On Tue, Aug 4, 2026 at 10:45 AM Alexis Lothoré (eBPF Foundation)
<[email protected]> wrote:
>
> Hello,
> this is v6 of the series aiming to bring basic support for KASAN checks
> to BPF JITed programs. This new revision takes a step back on stack
> accessing insn tracking, as the previous attempt was fragile and
> error-prone, it brings back a simpler tracking, at the cost of some
> unecessary checks being inserted. While at it, I took this time a look
> at how many accesses are being instrumented, and how many of those
> are "wrongly" instrumented (because they access stack), and I got
> those rough numbers on the whole selftests set:
> - total: 451997 checks inserted
> - checks added on stack access (checking reg == BPF_REG_FP, not precise,
>   but gives a rough idea): 21786
>
> So that makes ~5% of "over-instrumented" accesses
>
> Original cover letter:
>
> "Traditional" KASAN allows to spot memory management mistakes by
> reserving a fraction of memory as "shadow memory" that will map to the
> rest of the memory and allow its monitoring. Each memory-accessing
> instruction is then instrumented at build time to call some ASAN check
> function, that will analyze the corresponding bits in shadow memory, and
> if it detects the access as invalid, trigger a detailed report. The goal
> of this series is to replicate this mechanism for BPF programs when they
> are being JITed into native instructions: that's then the JIT compiler
> that is in charge of inserting calls to the corresponding kasan checks,
> when a program is being loaded into the kernel. This task involves:
> - identifying at program load time the instructions performing memory
>   accesses
> - identifying those accesses properties (size ? read or write ?) to
>   define the relevant kasan check function to call
> - just before the identified instructions:
>   - perform the basic context saving (ie: saving registers)
>   - inserting a call to the relevant kasan check function
>   - restore context
> - whenever the instrumented program executes, if it performs an invalid
>   access, it triggers a kasan report identical to those instrumented on
>   kernel side at build time.
>
> The series comes with new selftests programs that generate a wide
> variety of kasan reports: those need the kernel to be running with
> kasan_multi_shot enabled.
>
> As discussed in [1], this series is based on some choices and
> assumptions:
> - it focuses on x86_64 for now, and so only on KASAN_GENERIC
> - not all memory accessing BPF instructions are being instrumented:
>   - it discards instructions accessing BPF program stack (already
>     monitored by page guards)
>   - it discards possibly faulting instructions, like BPF_PROBE_MEM or
>     BPF_PROBE_ATOMIC insns
>
> ---
> Changes in v6:
> - dropped instruction original offset tracking
> - when patching instructions, track former non_stack_access flag by
>   passing original insn to adjust_insn_aux_data
> - drop unecessary dep on CONFIG_KASAN in Kconfig
> - fold patch adding the emit_kasan_helper into the patch actually
>   calling it, to avoid an unused static function warning
> - move stack access check out of emit_kasan_check
> - replace hardcoded ip value by a computed value
> - add OoB testing
> - add fix commit to make cmdline_contains stricter
>
> - Link to v5: 
> https://patch.msgid.link/[email protected]
>
> Changes in v5:
> - fixed a few instruction offset for generated fixups
> - fix insn marking for single insn patches
> - enforce more checks in tests
> - skip tests if kasan_multi_shot isn't enabled
> - Link to v4: 
> https://patch.msgid.link/[email protected]
>
> Changes in v4:
> - fix insn_offs_in_patch leakage in bpf_convert_ctx_access
> - handle BPF_ATOMIC in is_mem_insn
> - correctly mark fixup instructions if a single insn is generated
> - clarify new kconfig (Andrey) and drop VMAP_STACK dep
> - refactor BPF_FETCH atomic handling in JIT loop
> - make kernel log reading resilient to unrelated, interleaved logs in
>   the selftests
> - make new test kfuncs depend on BPF_JIT_KASAN rather than KASAN_GENERIC
> - Link to v3: 
> https://patch.msgid.link/[email protected]
>
> Changes in v3:
> - Do not insert KASAN instrumentation when dealing with cBPF
> - Fix stack-accessing insn tracking for verifier patches, as original
>   instruction location in the generated patch may vary
> - drop cBPF support for stack-accessing insn marking
> - make sure to flag correctly memory access if different verifier states
>   involve different memory types (eg: stack in one path, non-stack in
>   another path)
> - refactor BPF_ST handling in x86 JIT compiler
> - improve tests coverage (cover instrumentation for a few patches
>   emitted by the verifier)
> - Link to v2: 
> https://patch.msgid.link/[email protected]
>
> Changes in v2:
> - declare asan functions as extern in JIT compiler rather than exposing
>   them in kasan header
> - invert stack-accessing instructions marking to make sure not to skip
>   instructions that could end up accessing to-be-checked memory
> - fix stack accesses marking when verifier patches instructions
> - add best effort marking for cBPF
> - add missing call depth accounting in jited instrumentation
> - skip unused registers in kasan instrumentation save/restore
> - remove faulty stack align in kasan instrumentation
> - drop commit skipping some jit-related tests
> - cover missing instructions: BPF_ST and atomics
> - completely rework tests: directly tune shadow memory, increase
>   coverage, do not consume kernel logs
> - Link to v1: 
> https://patch.msgid.link/[email protected]
>
> To: Alexei Starovoitov <[email protected]>
> To: Daniel Borkmann <[email protected]>
> To: John Fastabend <[email protected]>
> To: Andrii Nakryiko <[email protected]>
> To: Martin KaFai Lau <[email protected]>
> To: Eduard Zingerman <[email protected]>
> To: Kumar Kartikeya Dwivedi <[email protected]>
> To: Song Liu <[email protected]>
> To: Yonghong Song <[email protected]>
> To: Jiri Olsa <[email protected]>
> To: Thomas Gleixner <[email protected]>
> To: Borislav Petkov <[email protected]>
> To: Dave Hansen <[email protected]>
> To: [email protected]
> To: "H. Peter Anvin" <[email protected]>
> To: Shuah Khan <[email protected]>
> To: Ingo Molnar <[email protected]>
> To: Andrey Konovalov <[email protected]>
> Cc: [email protected]
> Cc: Bastien Curutchet <[email protected]>
> Cc: Thomas Petazzoni <[email protected]>
> Cc: [email protected]
> Cc: [email protected]
> Cc: [email protected]
>
> ---
> Alexis Lothoré (eBPF Foundation) (9):
>       bpf: mark instructions accessing program stack
>       bpf: add BPF_JIT_KASAN for KASAN instrumentation of JITed programs
>       bpf, x86: refactor BPF_ST management in do_jit
>       bpf, x86: emit KASAN checks in x86 JITed programs
>       bpf, x86: enable KASAN for JITed programs on x86
>       selftests/bpf: make cmdline_contains stricter
>       selftests/bpf: add helpers for KASAN in JIT testing
>       selftests/bpf: move bpf_jit_harden helper into testing_helpers
>       selftests/bpf: add tests to validate KASAN on JIT programs
>

