfsZR1Gsd51Tdv2X2ja0As1Mi26xKQY3tvfAppwEWvSf6nV9b4895 PJhomInzrH/xevBs163oi4ZgfOsCsDaWYCosHOUMtLMBBidIYptQnZOapLrChVP0ViIk 7wbA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :message-id:date:subject:cc:to:from; bh=+/NRCUh21EwSCHQTGMkg0JbDBsWfdCVqSK+6Bs3uOLY=; b=UDOSgfHlmTL1DC0hbMOYmfS9VaWy6yF2Y6tZpcrhRh7vJpwfDs3xz8U/AvuK0REHZE 3O4wFXO6UefWSB83hHHh1KyYDFg5Pf9ZjHoOKMxeV9JMM/8gm4ZBP965dDP/eQIaWtGy StylvVPkpode0vJNeSKCZqSrL7jYNMJ+K1XSFpXGsJmfH5ZBiyi+C6uheWkY/Ozy5nRW LB/7ItRfJG5CGWwQGvBNUlfHheliwl1fx6faImO1xA6LEPePzn0Sbn9pCy3vboFAn8Wn Uykxg/Nnlwh8ecVS0IC/74HzomjcziGsDXw+HRvtE1+ZQQwmHruZNY3K0HwJ7lNPuyZ/ Na5w== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id y26-20020aa793da000000b006373ec6207bsi4917022pff.98.2023.04.10.21.40.55; Mon, 10 Apr 2023 21:41:08 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S229879AbjDKEQl (ORCPT + 99 others); Tue, 11 Apr 2023 00:16:41 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:35872 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229640AbjDKEQj (ORCPT ); Tue, 11 Apr 2023 00:16:39 -0400 Received: from mail-qv1-f51.google.com (mail-qv1-f51.google.com [209.85.219.51]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id B2A8FE74; Mon, 10 Apr 2023 21:16:37 -0700 (PDT) Received: by mail-qv1-f51.google.com with SMTP id om8so5591789qvb.3; Mon, 10 Apr 2023 21:16:37 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; t=1681186596; x=1683778596; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=+/NRCUh21EwSCHQTGMkg0JbDBsWfdCVqSK+6Bs3uOLY=; b=C27iSmbNBoZDtfI5DW380E6Veo8NgFB+WxJ9hGYdraHeApKdy6KImA3DHTmdlDFqq3 b4mHr4Okki5JqMoN5tqok4zD0asyKlg4vwH2XHN+nS+UNoQAAzEfZIxSn64Pqqw2gqNQ Rn3hIrnlXjIGFSHh8hZjtd83qJaz9kX4oZP7igLx3VHqvLI4FPeRNrxL+itJYYpwUMm+ mC5R99VhvWg/y2ByE/YIYU65Rdw9jTP7PsMaFxFh0EpjxoOhhAtptz4A3z+iu0E9DV7q zY1Z5hdFMJq74LxQ/zJEd2F8gIZUInlD17Q4/zdUTN/EKOIpQizDeuUaGSngy83PCMdh teNw== X-Gm-Message-State: AAQBX9fDyt27sT5ZcOJN027qK+aDJUxvunvvWGFfrY9M5/cwF6uRGhEz o6AmAHWHmKByU7lp+I0MRgtz/dD9CMUIroAF X-Received: by 2002:a05:6214:ac6:b0:577:5ffe:e0ce with SMTP id g6-20020a0562140ac600b005775ffee0cemr26837599qvi.25.1681186596414; Mon, 10 Apr 2023 21:16:36 -0700 (PDT) Received: from localhost ([2620:10d:c091:400::5:8681]) by smtp.gmail.com with ESMTPSA id u6-20020a0cfe46000000b005e2007584f1sm3855319qvs.24.2023.04.10.21.16.35 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 10 Apr 2023 21:16:35 -0700 (PDT) From: David Vernet To: bpf@vger.kernel.org Cc: ast@kernel.org, daniel@iogearbox.net, andrii@kernel.org, martin.lau@linux.dev, song@kernel.org, yhs@fb.com, john.fastabend@gmail.com, kpsingh@kernel.org, sdf@google.com, haoluo@google.com, jolsa@kernel.org, linux-kernel@vger.kernel.org, kernel-team@meta.com Subject: [PATCH bpf-next 1/3] bpf: Make bpf_cgroup_acquire() KF_RCU | KF_RET_NULL Date: Mon, 10 Apr 2023 23:16:31 -0500 Message-Id: <20230411041633.179404-1-void@manifault.com> X-Mailer: git-send-email 2.40.0 MIME-Version: 1.0 X-Spam-Status: No, score=0.5 required=5.0 tests=FREEMAIL_FORGED_FROMDOMAIN, FREEMAIL_FROM,HEADER_FROM_DIFFERENT_DOMAINS,RCVD_IN_DNSWL_NONE, RCVD_IN_MSPIKE_H2,SPF_HELO_NONE,SPF_PASS autolearn=no autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?= X-GMAIL-THRID: =?utf-8?q?1762853460542311249?= X-GMAIL-MSGID: =?utf-8?q?1762853460542311249?