This series fixes two NULL-ptr-derefs in BTF handling. Patch 1 handles the syzbot report. A key-less BTF (btf_key_type_id == 0) used to be rejected for hash maps, until htab and rhtab gained a ->map_check_btf (to register a dtor) that does not look at the key, so a key-less hash map is now accepted. Dumping it through bpffs feeds the key type_id 0 into btf_type_seq_show() and NULL-derefs in btf_type_show(). Reject it again.
Patch 2 fixes a related, pre-existing crash reachable via bpf_snprintf_btf(). A "const void" type_id (a modifier that resolves to void, present in the vmlinux BTF) NULL-derefs in btf_modifier_show() - void has no ->show op. void has no size and nothing to render, so route the show call sites through a helper that falls back to btf_df_show() - the "<unsupported kind:N>" placeholder already used for FWD/FUNC/FLOAT/DECL_TAG. Patches 3 and 4 add selftests for the two cases. They are meant to reproduce the crashes: each deliberately walks the faulting path, so on an unfixed kernel it oopses the task (and panics it under panic_on_oops). That is intentional - the tests verify the fix and reproduce the bug - so a static review flagging them for crashing an unfixed kernel can be ignored. v1 -> v2: AI reported a pre-exist issue. Let's fold it in this series. v1: https://lore.kernel.org/bpf/[email protected]/ Jiayuan Chen (4): bpf: Reject key-less BTF for hash maps bpf: Fix NULL-ptr-deref when showing a void BTF type selftests/bpf: Add test for key-less BTF hash map selftests/bpf: Add test for showing a void BTF type kernel/bpf/btf.c | 10 ++- kernel/bpf/hashtab.c | 8 ++ .../bpf/prog_tests/btf_map_keyless.c | 83 +++++++++++++++++++ .../selftests/bpf/prog_tests/btf_show_void.c | 57 +++++++++++++ .../selftests/bpf/progs/btf_show_void.c | 22 +++++ 5 files changed, 179 insertions(+), 1 deletion(-) create mode 100644 tools/testing/selftests/bpf/prog_tests/btf_map_keyless.c create mode 100644 tools/testing/selftests/bpf/prog_tests/btf_show_void.c create mode 100644 tools/testing/selftests/bpf/progs/btf_show_void.c -- 2.43.0

