Re: [PATCH bpf-next v3 1/2] bpf: Fix sleepable check for tracing prog

From: Andrii Nakryiko

Date: Tue Aug 04 2026 - 19:46:09 EST


On Tue, Aug 4, 2026 at 7:57 AM Leon Hwang <leon.hwang@xxxxxxxxx> wrote:
>
> When CONFIG_FUNCTION_ERROR_INJECTION is disabled, a sleepable tracing prog
> is allowed to attach to '__x64_'-alike prefix symbols.
>
> It is because the verifier does not verify whether the symbol is a kernel
> function or a bpf prog. That said, a sleepable tracing prog is allowed to
> attach to a bpf prog target whose name has '__x64_'-alike prefix.
>
> For example, a sleepable fentry prog attaches to a '__x64_sys_nop' XDP
> prog, and copies buffer from a user pointer with bpf_copy_from_user()
> helper. After attaching the XDP prog to lo interface, the kernel BUG
> could be triggered by 'ping -c 1 -W 1 127.0.0.1':
>
> [ 3.460756] BUG: sleeping function called from invalid context at kernel/bpf/trampoline.c:1324
>
> Fix it by disallowing sleepable tracing prog always when its target btf
> is not kernel's btf.
>
> Fixes: 16d9c5660692 ("bpf: Always allow sleepable programs on syscalls")
> Acked-by: Viktor Malik <vmalik@xxxxxxxxxx>
> Signed-off-by: Leon Hwang <leon.hwang@xxxxxxxxx>
> ---
> kernel/bpf/verifier.c | 3 +++
> 1 file changed, 3 insertions(+)
>
> diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
> index b274004fccfd..7bb541e343b2 100644
> --- a/kernel/bpf/verifier.c
> +++ b/kernel/bpf/verifier.c
> @@ -19019,6 +19019,9 @@ static int btf_id_allow_sleepable(u32 btf_id, unsigned long addr, const struct b
>
> switch (prog->type) {
> case BPF_PROG_TYPE_TRACING:
> + if (!btf_is_kernel(btf))
> + return -EINVAL;
> +

see sashiko reply, just move it outside of switch and disallow
sleepable for anything that is not kernel/module BTF, regardless of
program type

pw-bot: cr


> t = btf_type_by_id(btf, btf_id);
> if (!t)
> return -EINVAL;
> --
> 2.55.0
>