[RFC PATCH bpf-next 11/12] bpf: add a lockless path ancestor iterator
sashiko-bot at kernel.org
sashiko-bot at kernel.org
Tue Oct 6 00:31:19 UTC 2026
> Add a second variant of the ancestor iterator that drives the walk's
> rcu mode: bpf_iter_path_ancestors_rcu is KF_RCU_PROTECTED, so the whole
> iteration sits in one RCU read-side critical section - implicit in
> non-sleepable programs, bpf_rcu_read_lock() in sleepable ones - within
> which the verifier already rejects everything sleepable. This is what
> makes a path-based policy expressible from the non-sleepable LSM hooks,
> and it drops the per-position reference traffic for the sleepable ones.
>
> Positions come borrowed rather than acquired here: a lockless iteration
> holds no reference to pass on, so bpf_iter_path_ancestors_rcu_next()
> hands out the walk's own position, valid until the next step. That is
> what RCU protection buys and all it buys: the dentry cannot be freed
> under the iteration, but nothing read out of the position may be passed
> to a kfunc demanding a trusted argument.
>
> [ ... ]
> else is needed: the source argument's ordinary "__iter" classification
> already rejects a handover from an iterator whose RCU read-side
> critical section has ended.
>
> Signed-off-by: Justin Suess <utilityemal77 at gmail.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261006002020.2890858-1-utilityemal77@gmail.com?part=11
More information about the Linux-security-module-archive
mailing list