= struct cgroup is already an RCU-safe type in the verifier. We can therefore update bpf_cgroup_acquire() to be KF_RCU | KF_RET_NULL, and subsequently remove bpf_cgroup_kptr_get(). This patch does the first of these by updating bpf_cgroup_acquire() to be KF_RCU | KF_RET_NULL, and also updates selftests accordingly. Signed-off-by: David Vernet --- kernel/bpf/helpers.c | 5 ++- .../selftests/bpf/progs/cgrp_kfunc_common.h | 5 +++ .../selftests/bpf/progs/cgrp_kfunc_failure.c | 35 +++++++++++++++---- .../selftests/bpf/progs/cgrp_kfunc_success.c | 5 ++- 4 files changed, 40 insertions(+), 10 deletions(-) diff --git a/kernel/bpf/helpers.c b/kernel/bpf/helpers.c index b6a5cda5bb59..71f0604bdc97 100644 --- a/kernel/bpf/helpers.c +++ b/kernel/bpf/helpers.c @@ -2037,8 +2037,7 @@ __bpf_kfunc void bpf_task_release(struct task_struct *p) */ __bpf_kfunc struct cgroup *bpf_cgroup_acquire(struct cgroup *cgrp) { - cgroup_get(cgrp); - return cgrp; + return cgroup_tryget(cgrp) ? cgrp : NULL; } /** @@ -2314,7 +2313,7 @@ BTF_ID_FLAGS(func, bpf_rbtree_add) BTF_ID_FLAGS(func, bpf_rbtree_first, KF_RET_NULL) #ifdef CONFIG_CGROUPS -BTF_ID_FLAGS(func, bpf_cgroup_acquire, KF_ACQUIRE | KF_TRUSTED_ARGS) +BTF_ID_FLAGS(func, bpf_cgroup_acquire, KF_ACQUIRE | KF_RCU | KF_RET_NULL) BTF_ID_FLAGS(func, bpf_cgroup_kptr_get, KF_ACQUIRE | KF_KPTR_GET | KF_RET_NULL) BTF_ID_FLAGS(func, bpf_cgroup_release, KF_RELEASE) BTF_ID_FLAGS(func, bpf_cgroup_ancestor, KF_ACQUIRE | KF_RCU | KF_RET_NULL) diff --git a/tools/testing/selftests/bpf/progs/cgrp_kfunc_common.h b/tools/testing/selftests/bpf/progs/cgrp_kfunc_common.h index d0b7cd0d09d7..b0e279f4652b 100644 --- a/tools/testing/selftests/bpf/progs/cgrp_kfunc_common.h +++ b/tools/testing/selftests/bpf/progs/cgrp_kfunc_common.h @@ -61,6 +61,11 @@ static inline int cgrps_kfunc_map_insert(struct cgroup *cgrp) } acquired = bpf_cgroup_acquire(cgrp); + if (!acquired) { + bpf_map_delete_elem(&__cgrps_kfunc_map, &id); + return -ENOENT; + } + old = bpf_kptr_xchg(&v->cgrp, acquired); if (old) { bpf_cgroup_release(old); diff --git a/tools/testing/selftests/bpf/progs/cgrp_kfunc_failure.c b/tools/testing/selftests/bpf/progs/cgrp_kfunc_failure.c index 48b2034cadb3..49347f12de39 100644 --- a/tools/testing/selftests/bpf/progs/cgrp_kfunc_failure.c +++ b/tools/testing/selftests/bpf/progs/cgrp_kfunc_failure.c @@ -41,6 +41,23 @@ int BPF_PROG(cgrp_kfunc_acquire_untrusted, struct cgroup *cgrp, const char *path /* Can't invoke bpf_cgroup_acquire() on an untrusted pointer. */ acquired = bpf_cgroup_acquire(v->cgrp); + if (acquired) + bpf_cgroup_release(acquired); + + return 0; +} + +SEC("tp_btf/cgroup_mkdir") +__failure __msg("Possibly NULL pointer passed to trusted arg0") +int BPF_PROG(cgrp_kfunc_acquire_no_null_check, struct cgroup *cgrp, const char *path) +{ + struct cgroup *acquired; + + acquired = bpf_cgroup_acquire(cgrp); + /* + * Can't invoke bpf_cgroup_release() without checking the return value + * of bpf_cgroup_acquire(). + */ bpf_cgroup_release(acquired); return 0; @@ -54,7 +71,8 @@ int BPF_PROG(cgrp_kfunc_acquire_fp, struct cgroup *cgrp, const char *path) /* Can't invoke bpf_cgroup_acquire() on a random frame pointer. */ acquired = bpf_cgroup_acquire((struct cgroup *)&stack_cgrp); - bpf_cgroup_release(acquired); + if (acquired) + bpf_cgroup_release(acquired); return 0; } @@ -67,7 +85,8 @@ int BPF_PROG(cgrp_kfunc_acquire_unsafe_kretprobe, struct cgroup *cgrp) /* Can't acquire an untrusted struct cgroup * pointer. */ acquired = bpf_cgroup_acquire(cgrp); - bpf_cgroup_release(acquired); + if (acquired) + bpf_cgroup_release(acquired); return 0; } @@ -80,7 +99,8 @@ int BPF_PROG(cgrp_kfunc_acquire_trusted_walked, struct cgroup *cgrp, const char /* Can't invoke bpf_cgroup_acquire() on a pointer obtained from walking a trusted cgroup. */ acquired = bpf_cgroup_acquire(cgrp->old_dom_cgrp); - bpf_cgroup_release(acquired); + if (acquired) + bpf_cgroup_release(acquired); return 0; } @@ -93,9 +113,8 @@ int BPF_PROG(cgrp_kfunc_acquire_null, struct cgroup *cgrp, const char *path) /* Can't invoke bpf_cgroup_acquire() on a NULL pointer. */ acquired = bpf_cgroup_acquire(NULL); - if (!acquired) - return 0; - bpf_cgroup_release(acquired); + if (acquired) + bpf_cgroup_release(acquired); return 0; } @@ -137,6 +156,8 @@ int BPF_PROG(cgrp_kfunc_get_non_kptr_acquired, struct cgroup *cgrp, const char * struct cgroup *kptr, *acquired; acquired = bpf_cgroup_acquire(cgrp); + if (!acquired) + return 0; /* Cannot use bpf_cgroup_kptr_get() on a non-map-value, even if the kptr was acquired. */ kptr = bpf_cgroup_kptr_get(&acquired); @@ -256,6 +277,8 @@ int BPF_PROG(cgrp_kfunc_release_null, struct cgroup *cgrp, const char *path) return -ENOENT; acquired = bpf_cgroup_acquire(cgrp); + if (!acquired) + return -ENOENT; old = bpf_kptr_xchg(&v->cgrp, acquired); diff --git a/tools/testing/selftests/bpf/progs/cgrp_kfunc_success.c b/tools/testing/selftests/bpf/progs/cgrp_kfunc_success.c index 030aff700084..e9dbd1af05a7 100644 --- a/tools/testing/selftests/bpf/progs/cgrp_kfunc_success.c +++ b/tools/testing/selftests/bpf/progs/cgrp_kfunc_success.c @@ -38,7 +38,10 @@ int BPF_PROG(test_cgrp_acquire_release_argument, struct cgroup *cgrp, const char return 0; acquired = bpf_cgroup_acquire(cgrp); - bpf_cgroup_release(acquired); + if (!acquired) + err = 1; + else + bpf_cgroup_release(acquired); return 0; } From patchwork Tue Apr 11 04:16:32 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: David Vernet X-Patchwork-Id: 81710 Return-Path: Delivered-To: ouuuleilei@gmail.com Received: by 2002:a59:b0ea:0:b0:3b6:4342:cba0 with SMTP id b10csp2321272vqo; Mon, 10 Apr 2023 21:21:04 -0700 (PDT) X-Google-Smtp-Source: AKy350brVrcEBONoyiq6/LMoUeUzbzsCiae8IDt+qH96IqKhr9A0MaeED9yTUoDMVfzjV7VLSnLw X-Received: by 2002:a17:907:d08e:b0:94a:4ce3:803d with SMTP id vc14-20020a170907d08e00b0094a4ce3803dmr7857658ejc.15.1681186864679; Mon, 10 Apr 2023 21:21:04 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1681186864; cv=none; d=google.com; s=arc-20160816; b=z55uHZyPDo9Nv4K3vCcfexH9mWFw0jfGH7evuyHxfKNDE3mKL/OW3HCDE+saeX+l0a 2BCQ84Nnb87PgloewYONe1ljGA6Tt2bW2LIJ41tJliYm/6K7hI/+M/Y2MccuSR3+7EZ2 wdggu74CKt04M+xidkt8IqcGZ2y2oS5JOo0rXZ4jhUEGDhv6TgL0N1g0l7MsmUjY4adC +qx3EcrHuVlulgjz4ost49FXh5gFsaTq/DTv1KrisHls4xCD7EA25hdHhyI3waitSkRn Hi9+j3VbSK9HhfxcNRTvx1yCKyOMarbUhZjTnGIfvrPvXryNDe1N8elDTrizouHdpJqL 8MBw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from; bh=W/BJCuOQvpJU6klSzxJXEK3wu7oFUkKcR2d+BvN18us=; b=znWe4ViiVT1uip1BvYVzlUAtkibnU4/7tuCNQ8CQorxHGISvlZ711uXJBjjNNP6XDd Vn6P4XRfhdztF+7AVbAplEv/zQT1L2nsVyJRgectsbhvs+2yah9eMfF7MaFD+aAHg9sN oANs6D2f/WSf3VN1JFeFzEkA8gHy07VKDDaXLZ7Ncz33O+BEDvTjY0rd4uwJ3LbITyQU nGoUu5IqSoxSRNnFqgZZaqCO8rKcYJoVqs1aL8I9Zq94UDWCgKvJilGKb0JhzDoxwiGx