BPF List
 help / color / mirror / Atom feed
* [PATCH bpf-next v2 0/5] bpf: infer zext_dst based on static register liveness analysis
@ 2026-08-01  1:09 Eduard Zingerman
  2026-08-01  1:09 ` [PATCH bpf-next v2 1/5] bpf: do not print a newline after disassembly in bpf_verbose_insn() Eduard Zingerman
                   ` (4 more replies)
  0 siblings, 5 replies; 13+ messages in thread
From: Eduard Zingerman @ 2026-08-01  1:09 UTC (permalink / raw)
  To: bpf, ast, andrii
  Cc: daniel, martin.lau, kernel-team, yonghong.song, eddyz87, memxor,
	iii, gimm78064

Min-gyu Kim reported a bug in 32-bit operations zero extension
handling [1]. The bug was introduced by the commit [2].
The tl;dr of the bug is that the verifier does not carry zero
extension marks across pruning points. The detailed mechanism is
described in patch #3.

Fix this by reworking zero extension logic to avoid main-path based
subreg_def tracking, and instead extend the live registers analysis to
track upper register halves' liveness.

As noted in the commit message for patch #3:

  There is one notable drop in precision: whenever a BPF subprogram is
  called, all 64 bits of parameter registers are presumed to be used.
  The assumption is that such a drop in precision would not inflict
  noticeable performance penalty.

Ilya, could you please help with testing this conjecture?
Min-gyu, could you please test the proposed fix against your
reproducer?

Side note:
Patch #1 is a small refactoring for disasm.c, as patch #3 adds a new
location where bpf_verbose_insn() is called and there as well I have
to wrangle with the newline added by the disasm code.

[1] https://lore.kernel.org/bpf/CAGKGUv=sOuqQtA1Ub-5JXfA4FPosJFYKAQE4B79cK+P1erxqtg@mail.gmail.com/
[2] commit 107e16979905 ("bpf: disable and remove registers chain based liveness")

Changelog:
v1 -> v2:
- fixed BPF_JMP32 handling, these no longer for zero extension (sashiko)
- removed dead code in print_insn_for_graph() (bot+bpf-ci)
- reworked bpf_is_reg64() to drop dead code (sashiko, bot+bpf-ci)

v1: https://lore.kernel.org/bpf/20260731-static-zext-v1-0-98a4dc73e94b@gmail.com/T/

---
Eduard Zingerman (5):
      bpf: do not print a newline after disassembly in bpf_verbose_insn()
      bpf: track upper 32-bit register halves' liveness in compute_live_registers()
      bpf: infer zext_dst based on static register liveness analysis
      bpf: simplify the bpf_is_reg64()
      selftests/bpf: verify zext_dst annotations for various instructions

 include/linux/bpf_verifier.h                      |   9 +-
 kernel/bpf/backtrack.c                            |   1 +
 kernel/bpf/disasm.c                               |  68 ++---
 kernel/bpf/fixups.c                               |  55 +++-
 kernel/bpf/liveness.c                             | 144 +++++++---
 kernel/bpf/verifier.c                             | 201 +-------------
 tools/bpf/bpftool/xlated_dumper.c                 |  19 +-
 tools/testing/selftests/bpf/disasm_helpers.c      |   3 +-
 tools/testing/selftests/bpf/prog_tests/verifier.c |   2 +
 tools/testing/selftests/bpf/progs/verifier_zext.c | 315 ++++++++++++++++++++++
 10 files changed, 519 insertions(+), 298 deletions(-)
---
base-commit: fdec474c65fd35d5a6e1497ed50a9f98c07192f0
change-id: 20260731-static-zext-938cd128273c

^ permalink raw reply	[flat|nested] 13+ messages in thread

end of thread, other threads:[~2026-08-01  5:41 UTC | newest]

Thread overview: 13+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-01  1:09 [PATCH bpf-next v2 0/5] bpf: infer zext_dst based on static register liveness analysis Eduard Zingerman
2026-08-01  1:09 ` [PATCH bpf-next v2 1/5] bpf: do not print a newline after disassembly in bpf_verbose_insn() Eduard Zingerman
2026-08-01  1:09 ` [PATCH bpf-next v2 2/5] bpf: track upper 32-bit register halves' liveness in compute_live_registers() Eduard Zingerman
2026-08-01  1:35   ` sashiko-bot
2026-08-01  4:40     ` Eduard Zingerman
2026-08-01  1:09 ` [PATCH bpf-next v2 3/5] bpf: infer zext_dst based on static register liveness analysis Eduard Zingerman
2026-08-01  1:42   ` sashiko-bot
2026-08-01  5:41     ` Eduard Zingerman
2026-08-01  1:09 ` [PATCH bpf-next v2 4/5] bpf: simplify the bpf_is_reg64() Eduard Zingerman
2026-08-01  1:34   ` sashiko-bot
2026-08-01  1:09 ` [PATCH bpf-next v2 5/5] selftests/bpf: verify zext_dst annotations for various instructions Eduard Zingerman
2026-08-01  1:33   ` sashiko-bot
2026-08-01  4:24     ` Eduard Zingerman

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox