[PATCH bpf-next v2 02/11] bpf: Pass the owning verifier state to callback setters

From: Ihor Solodrai

Date: Fri Oct 09 2026 - 16:30:01 EST


Callback setters receive the caller and callee frames, but not the
verifier state that owns the callee. Synchronous callbacks use a queued
state and asynchronous callbacks use a separate state, neither of which
is env->cur_state.

Callback-local bookkeeping needs to be recorded in that owning state.
Pass it through the callback setters and the map callback setup hook.

No functional change.

Signed-off-by: Ihor Solodrai <ihor.solodrai@xxxxxxxxx>
---
include/linux/bpf.h | 3 +++
kernel/bpf/verifier.c | 16 +++++++++++++---
2 files changed, 16 insertions(+), 3 deletions(-)

diff --git a/include/linux/bpf.h b/include/linux/bpf.h
index 54144372281c..d5de9d49a168 100644
--- a/include/linux/bpf.h
+++ b/include/linux/bpf.h
@@ -39,6 +39,7 @@
#include <asm/rqspinlock.h>

struct bpf_verifier_env;
+struct bpf_verifier_state;
struct bpf_verifier_log;
struct perf_event;
struct bpf_prog;
@@ -178,6 +179,7 @@ struct bpf_map_ops {


int (*map_set_for_each_callback_args)(struct bpf_verifier_env *env,
+ struct bpf_verifier_state *state,
struct bpf_func_state *caller,
struct bpf_func_state *callee);
long (*map_for_each_callback)(struct bpf_map *map,
@@ -3183,6 +3185,7 @@ int bpf_iter_map_fill_link_info(const struct bpf_iter_aux_info *aux,
struct bpf_link_info *info);

int map_set_for_each_callback_args(struct bpf_verifier_env *env,
+ struct bpf_verifier_state *state,
struct bpf_func_state *caller,
struct bpf_func_state *callee);

diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
index a0310e093880..8d6812fee0c9 100644
--- a/kernel/bpf/verifier.c
+++ b/kernel/bpf/verifier.c
@@ -10817,6 +10817,7 @@ static void invalidate_outgoing_stack_args(struct bpf_verifier_env *env,
}

typedef int (*set_callee_state_fn)(struct bpf_verifier_env *env,
+ struct bpf_verifier_state *state,
struct bpf_func_state *caller,
struct bpf_func_state *callee,
int insn_idx);
@@ -11000,7 +11001,7 @@ static int push_callback_call(struct bpf_verifier_env *env, struct bpf_insn *ins
callee->async_entry_cnt = state->frame[0]->async_entry_cnt + 1;

/* Convert bpf_timer_set_callback() args into timer callback args */
- err = set_callee_state_cb(env, caller, callee, insn_idx);
+ err = set_callee_state_cb(env, async_cb, caller, callee, insn_idx);
if (err)
return err;

@@ -11027,7 +11028,7 @@ static int push_callback_call(struct bpf_verifier_env *env, struct bpf_insn *ins
if (IS_ERR(callee))
return PTR_ERR(callee);

- err = set_callee_state_cb(env, caller, callee, insn_idx);
+ err = set_callee_state_cb(env, callback_state, caller, callee, insn_idx);
if (err)
return err;

@@ -11257,6 +11258,7 @@ static int check_func_callx(struct bpf_verifier_env *env, struct bpf_insn *insn,
}

int map_set_for_each_callback_args(struct bpf_verifier_env *env,
+ struct bpf_verifier_state *state,
struct bpf_func_state *caller,
struct bpf_func_state *callee)
{
@@ -11287,6 +11289,7 @@ int map_set_for_each_callback_args(struct bpf_verifier_env *env,
}

static int set_map_elem_callback_state(struct bpf_verifier_env *env,
+ struct bpf_verifier_state *state,
struct bpf_func_state *caller,
struct bpf_func_state *callee,
int insn_idx)
@@ -11303,7 +11306,7 @@ static int set_map_elem_callback_state(struct bpf_verifier_env *env,
return -ENOTSUPP;
}

- err = map->ops->map_set_for_each_callback_args(env, caller, callee);
+ err = map->ops->map_set_for_each_callback_args(env, state, caller, callee);
if (err)
return err;

@@ -11313,6 +11316,7 @@ static int set_map_elem_callback_state(struct bpf_verifier_env *env,
}

static int set_loop_callback_state(struct bpf_verifier_env *env,
+ struct bpf_verifier_state *state,
struct bpf_func_state *caller,
struct bpf_func_state *callee,
int insn_idx)
@@ -11335,6 +11339,7 @@ static int set_loop_callback_state(struct bpf_verifier_env *env,
}

static int set_timer_callback_state(struct bpf_verifier_env *env,
+ struct bpf_verifier_state *state,
struct bpf_func_state *caller,
struct bpf_func_state *callee,
int insn_idx)
@@ -11370,6 +11375,7 @@ static int set_timer_callback_state(struct bpf_verifier_env *env,
}

static int set_find_vma_callback_state(struct bpf_verifier_env *env,
+ struct bpf_verifier_state *state,
struct bpf_func_state *caller,
struct bpf_func_state *callee,
int insn_idx)
@@ -11398,6 +11404,7 @@ static int set_find_vma_callback_state(struct bpf_verifier_env *env,
}

static int set_user_ringbuf_callback_state(struct bpf_verifier_env *env,
+ struct bpf_verifier_state *state,
struct bpf_func_state *caller,
struct bpf_func_state *callee,
int insn_idx)
@@ -11421,6 +11428,7 @@ static int set_user_ringbuf_callback_state(struct bpf_verifier_env *env,
}

static int set_rbtree_add_callback_state(struct bpf_verifier_env *env,
+ struct bpf_verifier_state *state,
struct bpf_func_state *caller,
struct bpf_func_state *callee,
int insn_idx)
@@ -11454,6 +11462,7 @@ static int set_rbtree_add_callback_state(struct bpf_verifier_env *env,
}

static int set_task_work_schedule_callback_state(struct bpf_verifier_env *env,
+ struct bpf_verifier_state *state,
struct bpf_func_state *caller,
struct bpf_func_state *callee,
int insn_idx)
@@ -11489,6 +11498,7 @@ static int set_task_work_schedule_callback_state(struct bpf_verifier_env *env,
}

static int set_rcu_callback_state(struct bpf_verifier_env *env,
+ struct bpf_verifier_state *state,
struct bpf_func_state *caller,
struct bpf_func_state *callee,
int insn_idx)
--
2.56.0