Alexis, please resend your patch set rebased on the latest bpf-next,
it has a merge conflict. Hopefully we'll get around to reviewing this
after the resend, thanks!

pw-bot: cr

>  arch/x86/Kconfig                                   |   1 +
>  arch/x86/net/bpf_jit_comp.c                        | 283 ++++++++++---
>  include/linux/bpf_verifier.h                       |   2 +
>  kernel/bpf/Kconfig                                 |  17 +
>  kernel/bpf/fixups.c                                |  45 +-
>  kernel/bpf/verifier.c                              |   9 +
>  .../selftests/bpf/prog_tests/bpf_insn_array.c      |  44 +-
>  tools/testing/selftests/bpf/prog_tests/kasan.c     | 454 ++++++++++++++++++++
>  tools/testing/selftests/bpf/progs/kasan.c          | 462 
> +++++++++++++++++++++
>  tools/testing/selftests/bpf/progs/kasan_harden.c   |  41 ++
>  .../testing/selftests/bpf/test_kmods/bpf_testmod.c |  55 +++
>  tools/testing/selftests/bpf/testing_helpers.c      |  32 ++
>  tools/testing/selftests/bpf/testing_helpers.h      |   1 +
>  tools/testing/selftests/bpf/unpriv_helpers.c       |  21 +-
>  tools/testing/selftests/bpf/unpriv_helpers.h       |   2 +
>  15 files changed, 1369 insertions(+), 100 deletions(-)
> ---
> base-commit: 5fb2b9636c7043f415a12e3336f2bf6983c9e93a
> change-id: 20260126-kasan-fcd68f64cd7b
>
> Best regards,
> --
> Alexis Lothoré (eBPF Foundation) <[email protected]>
>

Reply via email to