Thread (9 messages) read the whole thread 9 messages, 2 authors, 9d ago

Re: [PATCH 6.16.y 0/6] cBPF JIT spray hardening

From: Pawan Gupta <pawan.kumar.gupta@linux.intel.com>
Date: 2026-07-22 15:18:12
Also in: bpf, linux-arm-kernel, linux-riscv, loongarch, stable

On Tue, Jul 21, 2026 at 03:08:11PM +0200, Greg Kroah-Hartman wrote:
On Tue, Jul 14, 2026 at 11:58:24AM -0700, Pawan Gupta wrote:
quoted
Hi,

These backports harden BPF JIT against spectre-v2 class of attacks. Without
a predictor flush, execution of new BPF program may use stale prediction
left behind by the freed one.

To avoid this, issue an IBPB flush on all CPUs on JIT program allocation.
The flush is conditional to spectre-v2 mitigation applied.

Patch 1-2: Adds the predictor flush hook and enables it on x86 via IBPB.

	  bpf: Support for hardening against JIT spraying
	  x86/bugs: Enable IBPB flush on BPF JIT allocation

Patch 3-6: Narrow the flush to only unprivileged JIT allocations
	   to avoid redundant flushes. Also adds pack-selection changes
	   that minimizes flushes.

	  bpf: Restrict JIT predictor flush to cBPF
	  bpf: Skip redundant IBPB in pack allocator
	  bpf: Prefer packs that won't trigger an IBPB flush on allocation
	  bpf: Prefer dirty packs for eBPF allocations

This one is mostly similar to 6.18:

  https://lore.kernel.org/all/20260713-cbpf-jit-spray-hardening-6-18-y-v1-0-755f60c55705@linux.intel.com/ (local)
There is no active 6.16.y kernel branch, so why is this being sent to
us?
Sorry that was a mistake. I had an old 6.16.y worktree in my machine and I
assumed it was still active. Please ignore.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help