Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider: - [Medium] bpf: panic reactor BPF program rejected due to PTR_TO_STACK argument - [Medium] rv: NULL pointer dereference in list_reactor_action on missing BTF --
commit fed00056d145e6ae07ec2d9b2b99084fea10c012 Author: Gabriele Monaco <[email protected]> tools/rv: Add reactors support to BPF monitors The commit adds reactors support to BPF monitors in the rv tool. It implements rv_react to format and pass messages to a BPF function, which can be overridden at load time by dynamically linking reactor object files like panic.o and printk.o. > diff --git a/tools/verification/rv/bpf_reactors/panic.c > b/tools/verification/rv/bpf_reactors/panic.c > new file mode 100644 > index 0000000000000..775f91a300f01 > --- /dev/null > +++ b/tools/verification/rv/bpf_reactors/panic.c > @@ -0,0 +1,15 @@ > +// SPDX-License-Identifier: GPL-2.0 > + > +#include "vmlinux.h" > +#include <bpf/bpf_helpers.h> > + > +void bpf_rv_react(char *msg) > +{ > + struct pt_regs regs = { 0 }; > + > + crash_kexec(®s); [Severity: Medium] Will the BPF verifier reject this program? The ®s argument evaluates to a PTR_TO_STACK register type, but crash_kexec expects a tracked PTR_TO_BTF_ID. The verifier's check_kfunc_args strictly requires KF_ARG_PTR_TO_BTF_ID for regular struct pointers unless explicitly tagged, so it may reject PTR_TO_STACK. > +} [ ... ] > diff --git a/tools/verification/rv/src/bpf_monitor.c > b/tools/verification/rv/src/bpf_monitor.c > index d43ee75d3904f..35bd1f40a109c 100644 > --- a/tools/verification/rv/src/bpf_monitor.c > +++ b/tools/verification/rv/src/bpf_monitor.c > @@ -676,12 +679,31 @@ static struct ring_buffer *bpf_setup_ring_buffer(struct > bpf_object *obj, > return rb; > } > > +static void list_reactor_action(const char *name, struct bpf_object *obj) > +{ > + const struct btf *btf = bpf_object__btf(obj); > + > + if (btf__find_by_name_kind(btf, BPF_REACTOR, BTF_KIND_FUNC) >= 0) [Severity: Medium] Can this cause a NULL pointer dereference? If the object file lacks BTF information (e.g., if it was stripped or compiled without -g), bpf_object__btf() returns NULL. btf__find_by_name_kind() then directly dereferences this NULL pointer in libbpf's btf__type_cnt() without validation. > + fprintf(stderr, "%s ", name); > +} -- Sashiko AI review ยท https://sashiko.dev/#/patchset/[email protected]?part=12
