From: sashiko-bot@kernel.org
To: "Alexei Starovoitov" <alexei.starovoitov@gmail.com>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf-next v2 02/15] selftests/bpf: Add tests for ALU on pointers with CAP_PERFMON
Date: Fri, 02 Oct 2026 13:08:03 +0000 [thread overview]
Message-ID: <20261002130803.A0FFA1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20261002124714.180012-3-alexei.starovoitov@gmail.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] bpf/selftests: test logic fails to verify ^= and *= on pointers
--
commit f742d8e4562c4f3d08b13ad422c226ac60b38d25
Author: Alexei Starovoitov <ast@kernel.org>
selftests/bpf: Add tests for ALU on pointers with CAP_PERFMON
This commit adds BPF selftests to check that various ALU operations
(&=, |=, ^=, >>=, *=) on a pointer to a map value properly produce a scalar
or are rejected as expected depending on capabilities.
> diff --git a/tools/testing/selftests/bpf/progs/verifier_value_illegal_alu.c b/tools/testing/selftests/bpf/progs/verifier_value_illegal_alu.c
> index 9f669cf85c593..31663338866d3 100644
> --- a/tools/testing/selftests/bpf/progs/verifier_value_illegal_alu.c
> +++ b/tools/testing/selftests/bpf/progs/verifier_value_illegal_alu.c
> @@ -165,6 +165,171 @@ __naked void map_ptr_illegal_alu_op(void)
> : __clobber_all);
> }
>
> +SEC("socket")
> +__description("tag in the low bit of a pointer, and, shift")
> +__success __retval(0)
> +__failure_unpriv __msg_unpriv("R1 bitwise operator &= on pointer")
> +__naked void ptr_tag_and_shift(void)
> +{
> + asm volatile (" \
> + r2 = r10; \
> + r2 += -8; \
> + r1 = 0; \
> + *(u64*)(r2 + 0) = r1; \
> + r1 = %[map_hash_48b] ll; \
> + call %[bpf_map_lookup_elem]; \
> + if r0 == 0 goto l0_%=; \
> + r1 = r0; \
> + r1 &= 1; \
> + r2 = r0; \
> + r2 >>= 1; \
> + r3 = r0; \
> + r3 |= 1; \
> + r3 ^= 1; \
[Severity: Medium]
Does this sequence correctly verify the ^= operation on a pointer?
The preceding |= operation converts the pointer in r3 to a scalar, which
means the ^= operation is subsequently performed on a scalar rather than a
pointer.
Additionally, since this program places multiple unprivileged operations
sequentially, wouldn't the verifier abort at the first failure (r1 &= 1),
leaving the unprivileged rejection of the subsequent operations (>>=, |=, ^=)
completely untested?
[ ... ]
> +SEC("socket")
> +__description("number op= pointer")
> +__success __retval(0)
> +__failure_unpriv __msg_unpriv("R1 pointer arithmetic with *= operator")
> +__naked void number_mul_ptr(void)
> +{
> + asm volatile (" \
> + r2 = r10; \
> + r2 += -8; \
> + r1 = 0; \
> + *(u64*)(r2 + 0) = r1; \
> + r1 = %[map_hash_48b] ll; \
> + call %[bpf_map_lookup_elem]; \
> + if r0 == 0 goto l0_%=; \
> + r1 = 7; \
> + r1 *= r0; \
[Severity: Medium]
Does this actually test the verifier's handling of pointer *= scalar?
The multiplication is applied to a scalar destination (r1) with a pointer
source (r0). Would it be more accurate to test if applying *= to a pointer
destination correctly downgrades the pointer to a scalar?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261002124714.180012-1-alexei.starovoitov@gmail.com?part=2
next prev parent reply other threads:[~2026-10-02 13:08 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-02 12:46 [PATCH bpf-next v2 00/15] bpf: Support programs compiled by rust-bpf Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 01/15] bpf: Allow bitwise ops, shifts and mul/div on pointers with CAP_PERFMON Alexei Starovoitov
2026-10-02 13:49 ` bot+bpf-ci
2026-10-02 12:47 ` [PATCH bpf-next v2 02/15] selftests/bpf: Add tests for ALU " Alexei Starovoitov
2026-10-02 13:08 ` sashiko-bot [this message]
2026-10-03 11:48 ` Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 03/15] bpf: Treat load and store through a number as arena access Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 04/15] selftests/bpf: Add tests for arena access through numbers Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 05/15] bpf: Allow names of Rust types and functions in BTF Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 06/15] selftests/bpf: Add tests for " Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 07/15] bpf: Allow arguments without names in static " Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 08/15] selftests/bpf: Add test for arguments without names in static functions Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 09/15] bpf: Allow a variable in DATASEC that is smaller than its type Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 10/15] bpftool: Skip pieces of variables in DATASEC Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 11/15] selftests/bpf: Add tests for a variable that is smaller than its type Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 12/15] libbpf: Keep global data in arena when the object has .arena.data Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 13/15] libbpf: Keep format strings of bpf_printk() in .rodata.str Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 14/15] selftests/bpf: Add test for global data in arena Alexei Starovoitov
2026-10-02 13:49 ` bot+bpf-ci
2026-10-02 12:47 ` [PATCH bpf-next v2 15/15] selftests/bpf: Add test for global data of a program in Rust Alexei Starovoitov
2026-10-03 1:33 ` sashiko-bot
2026-10-03 11:47 ` Alexei Starovoitov
2026-10-03 14:20 ` [PATCH bpf-next v2 00/15] bpf: Support programs compiled by rust-bpf patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261002130803.A0FFA1F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=alexei.starovoitov@gmail.com \
--cc=bpf@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.