Re: [PATCH bpf] bpf: Fix smp_processor_id() warning in rhtab_delete_elem()
From: Alexei Starovoitov
Date: Tue Sep 29 2026 - 02:09:57 EST
On Mon, Sep 28, 2026 at 08:31 PM Ömer Mete Kaya <omermetekaya0@xxxxxxxxx> wrote:
> bpf_mem_cache_free_rcu() uses this_cpu_ptr() which requires preemption
> to be disabled. In rhtab_delete_elem(), this call happens after
> bpf_enable_instrumentation(), so preemption is re-enabled at that
> point and this_cpu_ptr() triggers:
bpf_disable_instrumentation() doesn't disable preemption.
It's migrate_disable() plus bpf_prog_active++.
bpf_mem_alloc relies on the callers to disable migration.
See the comment above bpf_mem_alloc().
All callers of rhtab_delete_elem() do that except
__rhtab_map_lookup_and_delete_batch(). That's the bug.
bpf_disable_instrumentation() in rhtab_delete_elem() protects
the bucket lock from NMI progs. rhtab_map_update_elem() calls
bpf_mem_cache_alloc/free() outside of it too.
Don't stretch it. Disable migration in the batch.
> Fixes: 6905f8601298 ("bpf: Allow special fields in resizable hashtab")
Wrong tag. The batch came in
commit 818e00848227 ("bpf: Implement iteration ops for resizable hashtab")
pw-bot: cr