> bpf_check() fetches the vmlinux BTF up front for every program, whether
> the program uses kernel types or not.  With the upcoming
> CONFIG_DEBUG_INFO_BTF=m the BTF is a module that is loaded on demand,
> and since systemd loads socket filters at boot, a program that needs the
> BTF only because bpf_check() asked for it would pull it in on every
> system, whether anything uses BTF or not.
> 
> Stop fetching up front and fetch at the points where kernel types enter
> the verifier state instead:
> 
>  - bpf_add_kfunc_call(), for the first kfunc call of a program;
>  - check_pseudo_btf_id(), for ldimm64 of a kernel variable;
>  - check_ptr_to_map_access(), for accessing a map pointer's fields;
>  - check_helper_call(), when the helper's prototype takes or returns a
>    PTR_TO_BTF_ID, or is bpf_snprintf_btf()/bpf_seq_printf_btf(), which
> [ ... ]
> With CONFIG_DEBUG_INFO_BTF=y the vmlinux BTF is parsed at boot by the
> first kfunc registration, and without BTF the new helper check is
> skipped, so nothing changes for either.
> 
> Signed-off-by: Jay Wang <[email protected]>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/[email protected]?part=3


Reply via email to