On 31/7/26 23:21, Andrii Nakryiko wrote: > On Thu, Jul 30, 2026 at 10:20 PM Leon Hwang <[email protected]> wrote: >> >> On 31/7/26 08:07, Andrii Nakryiko wrote: >>> On Sat, Jul 25, 2026 at 6:27 AM Leon Hwang <[email protected]> wrote: >>>> >>>> When CONFIG_FUNCTION_ERROR_INJECTION is disabled, a sleepable tracing prog >>>> is allowed to attach to '__x64_'-alike prefix symbols. >>>> >>>> It is because the verifier does not verify whether the symbol is a kernel >>>> function or a bpf prog. That said, a sleepable tracing prog is allowed to >>>> attach to a bpf prog target whose name has '__x64_'-alike prefix. >>>> >>>> For example, a sleepable fentry prog attaches to a '__x64_sys_nop' XDP >>> >>> we do have addr, so we should be able to distinguish between attaching >>> to kernel function vs BPF program, no? >> >> >> Yes, we can distinguish a bpf prog from a kernel function by addr. >> >> I'd prefer passing 'tgt_prog' to btf_id_allow_sleepable() as a simple >> change. >> > > I don't think there is a need for new tgt_prog argument, we can just > check that supplied btf is not kernel/module BTF (see btf_is_kernel()) >
Makes sense. Will use btf_is_kernel(). Thanks, Leon

