On Tue, Jul 30, 2024 at 01:16:02AM GMT, viro@xxxxxxxxxx wrote: > From: Al Viro <viro@xxxxxxxxxxxxxxxxxx> > > Irregularity here is fdput() not in the same scope as fdget(); > just fold ____bpf_prog_get() into its (only) caller and that's > it... > > Signed-off-by: Al Viro <viro@xxxxxxxxxxxxxxxxxx> > --- > kernel/bpf/syscall.c | 32 +++++++++++--------------------- > 1 file changed, 11 insertions(+), 21 deletions(-) > > diff --git a/kernel/bpf/syscall.c b/kernel/bpf/syscall.c > index 3093bf2cc266..c5b252c0faa8 100644 > --- a/kernel/bpf/syscall.c > +++ b/kernel/bpf/syscall.c > @@ -2407,18 +2407,6 @@ int bpf_prog_new_fd(struct bpf_prog *prog) > O_RDWR | O_CLOEXEC); > } > > -static struct bpf_prog *____bpf_prog_get(struct fd f) > -{ > - if (!fd_file(f)) > - return ERR_PTR(-EBADF); > - if (fd_file(f)->f_op != &bpf_prog_fops) { > - fdput(f); > - return ERR_PTR(-EINVAL); > - } > - > - return fd_file(f)->private_data; > -} > - > void bpf_prog_add(struct bpf_prog *prog, int i) > { > atomic64_add(i, &prog->aux->refcnt); > @@ -2474,20 +2462,22 @@ bool bpf_prog_get_ok(struct bpf_prog *prog, > static struct bpf_prog *__bpf_prog_get(u32 ufd, enum bpf_prog_type *attach_type, > bool attach_drv) > { > - struct fd f = fdget(ufd); > + CLASS(fd, f)(ufd); > struct bpf_prog *prog; > > - prog = ____bpf_prog_get(f); > - if (IS_ERR(prog)) > + if (fd_empty(f)) > + return ERR_PTR(-EBADF); > + if (fd_file(f)->f_op != &bpf_prog_fops) > + return ERR_PTR(-EINVAL); > + > + prog = fd_file(f)->private_data; > + if (IS_ERR(prog)) // can that actually happen? > return prog; With or without that removed: Reviewed-by: Christian Brauner <brauner@xxxxxxxxxx>