Re: [PATCH bpf-next 0/4] Use correct destructor kfunc types
From: Yonghong Song <yonghong.song@linux.dev>
Date: 2025-07-25 16:54:47
Also in:
bpf, lkml
On 7/25/25 9:22 AM, Sami Tolvanen wrote:
Hi, On Fri, Jul 25, 2025 at 9:05 AM Yonghong Song [off-list ref] wrote:quoted
I tried your patch set on top of latest bpf-next. The problem still exists with the following error: [ 71.976265] CFI failure at bpf_obj_free_fields+0x298/0x620 (target: __bpf_crypto_ctx_release+0x0/0x10; expected type: 0xc1113566) [ 71.980134] Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI ... The following is the CFI related config items: $ grep CFI .config CONFIG_CFI_AUTO_DEFAULT=y CONFIG_FUNCTION_PADDING_CFI=11 CONFIG_ARCH_SUPPORTS_CFI_CLANG=y CONFIG_ARCH_USES_CFI_TRAPS=y CONFIG_CFI_CLANG=y # CONFIG_CFI_ICALL_NORMALIZE_INTEGERS is not set CONFIG_HAVE_CFI_ICALL_NORMALIZE_INTEGERS_CLANG=y CONFIG_HAVE_CFI_ICALL_NORMALIZE_INTEGERS_RUSTC=y # CONFIG_CFI_PERMISSIVE is not set Did I miss anything?Interesting. I tested this on arm64 and confirmed that the issue is fixed there, so I wonder if we need to use KCFI_REFERENCE() here to make sure objtool / x86 runtime patching knows this function actually indirectly called. I'll test this on x86 and see what's going on.
I just tried arm64 with your patch set. CFI crash still happened: CFI failure at tcp_ack+0xe74/0x13cc (target: bpf__tcp_congestion_ops_in_ack_event+0x0/0x78; expected type: 0x64424 87a) Internal error: Oops - CFI: 00000000f2008228 [#1] SMP Modules linked in: bpf_testmod(OE) [last unloaded: bpf_testmod(OE)] CPU: 0 UID: 0 PID: 152 Comm: test_progs Tainted: G OE 6.16.0-rc6-g95993dc3039e-dirty #162 NONE Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE Hardware name: linux,dummy-virt (DT) pstate: 33400005 (nzCV daif +PAN -UAO +TCO +DIT -SSBS BTYPE=--) pc : tcp_ack+0xe74/0x13cc lr : tcp_ack+0xe34/0x13cc The arm64 CFI related config: $ cat .config | grep CFI CONFIG_AS_HAS_CFI_NEGATE_RA_STATE=y CONFIG_ARCH_SUPPORTS_CFI_CLANG=y CONFIG_CFI_CLANG=y # CONFIG_CFI_ICALL_NORMALIZE_INTEGERS is not set CONFIG_HAVE_CFI_ICALL_NORMALIZE_INTEGERS_CLANG=y # CONFIG_CFI_PERMISSIVE is not set
Thanks for taking a look! Sami