Skip to content

Commit 241e169

Browse files
Kernel gate: print the verifier log for a rejected object; socket tap loads on 6.1
First run of the matrix: 6.12 clean, wire rejected on 6.1 and 6.6 after ~1600 processed insns, walk rejected on bpf-next (7.3-rc4), and the socket tap loaded everywhere, its iov_iter reads being CO-RE guarded. The gate ran veristat at log level 0, so none of the reasons reached CI. It now reloads just the rejected objects with -v -l1 and a rotated 64 KiB log, tail-bounded, before failing. Correct the README and workflow header: the 6.4 floor for the socket tap is for the build host's vmlinux.h, not for the kernel it loads on.
1 parent 234bf50 commit 241e169

3 files changed

Lines changed: 24 additions & 9 deletions

File tree

‎.github/workflows/kernel-matrix.yml‎

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -26,11 +26,11 @@ name: kernel-matrix
2626
# old stamps.
2727
#
2828
# Expected failures are part of the signal: the wire tap attaches with TCX
29-
# (6.6+), and the legacy socket tap reads `iov_iter.__iov`, which only exists
30-
# from 6.4 — so a rejection of those on 6.1 marks the floor, not a regression.
31-
# The CO-RE objects themselves are compiled against the runner's own kernel
32-
# BTF (vmlinux.h is generated by `make bpf`), so the build host must be 6.4+
33-
# for the socket tap to compile at all; ubuntu-latest is.
29+
# (6.6+), so a rejection of it on 6.1 marks the floor, not a regression. The
30+
# legacy socket tap names `iov_iter.__iov`, which only exists from 6.4, but
31+
# its reads are CO-RE guarded, so it loads on older kernels; the 6.4 floor is
32+
# for the build host, since vmlinux.h is generated from the runner's own BTF
33+
# by `make bpf`. ubuntu-latest is well past it.
3434

3535
on:
3636
workflow_dispatch:

‎README.md‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -471,9 +471,9 @@ buffer held before — a response head where curl's body should be.
471471
bpf-next under cilium's little-vm-helper, and runs the vendored static
472472
veristat in each VM via `build/verify-kernel.sh`. The summary is a grid
473473
of (object, program) × kernel, since `peer_sendmsg`/`peer_recvmsg`
474-
recur across the TLS taps. Rejections on 6.1 are expected for the wire
475-
tap (TCX attach, 6.6+) and the socket tap (`iov_iter.__iov`, 6.4+);
476-
they mark the floor. `make veristat-matrix` runs the same thing
474+
recur across the TLS taps. The socket tap loads on 6.1 despite the
475+
header note above: its `iov_iter` reads are CO-RE guarded, so the 6.4
476+
floor is for the build host only. `make veristat-matrix` runs the same thing
477477
locally with lvh + a static qemu (Linux, KVM, root for the VM), and
478478
`make veristat` is the single-kernel check against this host.
479479

‎build/verify-kernel.sh‎

Lines changed: 16 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -56,7 +56,22 @@ if [ -n "${OUT_CSV:-}" ]; then
5656
fi
5757

5858
# Drop the header row; fail if any program's verdict is not "success".
59-
if printf '%s\n' "$csv" | tail -n +2 | grep -q ',failure$'; then
59+
# Before failing, reload just the rejected objects in verbose mode so the
60+
# verifier's own explanation lands in the CI log — the first pass runs at
61+
# log level 0 and only reports the verdict. The log is rotated to its tail
62+
# (that is where the rejection reason is), bounded so a long program's
63+
# trace does not swamp the job output.
64+
failed="$(printf '%s\n' "$csv" | tail -n +2 | grep ',failure$' | cut -d, -f1 | sort -u || true)"
65+
if [ -n "$failed" ]; then
66+
objs=""
67+
for f in $failed; do
68+
for o in $OBJS; do
69+
[ "$(basename "$o")" = "$f" ] && objs="$objs $o"
70+
done
71+
done
72+
echo ">> verifier log for the rejected object(s):$objs"
73+
# shellcheck disable=SC2086
74+
"$VERISTAT" -v -l1 --log-size=65536 $objs 2>&1 | grep -v '^\s*$' | tail -n 200 || true
6075
echo "::error::BPF verifier rejected a program on kernel $KREL" >&2
6176
exit 1
6277
fi

0 commit comments

Comments
 (0)