zqJaQ23K9nAxKqjAuX3ar87EYcdRRLzHoejUcudWZEYLjVThVWSCQW23oks/wuaAGukV ginQ== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id c4-20020aa7d604000000b005024e71ba26si7132737edr.447.2023.04.10.21.20.37; Mon, 10 Apr 2023 21:21:04 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S230042AbjDKEQo (ORCPT + 99 others); Tue, 11 Apr 2023 00:16:44 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:35880 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229789AbjDKEQk (ORCPT ); Tue, 11 Apr 2023 00:16:40 -0400 Received: from mail-qt1-f173.google.com (mail-qt1-f173.google.com [209.85.160.173]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 6C2B52691; Mon, 10 Apr 2023 21:16:39 -0700 (PDT) Received: by mail-qt1-f173.google.com with SMTP id ay36so3905726qtb.11; Mon, 10 Apr 2023 21:16:39 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; t=1681186598; x=1683778598; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=W/BJCuOQvpJU6klSzxJXEK3wu7oFUkKcR2d+BvN18us=; b=tUL3GiLBAUoY1UvpXJNOBneSiknOSoQUlm377M/xUiuPgobE1TZL+LPGFewEDasXWt 83KaM6CnSfNC0wu7Fq4ukgJCVWfPAq1vwTsyeGZMybm1Wd34yLlv+M4ccL1RYmkopHrh mGHHxJJTbsUvLRvOkYU6nKiiJh78tHDG/xkvRfHAyLZVdgoPROwi2sTEK1bkWUQ3iOcp FdYZMHcKKHqENgugBVnLUYvt1yWR5PwA15JbWE2igvbUHxgFbJfiEfGc208apddU/Uxo vv95nweooKj/Y/gmRndvHLvNui5yu5xrCRtbUiGywFi4MCt/3PkyFECCQGMV7m02Pkzo aaqA== X-Gm-Message-State: AAQBX9fBNuB5upKhZR3VermQAzXeqWvdZvJNHfHZqYkbAay1DgSHrj7t YPfdhEWRQDpVZqWRckw+SsJGmAQDb58dIgVx X-Received: by 2002:ac8:5c8c:0:b0:3e3:c889:ed06 with SMTP id r12-20020ac85c8c000000b003e3c889ed06mr23346779qta.21.1681186598145; Mon, 10 Apr 2023 21:16:38 -0700 (PDT) Received: from localhost ([2620:10d:c091:400::5:8681]) by smtp.gmail.com with ESMTPSA id d14-20020a05620a240e00b0071d0f1d01easm3696701qkn.57.2023.04.10.21.16.37 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 10 Apr 2023 21:16:37 -0700 (PDT) From: David Vernet To: bpf@vger.kernel.org Cc: ast@kernel.org, daniel@iogearbox.net, andrii@kernel.org, martin.lau@linux.dev, song@kernel.org, yhs@fb.com, john.fastabend@gmail.com, kpsingh@kernel.org, sdf@google.com, haoluo@google.com, jolsa@kernel.org, linux-kernel@vger.kernel.org, kernel-team@meta.com Subject: [PATCH bpf-next 2/3] bpf: Remove bpf_cgroup_kptr_get() kfunc Date: Mon, 10 Apr 2023 23:16:32 -0500 Message-Id: <20230411041633.179404-2-void@manifault.com> X-Mailer: git-send-email 2.40.0 In-Reply-To: <20230411041633.179404-1-void@manifault.com> References: <20230411041633.179404-1-void@manifault.com> MIME-Version: 1.0 X-Spam-Status: No, score=0.5 required=5.0 tests=FREEMAIL_FORGED_FROMDOMAIN, FREEMAIL_FROM,HEADER_FROM_DIFFERENT_DOMAINS,RCVD_IN_DNSWL_NONE, RCVD_IN_MSPIKE_H3,RCVD_IN_MSPIKE_WL,SPF_HELO_NONE,SPF_PASS autolearn=no autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?= X-GMAIL-THRID: =?utf-8?q?1762852197871250422?= X-GMAIL-MSGID: =?utf-8?q?1762852197871250422?