Hi Hui,

Thanks for the further fixes.

On 2026/8/13 20:02, Hui Su wrote:
> Per-CPU array, hash, and cgroup storage map updates without BPF_F_CPU
> or BPF_F_ALL_CPUS use a value buffer whose per-CPU slots are packed in
> possible-CPU order. The buffer is sized as:
> 
>   round_up(value_size, 8) * num_possible_cpus()
> 
> The update paths iterate over possible CPUs, but use the logical CPU ID
> to calculate the source offset:
> 
>   value + size * cpu
> 
> This only works when possible CPU IDs are contiguous starting at zero.
> 
> For example, with a possible CPU mask of 0,2-3, the buffer contains
> three slots corresponding to CPUs 0, 2, and 3. CPU2 is therefore
> expected to use slot 1 and CPU3 slot 2. Instead, the current code uses
> slots 2 and 3 respectively, causing incorrect per-CPU values and an
> out-of-bounds read from the update buffer for CPU3.
> 
> The corresponding lookup paths already use a dense offset while
> iterating over possible CPUs. Do the same for the array, hash, and
> cgroup storage update paths, advancing the source offset once for each
> possible CPU. BPF_F_ALL_CPUS continues to use the same value for every
> CPU.
> 
> Fixes: 8eb76cb03f0f ("bpf: Add BPF_F_CPU and BPF_F_ALL_CPUS flags support for 
> percpu_array maps")

The ci bot got the point about the missing Fixes:

Fixes: c6936161fd55 ("bpf: Add BPF_F_CPU and BPF_F_ALL_CPUS flags
support for percpu_hash and lru_percpu_hash maps")
Fixes: 47c79f05aa0d ("bpf: Add BPF_F_CPU and BPF_F_ALL_CPUS flags
support for percpu_cgroup_storage maps")

> Reported-by: [email protected]

This Reported-by is unnecessary, because Sashiko would review most LKML
patches.

> Signed-off-by: Hui Su <[email protected]>

Acked-by: Leon Hwang <[email protected]>

Thanks,
Leon

> ---

Reply via email to