[PATCH bpf 0/2] bpf: Require referenced or trusted pointer for __arg_trusted arg
From: Yiyang Chen
Date: Mon Oct 05 2026 - 11:21:52 EST
A global subprogram parameter tagged __arg_trusted is specified to accept
only the PTR_TRUSTED flavor of PTR_TO_BTF_ID, but the call-site check also
accepts a bare PTR_TO_BTF_ID and an MEM_RCU one.
check_reg_type() resolves the accepted types from the base argument type
alone without consulting arg_type's PTR_TRUSTED bit, and the trusted/RCU
enforcement in check_func_arg() is gated on is_kfunc(meta) so it never runs
for a subprogram call. A caller can therefore pass a pointer that is not
trusted and the callee is verified as holding PTR_TRUSTED, which makes the
dereference a raw load instead of a BPF_PROBE_MEM probe and lets the callee
pass the pointer on to a kfunc that would have rejected it at the original
call site.
Reject a PTR_TO_BTF_ID that is neither referenced nor trusted when the
argument is marked PTR_TRUSTED. A referenced register is accepted, as in
is_trusted_reg(). PTR_MAYBE_NULL is not counted as unsafe when __arg_nullable
declares it, so trusted-and-nullable arguments keep working. The kfunc path
is unchanged.
Yiyang Chen (2):
bpf: Require referenced or trusted pointer for __arg_trusted arg
selftests/bpf: Cover non-trusted pointer to __arg_trusted subprog arg
kernel/bpf/verifier.c | 21 ++++++++++++
.../selftests/bpf/progs/verifier_global_ptr_args.c | 40 ++++++++++++++++++++++
2 files changed, 61 insertions(+)
base-commit: d82cbceca49252bb0cd695326af8206c734e2744
--
2.34.0