= Now that bpf_cgroup_acquire() is KF_RCU | KF_RET_NULL, bpf_cgroup_kptr_get() is redundant. Let's remove it, and update selftests to instead use bpf_cgroup_acquire() where appropriate. The next patch will update the BPF documentation to not mention bpf_cgroup_kptr_get(). Signed-off-by: David Vernet --- kernel/bpf/helpers.c | 32 --------- .../selftests/bpf/progs/cgrp_kfunc_common.h | 3 +- .../selftests/bpf/progs/cgrp_kfunc_failure.c | 68 +++---------------- .../selftests/bpf/progs/cgrp_kfunc_success.c | 10 ++- 4 files changed, 14 insertions(+), 99 deletions(-) diff --git a/kernel/bpf/helpers.c b/kernel/bpf/helpers.c index 71f0604bdc97..f04e60a4847f 100644 --- a/kernel/bpf/helpers.c +++ b/kernel/bpf/helpers.c @@ -2040,37 +2040,6 @@ __bpf_kfunc struct cgroup *bpf_cgroup_acquire(struct cgroup *cgrp) return cgroup_tryget(cgrp) ? cgrp : NULL; } -/** - * bpf_cgroup_kptr_get - Acquire a reference on a struct cgroup kptr. A cgroup - * kptr acquired by this kfunc which is not subsequently stored in a map, must - * be released by calling bpf_cgroup_release(). - * @cgrpp: A pointer to a cgroup kptr on which a reference is being acquired. - */ -__bpf_kfunc struct cgroup *bpf_cgroup_kptr_get(struct cgroup **cgrpp) -{ - struct cgroup *cgrp; - - rcu_read_lock(); - /* Another context could remove the cgroup from the map and release it - * at any time, including after we've done the lookup above. This is - * safe because we're in an RCU read region, so the cgroup is - * guaranteed to remain valid until at least the rcu_read_unlock() - * below. - */ - cgrp = READ_ONCE(*cgrpp); - - if (cgrp && !cgroup_tryget(cgrp)) - /* If the cgroup had been removed from the map and freed as - * described above, cgroup_tryget() will return false. The - * cgroup will be freed at some point after the current RCU gp - * has ended, so just return NULL to the user. - */ - cgrp = NULL; - rcu_read_unlock(); - - return cgrp; -} - /** * bpf_cgroup_release - Release the reference acquired on a cgroup. * If this kfunc is invoked in an RCU read region, the cgroup is guaranteed to @@ -2314,7 +2283,6 @@ BTF_ID_FLAGS(func, bpf_rbtree_first, KF_RET_NULL) #ifdef CONFIG_CGROUPS BTF_ID_FLAGS(func, bpf_cgroup_acquire, KF_ACQUIRE | KF_RCU | KF_RET_NULL) -BTF_ID_FLAGS(func, bpf_cgroup_kptr_get, KF_ACQUIRE | KF_KPTR_GET | KF_RET_NULL) BTF_ID_FLAGS(func, bpf_cgroup_release, KF_RELEASE) BTF_ID_FLAGS(func, bpf_cgroup_ancestor, KF_ACQUIRE | KF_RCU | KF_RET_NULL) BTF_ID_FLAGS(func, bpf_cgroup_from_id, KF_ACQUIRE | KF_RET_NULL) diff --git a/tools/testing/selftests/bpf/progs/cgrp_kfunc_common.h b/tools/testing/selftests/bpf/progs/cgrp_kfunc_common.h index b0e279f4652b..22914a70db54 100644 --- a/tools/testing/selftests/bpf/progs/cgrp_kfunc_common.h +++ b/tools/testing/selftests/bpf/progs/cgrp_kfunc_common.h @@ -21,10 +21,11 @@ struct hash_map { } __cgrps_kfunc_map SEC(".maps"); struct cgroup *bpf_cgroup_acquire(struct cgroup *p) __ksym; -struct cgroup *bpf_cgroup_kptr_get(struct cgroup **pp) __ksym; void bpf_cgroup_release(struct cgroup *p) __ksym; struct cgroup *bpf_cgroup_ancestor(struct cgroup *cgrp, int level) __ksym; struct cgroup *bpf_cgroup_from_id(u64 cgid) __ksym; +void bpf_rcu_read_lock(void) __ksym; +void bpf_rcu_read_unlock(void) __ksym; static inline struct __cgrps_kfunc_map_value *cgrps_kfunc_map_value_lookup(struct cgroup *cgrp) { diff --git a/tools/testing/selftests/bpf/progs/cgrp_kfunc_failure.c b/tools/testing/selftests/bpf/progs/cgrp_kfunc_failure.c index 49347f12de39..0fa564a5cc5b 100644 --- a/tools/testing/selftests/bpf/progs/cgrp_kfunc_failure.c +++ b/tools/testing/selftests/bpf/progs/cgrp_kfunc_failure.c @@ -133,59 +133,6 @@ int BPF_PROG(cgrp_kfunc_acquire_unreleased, struct cgroup *cgrp, const char *pat return 0; } -SEC("tp_btf/cgroup_mkdir") -__failure __msg("arg#0 expected pointer to map value") -int