Re: [PATCH bpf-next v3 0/9] Fixes for bpf_jit_free

From: Pu Lehui

Date: Thu Aug 06 2026 - 05:20:01 EST


Hi Daniel,

Sorry for late reply.

On 2026/8/3 21:05, Daniel Borkmann wrote:
Hi Pu,

On 7/25/26 5:49 PM, Pu Lehui wrote:
From: Pu Lehui <pulehui@xxxxxxxxxx>

Fixes for bpf_jit_free identified by Sashiko, as previously noted in [0].

Link: https://lore.kernel.org/bpf/28ba19a4-b487-49fd-bbba-04410acdb113@xxxxxxxxxxxxx/ [0]

Given you need to introduce a bpf_jit_free multiple times in the various
JITs, could you rather look into moving this code into the core so core BPF
code can handle this? Then it would also be easier to test in CI if we can
consolidate the subprogram failure handling.


Before preparing the next, I'd like to clarify two points:

1. Only target non-pack archs (s390, parisc...),or touch binary-pack archs like x86/arm64 as well?

2. For handling jit priv data without callbacks, I have two options:
- Option A: Append jit priv data directly after jit_data in one allocation. Then a single kvfree(aux->jit_data) in core frees both.
```
// alloc
jit_data = kvzalloc(sizeof(*jit_data) + addrs_size, GFP_KERNEL);
jit_data->ctx.addrs = (void *)(jit_data + 1);

// free
kvfree(aux->jit_data)
```
- Option B: Add jit_priv_data to bpf_prog->aux and point to the jit priv data, and free both of them.
```
// alloc
jit_data = kvzalloc(sizeof(*jit_data), GFP_KERNEL);
jit_data->ctx.addrs = kvzalloc(addrs_size, GFP_KERNEL);
fp->aux->jit_priv_data = jit_data->ctx.addrs;

// free
kvfree(aux->jit_priv_data)
kvfree(aux->jit_data)
```

Which approach prefer, or do you have other recommendations?

Thanks,
Lehui


Thanks,
Daniel

v3:
- Add fix for private stack leak on arm64. (Sashiko)
- Some minor fixes.

v2: https://lore.kernel.org/bpf/20260725102020.2287770-1-pulehui@xxxxxxxxxxxxxxx
- Fix JITs not freeing leftover jit_data when jit_subprogs() aborts. (Sashiko)
- Drop fix for loongarch as it's applied.

v1: https://lore.kernel.org/bpf/20260722112754.1615201-1-pulehui@xxxxxxxxxxxxxxx


Pu Lehui (9):
   bpf: Extract the bpf_jit_binary_hdr helper
   s390/bpf: Fix memory leak in bpf_jit_free
   parisc: Fix memory leak in bpf_jit_free
   bpf, sparc64: Fix memory leak in bpf_jit_free
   ARC, bpf: Fix memory leak in bpf_jit_free
   bpf, arm64: Fix memory leak in bpf_jit_free
   bpf, arm64: Fix private stack leak when JIT failed
   riscv, bpf: Adjust bpf_func to account for CFI offset in bpf_jit_free
   bpf: Fix double-free RO header in bpf_jit_free

  arch/arc/net/bpf_jit_core.c      | 19 +++++++++++++++++++
  arch/arm64/net/bpf_jit_comp.c    |  6 +++---
  arch/loongarch/net/bpf_jit.c     |  6 ++----
  arch/parisc/net/bpf_jit_core.c   | 19 +++++++++++++++++++
  arch/powerpc/net/bpf_jit_comp.c  |  5 +++--
  arch/riscv/net/bpf_jit_core.c    |  8 +++-----
  arch/s390/net/bpf_jit_comp.c     | 19 +++++++++++++++++++
  arch/sparc/net/bpf_jit_comp_64.c | 19 +++++++++++++++++++
  arch/x86/net/bpf_jit_comp.c      |  7 ++-----
  include/linux/filter.h           |  2 ++
  kernel/bpf/core.c                | 19 ++++++++++---------
  11 files changed, 101 insertions(+), 28 deletions(-)