Validating the eBPF Verifier via State Embedding
Hao Sun, Zhendong Su
摘要
This paper introduces state embedding, a novel and highly effective technique for validating the correctness of the eBPF verifier, a critical component for Linux kernel security. To check whether a program is safe to execute, the verifier must track over-approximated program states along each potential control-flow path; any concrete state not contained in the tracked approximation may invalidate the verifier's conclusion. Our key insight is that one can effectively detect logic bugs in the verifier by embedding a program with certain approximation-correctness checks expected to be validated by the verifier. Indeed, for a program deemed safe by the verifier, our approach embeds concrete states via eBPF program constructs as correctness checks. By construction, the resulting state-embedded program allows the verifier to validate whether the embedded concrete states are correctly approximated by itself; any validation failure therefore reveals a logic bug in the verifier. We realize state embedding as a practical tool and apply it to test the eBPF verifier. Our evaluation results highlight its effectiveness. Despite the extensive scrutiny and testing undertaken on the eBPF verifier, our approach, within one month, uncovered 15 previously unknown logic bugs, 10 of which have already been fixed. Many of the detected bugs are severe, e.g., two are exploitable and can lead to local privilege escalation.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper13
- eTran: Extensible Kernel Transport with eBPFZhongjie Chen, Qingkai Meng, ChonLam Lao, Yifan Liu 等NSDI 2025 · 被引用 17 次
- Rex: Closing the language-verifier gap with safe and usable kernel extensionsJinghao Jia, Ruowen Qin, Milo Craun, Egor Lukiyanov 等USENIX ATC 2025 · 被引用 11 次
- PeTAL: Ensuring Access Control Integrity against Data-only Attacks on LinuxJuhee Kim, Jinbum Park, Yoochan Lee, Chengyu Song 等CCS 2024 · 被引用 6 次
- Neutrino: Fine-grained GPU Kernel Profiling via Programmable ProbingSonglin Huang, Chenshu WuOSDI 2025 · 被引用 5 次
- Revealing the Unstable Foundations of eBPF-Based Kernel ExtensionsShawn Wanxiang Zhong, Jing Liu, Andrea C. Arpaci-Dusseau, Remzi H. Arpaci-DusseauEuroSys 2025 · 被引用 4 次
它引用的顶会 Paper7
- kAFL: Hardware-Assisted Feedback Fuzzing for OS KernelsSergej Schumilo, Cornelius Aschermann, Robert Gawlik, Sebastian Schinzel 等USENIX Security 2017 · 被引用 324 次
- XRP: In-Kernel Storage Functions with eBPFYuhong Zhong, Haoyu Li, Yu Jian Wu, Ioannis Zarkadas 等OSDI 2022 · 被引用 100 次
- On learning meaningful assert statements for unit test casesCody Watson, Michele Tufano, Kevin Moran, Gabriele Bavota 等ICSE 2020 · 被引用 96 次
- Specification and verification in the field: Applying formal methods to BPF just-in-time compilers in the Linux kernelLuke Nelson, Jacob Van Geffen, Emina Torlak, Xi WangOSDI 2020 · 被引用 72 次
- Automated Assertion Generation via Information Retrieval and Its Integration with Deep learningHao Yu, Yiling Lou, Ke Sun, Dezhi Ran 等ICSE 2022 · 被引用 42 次
相关 Paper
- Finding Correctness Bugs in eBPF Verifier with Structured and Sanitized ProgramHao Sun, Yiru Xu, Jianzhong Liu, Yuheng Shen 等EuroSys 2024 · 被引用 24 次
- Verifying the Verifier: eBPF Range Analysis VerificationHarishankar Vishwanathan, Matan Shachnai, Srinivas Narayana, Santosh NagarakatteCAV 2023 · 被引用 37 次
- Formalizing the Linux eBPF Core ISA: A Mechanized Operational Semantics and Its Real-World ApplicationsShenghao Yuan, Yazhou Tang, Tianci Cao, Frédéric Besson 等OOPSLA 2026
- VEP: A Two-stage Verification Toolchain for Full eBPF ProgrammabilityXiwei Wu, Yueyang Feng, Tianyi Huang, Xiaoyang Lu 等NSDI 2025 · 被引用 8 次
- eBPF Misbehavior Detection: Fuzzing with a Specification-Based OracleTao Lyu, Kumar Kartikeya Dwivedi, Thomas Bourgeat, Mathias Payer 等SOSP 2025