BPF_PROG(cgrp_kfunc_get_non_kptr_param, struct cgroup *cgrp, const char *path) -{ - struct cgroup *kptr; - - /* Cannot use bpf_cgroup_kptr_get() on a non-kptr, even on a valid cgroup. */ - kptr = bpf_cgroup_kptr_get(&cgrp); - if (!kptr) - return 0; - - bpf_cgroup_release(kptr); - - return 0; -} - -SEC("tp_btf/cgroup_mkdir") -__failure __msg("arg#0 expected pointer to map value") -int BPF_PROG(cgrp_kfunc_get_non_kptr_acquired, struct cgroup *cgrp, const char *path) -{ - struct cgroup *kptr, *acquired; - - acquired = bpf_cgroup_acquire(cgrp); - if (!acquired) - return 0; - - /* Cannot use bpf_cgroup_kptr_get() on a non-map-value, even if the kptr was acquired. */ - kptr = bpf_cgroup_kptr_get(&acquired); - bpf_cgroup_release(acquired); - if (!kptr) - return 0; - - bpf_cgroup_release(kptr); - - return 0; -} - -SEC("tp_btf/cgroup_mkdir") -__failure __msg("arg#0 expected pointer to map value") -int BPF_PROG(cgrp_kfunc_get_null, struct cgroup *cgrp, const char *path) -{ - struct cgroup *kptr; - - /* Cannot use bpf_cgroup_kptr_get() on a NULL pointer. */ - kptr = bpf_cgroup_kptr_get(NULL); - if (!kptr) - return 0; - - bpf_cgroup_release(kptr); - - return 0; -} - SEC("tp_btf/cgroup_mkdir") __failure __msg("Unreleased reference") int BPF_PROG(cgrp_kfunc_xchg_unreleased, struct cgroup *cgrp, const char *path) @@ -207,8 +154,8 @@ int BPF_PROG(cgrp_kfunc_xchg_unreleased, struct cgroup *cgrp, const char *path) } SEC("tp_btf/cgroup_mkdir") -__failure __msg("Unreleased reference") -int BPF_PROG(cgrp_kfunc_get_unreleased, struct cgroup *cgrp, const char *path) +__failure __msg("must be referenced or trusted") +int BPF_PROG(cgrp_kfunc_rcu_get_release, struct cgroup *cgrp, const char *path) { struct cgroup *kptr; struct __cgrps_kfunc_map_value *v; @@ -217,11 +164,12 @@ int BPF_PROG(cgrp_kfunc_get_unreleased, struct cgroup *cgrp, const char *path) if (!v) return 0; - kptr = bpf_cgroup_kptr_get(&v->cgrp); - if (!kptr) - return 0; - - /* Kptr acquired above is never released. */ + bpf_rcu_read_lock(); + kptr = v->cgrp; + if (kptr) + /* Can't release a cgroup kptr stored in a map. */ + bpf_cgroup_release(kptr); + bpf_rcu_read_unlock(); return 0; } diff --git a/tools/testing/selftests/bpf/progs/cgrp_kfunc_success.c b/tools/testing/selftests/bpf/progs/cgrp_kfunc_success.c index e9dbd1af05a7..5354455a01be 100644 --- a/tools/testing/selftests/bpf/progs/cgrp_kfunc_success.c +++ b/tools/testing/selftests/bpf/progs/cgrp_kfunc_success.c @@ -126,13 +126,11 @@ int BPF_PROG(test_cgrp_get_release, struct cgroup *cgrp, const char *path) return 0; } - kptr = bpf_cgroup_kptr_get(&v->cgrp); - if (!kptr) { + bpf_rcu_read_lock(); + kptr = v->cgrp; + if (!kptr) err = 3; - return 0; - } - - bpf_cgroup_release(kptr); + bpf_rcu_read_unlock(); return 0; } From patchwork Tue Apr 11 04:16:33 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: David Vernet X-Patchwork-Id: 81715 Return-Path: Delivered-To: ouuuleilei@gmail.com Received: by 2002:a59:b0ea:0:b0:3b6:4342:cba0 with SMTP id b10csp2326003vqo; Mon, 10 Apr 2023 21:35:36 -0700 (PDT) X-Google-Smtp-Source: AKy350ahH+3pdXb8vzX8L5r+JvgMpw2SIEYRk+cD3/aZydDl4JkuqHPCOg3lZBysJIBmhXBSIANN X-Received: by 2002:a17:90a:5e4d:b0:240:75de:12d7 with SMTP id u13-20020a17090a5e4d00b0024075de12d7mr15758815pji.13.1681187736525; Mon, 10 Apr 2023 21:35:36 