From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f181.google.com (mail-pl1-f181.google.com [209.85.214.181]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DEEA239449C for ; Thu, 20 Aug 2026 18:26:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.181 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787250372; cv=none; b=CXVO5dAW7InoYZAtwKQrkyWhLJkX1QD/zu6wl2YZ7Nds8m/aM7lJRn6U2xvP78VVgSzfrfwpwodbz7JUEX34Cp3b2FohCSfxG9e+X1DrY8YEGhiu3Wu3hKiiFIQwlMqitStjqOLt0jNWgzdvjpk452R8vjU7Y3Jff5n9+mQEtPc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787250372; c=relaxed/simple; bh=nnAozmGFGvra2/iHSnITRelsom7JJlpRVcniFLhBxb8=; h=Message-ID:Subject:From:To:Cc:Date:In-Reply-To:References: Content-Type:MIME-Version; b=bXLbp1ZFW/rDwe62w9YfKMwSeaSA7Y1A2aqEqjYvQ1fx7ErCoEnLrHXHzeK6VyLrDxtsEzVkB0nhvW2KSNqN8AuSiv+Tln6WFJDtq808rTwjGLrEQucWPqq5RQ80hyPUtsb3IOchut6lNdnqf1qTw9WQgCHrjZU8hhTXvlyl4zo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=FskHZCyo; arc=none smtp.client-ip=209.85.214.181 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="FskHZCyo" Received: by mail-pl1-f181.google.com with SMTP id d9443c01a7336-2cf50c6f235so2655445ad.0 for ; Thu, 20 Aug 2026 11:26:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787250370; x=1787855170; darn=vger.kernel.org; h=mime-version:user-agent:content-transfer-encoding:content-type :references:in-reply-to:date:cc:to:from:subject:message-id:from:to :cc:subject:date:message-id:reply-to:content-type; bh=bBdyTAiG5JcLvXihuDX4B1484e1I/74jJ2owtdoOkdU=; b=FskHZCyoimRhmYfmcx9en4QwnfGw+V7UqcDZa4abfTikJEKrK4NnLDeQMUXb859qwb bZGcQGWrOHUUMCDghk05ViZoWUekvTMfcdxkE0jTO5XIpEaKcTvg6DstTYEu1jTIB1bE UBWS6EeITrx2QZ9yR77w10A+4Q69ptgNRn1ZuJMsacUlgrYrnDF5DOuV4QPeVk6v9sG8 sPtDhWLYOkq/NEUWBRk1hlVb53jkptuE+/xMh3yh5NC/l0XcDn8FB75/G7h/FQWG4kPL ZE7LXww+GFS0OuzCWMthe2OC/KdPT61YF3Ks75TSSKU7jnRUbCs2YocwaJY19V+lz2M0 dZGg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787250370; x=1787855170; h=mime-version:user-agent:content-transfer-encoding:content-type :references:in-reply-to:date:cc:to:from:subject:message-id:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=bBdyTAiG5JcLvXihuDX4B1484e1I/74jJ2owtdoOkdU=; b=Zz7QKODJYMFhH5nKEXhrP+bkwB7uHiB/WoeRSei4LJQjPSqqpUEQZxuIDE1VMQiwl0 xmOhUUV4VRkf90/Sgb+yDHGZb3/7/OsqborX5DTQzxdYlQ/R9zJYDv+gpQGhboRQYhfG yevHnrTxLI4U4VgcalOZcGam5/VJfVAFQ7EA7hlRBQRFyNEubQYZ+d/z6l0A30JGIMVo P+VaIQeeuoTrQlfIOpcqwm+k4AuE9a+xscTtcexBwQG1QVNUKkIU3pn8nFB7IOmUpWzH ss/Gov6zcixcI92wwIxKXW8b0hBBALYmkbfOSMxGeI45OJY0IOQ2C2Q4Zkv+sFLfu8VJ wRyA== X-Forwarded-Encrypted: i=1; AHgh+RpKWfhYBuf8CF+HmK/FZNIp5T/G28rGINsiuLe4HyubxR3IfMNhMEiEgcU6NzpL7n33/mJhBJVi2kbkX5Q=@vger.kernel.org X-Gm-Message-State: AFuF++kH/okmwOBsGKTHZO9XFdF0Yn5TewsSEVlbzLySyYXZwoTfbbH6 OPtQW8e9dQVw+sUBCVsqnD/1WPiP1SOCqgwPrAj6U6+4kK0Hxv/XdGrN