From: sashiko-bot@kernel.org
To: "Alexei Starovoitov" <alexei.starovoitov@gmail.com>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf-next 04/14] selftests/bpf: Add tests for arena access through numbers
Date: Wed, 30 Sep 2026 19:48:26 +0000 [thread overview]
Message-ID: <20260930194827.05A601F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260930193127.2181684-5-alexei.starovoitov@gmail.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] bpf: verifier rejects valid atomic RMW due to register aliasing in check_atomic_rmw
--
commit 3887e0dd2a26cbc2d80c4f160a7eb98315fcc18d
Author: Alexei Starovoitov <ast@kernel.org>
selftests/bpf: Add tests for arena access through numbers
This commit adds various tests for loading and storing through addresses
returned by bpf_arena_alloc_pages() without cast_kern. It includes tests
covering different sizes, atomic operations, and boundary conditions for
arena and non-arena pointers.
> diff --git a/tools/testing/selftests/bpf/progs/verifier_arena_scalar.c b/tools/testing/selftests/bpf/progs/verifier_arena_scalar.c
> new file mode 100644
> index 0000000000000..bebc37f501b7e
> --- /dev/null
> +++ b/tools/testing/selftests/bpf/progs/verifier_arena_scalar.c
[ ... ]
> +SEC("syscall")
> +__arena_scalar
> +__description("arena_scalar: xchg into the register that holds a pointer to stack")
> +__failure __msg("misaligned access off (0x0; 0xffffffffffffffff)+0 size 8")
> +__naked void xchg_into_stack_ptr(void)
> +{
> + asm volatile (" \
> + r1 = %[arena] ll; \
> + r1 = 0; \
> + *(u64 *)(r10 - 8) = r1; \
> + r1 = r10; \
> + r1 += -8; \
> + .8byte %[xchg_insn]; /* r1 = xchg_64(r1 + 0, r1) */ \
> + r0 = 0; \
> + exit; \
> +" :
> + : __imm_addr(arena),
> + __imm_insn(xchg_insn, BPF_ATOMIC_OP(BPF_DW, BPF_XCHG, BPF_REG_1, BPF_REG_1, 0))
> + : __clobber_all);
> +}
[Severity: Medium]
Does this test codify an incorrect verifier rejection?
It appears the BPF verifier incorrectly rejects valid atomic read-modify-write
operations (like xchg r1, [r1]) on non-arena pointers (like PTR_TO_STACK)
due to in-place register corruption.
Looking at kernel/bpf/verifier.c:check_atomic_rmw() at line 7312:
/* load_reg may be dst_reg. Look at dst_reg before it's marked as unknown. */
dst_reg = mem_access_reg(env, insn->dst_reg, &arena);
load_reg = bpf_atomic_load_reg(insn);
if (load_reg >= 0) {
/* check and record load of old value */
err = check_reg_arg(env, load_reg, DST_OP);
Since kernel/bpf/verifier.c:mem_access_reg() at line 7162 returns a live
reference to the register state for non-arena pointers:
if (!is_arena_scalar(env, regno))
return cur_regs(env) + regno;
Could this cause an aliasing bug when the live register is later mutated by
check_reg_arg(), leading to this test's misaligned access failure message?
This is where the verifier attempts to snapshot the destination register state
but fails to isolate it from the source register mutation.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260930193127.2181684-1-alexei.starovoitov@gmail.com?part=4
next prev parent reply other threads:[~2026-09-30 19:48 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 19:31 [PATCH bpf-next 00/14] bpf: Support programs compiled by rust-bpf Alexei Starovoitov
2026-09-30 19:31 ` [PATCH bpf-next 01/14] bpf: Allow bitwise ops, shifts and mul/div on pointers with CAP_PERFMON Alexei Starovoitov
2026-09-30 19:31 ` [PATCH bpf-next 02/14] selftests/bpf: Add tests for ALU " Alexei Starovoitov
2026-09-30 19:31 ` [PATCH bpf-next 03/14] bpf: Treat load and store through a number as arena access Alexei Starovoitov
2026-09-30 19:31 ` [PATCH bpf-next 04/14] selftests/bpf: Add tests for arena access through numbers Alexei Starovoitov
2026-09-30 19:48 ` sashiko-bot [this message]
2026-09-30 20:22 ` bot+bpf-ci
2026-09-30 19:31 ` [PATCH bpf-next 05/14] bpf: Allow names of Rust types and functions in BTF Alexei Starovoitov
2026-09-30 20:22 ` bot+bpf-ci
2026-10-01 17:42 ` Alan Maguire
2026-10-02 12:24 ` Alexei Starovoitov
2026-10-02 13:38 ` Alan Maguire
2026-09-30 19:31 ` [PATCH bpf-next 06/14] selftests/bpf: Add tests for " Alexei Starovoitov
2026-09-30 20:22 ` bot+bpf-ci
2026-09-30 19:31 ` [PATCH bpf-next 07/14] bpf: Allow arguments without names in static " Alexei Starovoitov
2026-10-01 21:14 ` Alan Maguire
2026-09-30 19:31 ` [PATCH bpf-next 08/14] selftests/bpf: Add test for arguments without names in static functions Alexei Starovoitov
2026-10-01 21:22 ` Alan Maguire
2026-09-30 19:31 ` [PATCH bpf-next 09/14] bpf: Allow a variable in DATASEC that is smaller than its type Alexei Starovoitov
2026-09-30 19:47 ` sashiko-bot
2026-09-30 19:31 ` [PATCH bpf-next 10/14] selftests/bpf: Add tests for a variable " Alexei Starovoitov
2026-09-30 19:31 ` [PATCH bpf-next 11/14] libbpf: Keep global data in arena when the object has .arena.data Alexei Starovoitov
2026-09-30 19:46 ` sashiko-bot
2026-09-30 20:22 ` bot+bpf-ci
2026-09-30 19:31 ` [PATCH bpf-next 12/14] libbpf: Keep format strings of bpf_printk() in .rodata.str Alexei Starovoitov
2026-09-30 20:22 ` bot+bpf-ci
2026-09-30 19:31 ` [PATCH bpf-next 13/14] selftests/bpf: Add test for global data in arena Alexei Starovoitov
2026-09-30 20:22 ` bot+bpf-ci
2026-09-30 19:31 ` [PATCH bpf-next 14/14] selftests/bpf: Add test for global data of a program in Rust Alexei Starovoitov
2026-09-30 19:53 ` sashiko-bot
2026-09-30 20:22 ` bot+bpf-ci
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260930194827.05A601F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=alexei.starovoitov@gmail.com \
--cc=bpf@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.