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1681187736; cv=none; d=google.com; s=arc-20160816; b=XWuZA0Q4QB05H13Mrg2aCLMNOUTzF5JuWm7YI8pjQ3VcxN+7qAgV7BTNN62Yp1PaIL +Q7Oz2nOa7NJvs9l8qL9PXb5P1a+ZUVxd55pkGjJfVfR+1LXSKskU8AGpNALhJZuSjBe 5+hXfpyMF1hszKVh6cs75LRkB3d1JFjYtynCE2DPuxDYF6hdLUXlL7QMJSdiazdfPG4T pKK4zHNbLOPHT2JjdKOgG+7mxDIsRfC6UxNJ70/0/5krFMuX6xaV14QoA0YQhdsW5QMe 1gKaOaTLAQ/rRUwxj/Cob3ykfT5a7ZAgtupPgrhU3iU0ztu3CB/1wW8DWGah3j6YSd9d //JQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from; bh=f8r9n+ovWuQwy53nYZcyLOjkE/UdHOnvkJQHdAE1iAk=; b=ENDIB8ihig/DYQ8ghNLjK/yr2Ff0UoDLygH4uqmirMmGBtRwOzvNBrS0UDEjyEI4Uh lwwYgGRKfWXY0HQwDwIcgqt7A5HwHKp7On6ElXG+YcGIumi8FecUOVGgRD6RjAkhAfLW REOozuKS7AgHcnd2EL2GkYmR5X6lCUVdqSPbwXHJ2xjcayJw5b3Dl5AaTgIkTK4Mwj2p OL1dliFZaSK8Fff7NmIB9r76STrTXd+ZNHLDnAhRfGlpQeZ55jkemj4c/bqDOwVXWnLj XNOcWxQHBKla8ldRL3B0bICNnQ8PSHlCXcx9f3H6VFQ3uPLQnIMLxKQDykNlUKhYaY+U isqA== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id 90-20020a17090a0fe300b002466d549574si8578634pjz.26.2023.04.10.21.35.24; Mon, 10 Apr 2023 21:35:36 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S230081AbjDKEQs (ORCPT + 99 others); Tue, 11 Apr 2023 00:16:48 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:35888 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229889AbjDKEQl (ORCPT ); Tue, 11 Apr 2023 00:16:41 -0400 Received: from mail-qt1-f169.google.com (mail-qt1-f169.google.com [209.85.160.169]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id DE10EE74; Mon, 10 Apr 2023 21:16:40 -0700 (PDT) Received: by mail-qt1-f169.google.com with SMTP id ge18so3761643qtb.0; Mon, 10 Apr 2023 21:16:40 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; t=1681186600; x=1683778600; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=f8r9n+ovWuQwy53nYZcyLOjkE/UdHOnvkJQHdAE1iAk=; b=JZY+S84zh2AgwldcJGTKW7KuYjVH6MS8xoNv9hBAfPnYRWbDjVJYpGx3AChTmRVwg2 GuuGta+B9rAb5hjXpdLYMb3a/VeRGB1wL0fhFENnqI50cE65QJidDOmoE/1FPA7XI7Np sOVMvwCw1MMM7e/HZvpYaKhCFPhauOsGvuw5VS4IcwI377b2RktPA9w7NNna9UbipUGD hk7Lzuubg+5dIyAg7O4pkkJsV30W1IR2ks9PzlysFJiOAIm4nKy7mVyccPWXXVTaHST7 NjF5hPqKm5YTnpal7JLO5C8pHHmYbMiLHQffnBznNG9+FtJlaFh8vB7Fr0zjeg7/ewP3 ve5g== X-Gm-Message-State: AAQBX9doZCAP12EHOqtA1DI8U1eLT+55Th/iBWikPbJeW9qWhbcdvnZw DWH5lZ+KiqtKTHQyxMOfTBDz1lYsVhzFtacf X-Received: by 2002:a05:622a:130f:b0:3e6:720f:bad7 with SMTP id v15-20020a05622a130f00b003e6720fbad7mr19864719qtk.54.1681186599543; Mon, 10 Apr 2023 21:16:39 -0700 (PDT) Received: from localhost ([2620:10d:c091:400::5:8681]) by smtp.gmail.com with ESMTPSA id o76-20020a37414f000000b007486052d731sm3738297qka.10.2023.04.10.21.16.38 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 10 Apr 2023 21:16:39 -0700 (PDT) From: David Vernet To: bpf@vger.kernel.org Cc: ast@kernel.org, daniel@iogearbox.net, andrii@kernel.org, martin.lau@linux.dev, song@kernel.org, yhs@fb.com, john.fastabend@gmail.com, kpsingh@kernel.org, sdf@google.com, haoluo@google.com, jolsa@kernel.org, linux-kernel@vger.kernel.org, kernel-team@meta.com Subject: [PATCH bpf-next 3/3] bpf,docs: Remove references to bpf_cgroup_kptr_get() Date: Mon, 10 Apr 2023 23:16:33 -0500 Message-Id: <20230411041633.179404-3-void@manifault.com> X-Mailer: git-send-email 2.40.0 In-Reply-To: <20230411041633.179404-1-void@manifault.com> References: <20230411041633.179404-1-void@manifault.com> MIME-Version: 1.0 X-Spam-Status: No, score=0.5 required=5.0 tests=FREEMAIL_FORGED_FROMDOMAIN, FREEMAIL_FROM,HEADER_FROM_DIFFERENT_DOMAINS,RCVD_IN_DNSWL_NONE, RCVD_IN_MSPIKE_H3,RCVD_IN_MSPIKE_WL,SPF_HELO_NONE,SPF_PASS autolearn=no autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?