> bpf_check() fetches the vmlinux BTF up front for every program, whether > the program uses kernel types or not. With the upcoming > CONFIG_DEBUG_INFO_BTF=m the BTF is a module that is loaded on demand, > and since systemd loads socket filters at boot, a program that needs the > BTF only because bpf_check() asked for it would pull it in on every > system, whether anything uses BTF or not. > > Stop fetching up front and fetch at the points where kernel types enter > the verifier state instead: > > - bpf_add_kfunc_call(), for the first kfunc call of a program; > - check_pseudo_btf_id(), for ldimm64 of a kernel variable; > - check_ptr_to_map_access(), for accessing a map pointer's fields; > - check_helper_call(), when the helper's prototype takes or returns a > PTR_TO_BTF_ID, or is bpf_snprintf_btf()/bpf_seq_printf_btf(), which > [ ... ] > With CONFIG_DEBUG_INFO_BTF=y the vmlinux BTF is parsed at boot by the > first kfunc registration, and without BTF the new helper check is > skipped, so nothing changes for either. > > Signed-off-by: Jay Wang <[email protected]>
Sashiko has reviewed this patch and found no issues. It looks great! -- Sashiko AI review ยท https://sashiko.dev/#/patchset/[email protected]?part=3