X-Gm-Gg: AR+sD12FG2oaSkmcsDcn+/7aTke8gucRQnEWLWsy1qVmaAvE3hk0qB5zsn4Fu6a2bxa afjcAYHLQUUhgbt+syhVOPoz7LSkPayT63bBQfhVGS4GsmXMwV2GAbJWuS8MDbeWk8VsxaiMmtG NKw+h/7OXpzh72npArbJAaCdC3yHLEs5F27TIQ/x3nynW5yxHzm5s9s7Ubmk7JTDLVbgTHBnQEa Y/sUe0HdUVJIgV0OJoRX3TiuldBNS1flDlQ/RH2GXhqHXGOP1s6khrBBEpChdTTW/NOwa0ss2JX LzpqxyMXCHEoPirPtwFk4b8agzGmCcYTvxghdmYn6SqizJGYVJj/mY9H4MAgFJqzsTU+JXmRaBK nanyoOLS1zYwK746k5afA2UMiHwZ6PW7A7YnRS6WLVUx0w6fsEH644jPgdhdXZJX/3/gQOD2+xP /bWOiCCnXYgQwGVceQ0HzRh6MQ2xY54VT4kxnDo/7Uh2EqUI+L3+RkQ3+g+eeBcvM+DTu1J0/sk TfA9xg2f9WX6pBdEOSF0/QIUU1dn0Ojh0CqAZVxGJ+5EA== X-Received: by 2002:a17:903:2bcb:b0:2ca:e5c:7fcf with SMTP id d9443c01a7336-2d64adaa1a2mr12318115ad.3.1787250370136; Thu, 20 Aug 2026 11:26:10 -0700 (PDT) Received: from ?IPv6:2a03:83e0:115c:1:89bc:48d2:9457:6223? ([2620:10d:c090:500::6:c5ba]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-327bf1970b0sm19018150eec.29.2026.08.20.11.26.08 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 20 Aug 2026 11:26:09 -0700 (PDT) Message-ID: <502518ed7ac143e2d9e4f588ab33c5c7c1566b84.camel@gmail.com> Subject: Re: [PATCH bpf 2/2] selftests/bpf: Add reg-invariants test for speculative pointer arithmetic From: Eduard Zingerman To: Jiayuan Chen , bpf@vger.kernel.org Cc: Alexei Starovoitov , Daniel Borkmann , John Fastabend , Andrii Nakryiko , Kumar Kartikeya Dwivedi , Martin KaFai Lau , Song Liu , Yonghong Song , Jiri Olsa , Emil Tsalapatis , Ihor Solodrai , Shuah Khan , Paul Chaignon , Amery Hung , Shung-Hsi Yu , Daniel Wade , KaFai Wan , linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org Date: Thu, 20 Aug 2026 11:26:07 -0700 In-Reply-To: <20260819125840.286434-2-jiayuan.chen@linux.dev> References: <20260819125840.286434-1-jiayuan.chen@linux.dev> <20260819125840.286434-2-jiayuan.chen@linux.dev> Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable User-Agent: Evolution 3.60.2 (3.60.2-1.fc44) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 On Wed, 2026-08-19 at 20:58 +0800, Jiayuan Chen wrote: > An unprivileged socket filter does variable pointer arithmetic on a > PTR_TO_MAP_VALUE whose offset collapses to a constant. The Spectre-v1 > speculative path used to snapshot the pointer with a const offset and an > unbounded r32, which tripped reg_bounds_sanity_check() on the following > register move. >=20 > Mark the test __success_unpriv (the speculative path only runs > unprivileged) and flag it BPF_F_TEST_REG_INVARIANTS so the invariant > violation becomes a hard load failure. The unprivileged run fails without > the verifier fix and passes with it: >=20 > verifier_bounds/spec_ptr_alu_const_offset @unpriv:FAIL # without fix > verifier_bounds/spec_ptr_alu_const_offset @unpriv:OK # with fix >=20 > Signed-off-by: Jiayuan Chen > --- Tested-by: Eduard Zingerman ...