[PATCH bpf-next 0/2] bpf: Keep target extended until its last freplace link detaches

From: chenyuan_fl

Date: Wed Sep 23 2026 - 05:38:43 EST


From: Yuan Chen <chenyuan@xxxxxxxxxx>

is_extended is a plain boolean, but one target prog can carry several
freplace links at the same time, one on its entry and one on a global
subprogram. __bpf_trampoline_unlink_prog() cleared it whenever *any*
of them detached, so with two links on one target, detaching one of
them re-armed the unbounded tail call loop closed by commit
d6083f040d5d ("bpf: Prevent tailcall infinite loop caused by freplace"):
a single BPF_PROG_TEST_RUN on the tail-called target then panics the
kernel, reproduced on both bpf-next and master.

Patch 1 replaces the boolean with a count of the freplace links
attached to each target prog, so the target stays extended until its
last link detaches. Patch 2 adds a selftest covering the sequence.

Yuan Chen (2):
bpf: Keep target extended until its last freplace link detaches
selftests/bpf: Verify is_extended with multiple freplace links

include/linux/bpf.h | 4 +-
kernel/bpf/arraymap.c | 2 +-
kernel/bpf/trampoline.c | 10 ++-
.../selftests/bpf/prog_tests/tailcalls.c | 74 +++++++++++++++++++
.../bpf/progs/tailcall_freplace_multi.c | 27 +++++++
5 files changed, 110 insertions(+), 7 deletions(-)
create mode 100644 tools/testing/selftests/bpf/progs/tailcall_freplace_multi.c

--
2.54.0