Re: [PATCH bpf-next v6 0/9] bpf: add support for KASAN checks in JITed programs

From: Andrii Nakryiko

Date: Fri Aug 21 2026 - 14:59:45 EST


On Tue, Aug 4, 2026 at 10:45 AM Alexis Lothoré (eBPF Foundation)
<alexis.lothore@xxxxxxxxxxx> wrote:
>
> Hello,
> this is v6 of the series aiming to bring basic support for KASAN checks
> to BPF JITed programs. This new revision takes a step back on stack
> accessing insn tracking, as the previous attempt was fragile and
> error-prone, it brings back a simpler tracking, at the cost of some
> unecessary checks being inserted. While at it, I took this time a look
> at how many accesses are being instrumented, and how many of those
> are "wrongly" instrumented (because they access stack), and I got
> those rough numbers on the whole selftests set:
> - total: 451997 checks inserted
> - checks added on stack access (checking reg == BPF_REG_FP, not precise,
> but gives a rough idea): 21786
>
> So that makes ~5% of "over-instrumented" accesses
>
> Original cover letter:
>
> "Traditional" KASAN allows to spot memory management mistakes by
> reserving a fraction of memory as "shadow memory" that will map to the
> rest of the memory and allow its monitoring. Each memory-accessing
> instruction is then instrumented at build time to call some ASAN check
> function, that will analyze the corresponding bits in shadow memory, and
> if it detects the access as invalid, trigger a detailed report. The goal
> of this series is to replicate this mechanism for BPF programs when they
> are being JITed into native instructions: that's then the JIT compiler
> that is in charge of inserting calls to the corresponding kasan checks,
> when a program is being loaded into the kernel. This task involves:
> - identifying at program load time the instructions performing memory
> accesses
> - identifying those accesses properties (size ? read or write ?) to
> define the relevant kasan check function to call
> - just before the identified instructions:
> - perform the basic context saving (ie: saving registers)
> - inserting a call to the relevant kasan check function
> - restore context
> - whenever the instrumented program executes, if it performs an invalid
> access, it triggers a kasan report identical to those instrumented on
> kernel side at build time.
>
> The series comes with new selftests programs that generate a wide
> variety of kasan reports: those need the kernel to be running with
> kasan_multi_shot enabled.
>
> As discussed in [1], this series is based on some choices and
> assumptions:
> - it focuses on x86_64 for now, and so only on KASAN_GENERIC
> - not all memory accessing BPF instructions are being instrumented:
> - it discards instructions accessing BPF program stack (already
> monitored by page guards)
> - it discards possibly faulting instructions, like BPF_PROBE_MEM or
> BPF_PROBE_ATOMIC insns
>
> ---
> Changes in v6:
> - dropped instruction original offset tracking
> - when patching instructions, track former non_stack_access flag by
> passing original insn to adjust_insn_aux_data
> - drop unecessary dep on CONFIG_KASAN in Kconfig
> - fold patch adding the emit_kasan_helper into the patch actually
> calling it, to avoid an unused static function warning
> - move stack access check out of emit_kasan_check
> - replace hardcoded ip value by a computed value
> - add OoB testing
> - add fix commit to make cmdline_contains stricter
>
> - Link to v5: https://patch.msgid.link/20260709-kasan-v5-0-1c64af8e4e1e@xxxxxxxxxxx
>
> Changes in v5:
> - fixed a few instruction offset for generated fixups
> - fix insn marking for single insn patches
> - enforce more checks in tests
> - skip tests if kasan_multi_shot isn't enabled
> - Link to v4: https://patch.msgid.link/20260708-kasan-v4-0-d5c177ab8227@xxxxxxxxxxx
>
> Changes in v4:
> - fix insn_offs_in_patch leakage in bpf_convert_ctx_access
> - handle BPF_ATOMIC in is_mem_insn
> - correctly mark fixup instructions if a single insn is generated
> - clarify new kconfig (Andrey) and drop VMAP_STACK dep
> - refactor BPF_FETCH atomic handling in JIT loop
> - make kernel log reading resilient to unrelated, interleaved logs in
> the selftests
> - make new test kfuncs depend on BPF_JIT_KASAN rather than KASAN_GENERIC
> - Link to v3: https://patch.msgid.link/20260701-kasan-v3-0-bd09bb942d86@xxxxxxxxxxx
>
> Changes in v3:
> - Do not insert KASAN instrumentation when dealing with cBPF
> - Fix stack-accessing insn tracking for verifier patches, as original
> instruction location in the generated patch may vary
> - drop cBPF support for stack-accessing insn marking
> - make sure to flag correctly memory access if different verifier states
> involve different memory types (eg: stack in one path, non-stack in
> another path)
> - refactor BPF_ST handling in x86 JIT compiler
> - improve tests coverage (cover instrumentation for a few patches
> emitted by the verifier)
> - Link to v2: https://patch.msgid.link/20260604-kasan-v2-0-c066e627fda8@xxxxxxxxxxx
>
> Changes in v2:
> - declare asan functions as extern in JIT compiler rather than exposing
> them in kasan header
> - invert stack-accessing instructions marking to make sure not to skip
> instructions that could end up accessing to-be-checked memory
> - fix stack accesses marking when verifier patches instructions
> - add best effort marking for cBPF
> - add missing call depth accounting in jited instrumentation
> - skip unused registers in kasan instrumentation save/restore
> - remove faulty stack align in kasan instrumentation
> - drop commit skipping some jit-related tests
> - cover missing instructions: BPF_ST and atomics
> - completely rework tests: directly tune shadow memory, increase
> coverage, do not consume kernel logs
> - Link to v1: https://patch.msgid.link/20260413-kasan-v1-0-1a5831230821@xxxxxxxxxxx
>
> To: Alexei Starovoitov <ast@xxxxxxxxxx>
> To: Daniel Borkmann <daniel@xxxxxxxxxxxxx>
> To: John Fastabend <john.fastabend@xxxxxxxxx>
> To: Andrii Nakryiko <andrii@xxxxxxxxxx>
> To: Martin KaFai Lau <martin.lau@xxxxxxxxx>
> To: Eduard Zingerman <eddyz87@xxxxxxxxx>
> To: Kumar Kartikeya Dwivedi <memxor@xxxxxxxxx>
> To: Song Liu <song@xxxxxxxxxx>
> To: Yonghong Song <yonghong.song@xxxxxxxxx>
> To: Jiri Olsa <jolsa@xxxxxxxxxx>
> To: Thomas Gleixner <tglx@xxxxxxxxxx>
> To: Borislav Petkov <bp@xxxxxxxxx>
> To: Dave Hansen <dave.hansen@xxxxxxxxxxxxxxx>
> To: x86@xxxxxxxxxx
> To: "H. Peter Anvin" <hpa@xxxxxxxxx>
> To: Shuah Khan <shuah@xxxxxxxxxx>
> To: Ingo Molnar <mingo@xxxxxxxxxx>
> To: Andrey Konovalov <andreyknvl@xxxxxxxxx>
> Cc: ebpf@xxxxxxxxxxxxxxxxxxx
> Cc: Bastien Curutchet <bastien.curutchet@xxxxxxxxxxx>
> Cc: Thomas Petazzoni <thomas.petazzoni@xxxxxxxxxxx>
> Cc: bpf@xxxxxxxxxxxxxxx
> Cc: linux-kernel@xxxxxxxxxxxxxxx
> Cc: linux-kselftest@xxxxxxxxxxxxxxx
>
> ---
> Alexis Lothoré (eBPF Foundation) (9):
> bpf: mark instructions accessing program stack
> bpf: add BPF_JIT_KASAN for KASAN instrumentation of JITed programs
> bpf, x86: refactor BPF_ST management in do_jit
> bpf, x86: emit KASAN checks in x86 JITed programs
> bpf, x86: enable KASAN for JITed programs on x86
> selftests/bpf: make cmdline_contains stricter
> selftests/bpf: add helpers for KASAN in JIT testing
> selftests/bpf: move bpf_jit_harden helper into testing_helpers
> selftests/bpf: add tests to validate KASAN on JIT programs
>