= X-GMAIL-THRID: =?utf-8?q?1762853112007518210?= X-GMAIL-MSGID: =?utf-8?q?1762853112007518210?= The bpf_cgroup_kptr_get() kfunc has been removed, and bpf_cgroup_acquire() / bpf_cgroup_release() now have the same semantics as bpf_task_acquire() / bpf_task_release(). This patch updates the BPF documentation to reflect this. Signed-off-by: David Vernet --- Documentation/bpf/kfuncs.rst | 68 ------------------------------------ 1 file changed, 68 deletions(-) diff --git a/Documentation/bpf/kfuncs.rst b/Documentation/bpf/kfuncs.rst index d8a16c4bef7f..3b42cfe12437 100644 --- a/Documentation/bpf/kfuncs.rst +++ b/Documentation/bpf/kfuncs.rst @@ -572,74 +572,6 @@ bpf_task_release() respectively, so we won't provide examples for them. ---- -You may also acquire a reference to a ``struct cgroup`` kptr that's already -stored in a map using bpf_cgroup_kptr_get(): - -.. kernel-doc:: kernel/bpf/helpers.c - :identifiers: bpf_cgroup_kptr_get - -Here's an example of how it can be used: - -.. code-block:: c - - /* struct containing the struct task_struct kptr which is actually stored in the map. */ - struct __cgroups_kfunc_map_value { - struct cgroup __kptr * cgroup; - }; - - /* The map containing struct __cgroups_kfunc_map_value entries. */ - struct { - __uint(type, BPF_MAP_TYPE_HASH); - __type(key, int); - __type(value, struct __cgroups_kfunc_map_value); - __uint(max_entries, 1); - } __cgroups_kfunc_map SEC(".maps"); - - /* ... */ - - /** - * A simple example tracepoint program showing how a - * struct cgroup kptr that is stored in a map can - * be acquired using the bpf_cgroup_kptr_get() kfunc. - */ - SEC("tp_btf/cgroup_mkdir") - int BPF_PROG(cgroup_kptr_get_example, struct cgroup *cgrp, const char *path) - { - struct cgroup *kptr; - struct __cgroups_kfunc_map_value *v; - s32 id = cgrp->self.id; - - /* Assume a cgroup kptr was previously stored in the map. */ - v = bpf_map_lookup_elem(&__cgroups_kfunc_map, &id); - if (!v) - return -ENOENT; - - /* Acquire a reference to the cgroup kptr that's already stored in the map. */ - kptr = bpf_cgroup_kptr_get(&v->cgroup); - if (!kptr) - /* If no cgroup was present in the map, it's because - * we're racing with another CPU that removed it with - * bpf_kptr_xchg() between the bpf_map_lookup_elem() - * above, and our call to bpf_cgroup_kptr_get(). - * bpf_cgroup_kptr_get() internally safely handles this - * race, and will return NULL if the task is no longer - * present in the map by the time we invoke the kfunc. - */ - return -EBUSY; - - /* Free the reference we just took above. Note that the - * original struct cgroup kptr is still in the map. It will - * be freed either at a later time if another context deletes - * it from the map, or automatically by the BPF subsystem if - * it's still present when the map is destroyed. - */ - bpf_cgroup_release(kptr); - - return 0; - } - ----- - Other kfuncs available for interacting with ``struct cgroup *`` objects are bpf_cgroup_ancestor() and bpf_cgroup_from_id(), allowing callers to access the ancestor of a cgroup and find a cgroup by its ID, respectively. Both