Alexis, please resend your patch set rebased on the latest bpf-next,
it has a merge conflict. Hopefully we'll get around to reviewing this
after the resend, thanks!

pw-bot: cr

> arch/x86/Kconfig | 1 +
> arch/x86/net/bpf_jit_comp.c | 283 ++++++++++---
> include/linux/bpf_verifier.h | 2 +
> kernel/bpf/Kconfig | 17 +
> kernel/bpf/fixups.c | 45 +-
> kernel/bpf/verifier.c | 9 +
> .../selftests/bpf/prog_tests/bpf_insn_array.c | 44 +-
> tools/testing/selftests/bpf/prog_tests/kasan.c | 454 ++++++++++++++++++++
> tools/testing/selftests/bpf/progs/kasan.c | 462 +++++++++++++++++++++
> tools/testing/selftests/bpf/progs/kasan_harden.c | 41 ++
> .../testing/selftests/bpf/test_kmods/bpf_testmod.c | 55 +++
> tools/testing/selftests/bpf/testing_helpers.c | 32 ++
> tools/testing/selftests/bpf/testing_helpers.h | 1 +
> tools/testing/selftests/bpf/unpriv_helpers.c | 21 +-
> tools/testing/selftests/bpf/unpriv_helpers.h | 2 +
> 15 files changed, 1369 insertions(+), 100 deletions(-)
> ---
> base-commit: 5fb2b9636c7043f415a12e3336f2bf6983c9e93a
> change-id: 20260126-kasan-fcd68f64cd7b
>
> Best regards,
> --
> Alexis Lothoré (eBPF Foundation) <alexis.lothore@xxxxxxxxxxx>
>