From: sashiko-bot@kernel.org
To: "Emil Tsalapatis" <emil@etsalapatis.com>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf 09/11] bpf: Track whether dynptr type is known
Date: Wed, 16 Sep 2026 05:22:28 +0000 [thread overview]
Message-ID: <20260916052228.CFE9F1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260916050830.8774-10-emil@etsalapatis.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] bpf: missing type_unknown check in stacksafe() allows unsafe pruning
--
commit 8f00e7cb51fcf9e4513f3c3e9be943021ba739cf
Author: Emil Tsalapatis <emil@etsalapatis.com>
bpf: Track whether dynptr type is known
This commit adds a type_unknown field to struct bpf_reg_state's dynptr
state to distinguish locally created dynptrs from global subprog arguments.
It updates the verifier to set this flag, preparing for proper invalidation
of unknown dynptrs in subsequent commits.
> diff --git a/include/linux/bpf_verifier.h b/include/linux/bpf_verifier.h
> index d5b4ab0bacd35..76aa724de1bcb 100644
> --- a/include/linux/bpf_verifier.h
> +++ b/include/linux/bpf_verifier.h
> @@ -71,6 +71,7 @@ struct bpf_reg_state {
> /* For dynptr stack slots */
> struct {
> enum bpf_dynptr_type type;
> + bool type_unknown;
[Severity: High]
Does this new field also need to be checked in stacksafe() when comparing
states?
Looking at stacksafe() in kernel/bpf/states.c, the STACK_DYNPTR case compares
type, first_slot, id, and parent_id, but it omits the new type_unknown field:
kernel/bpf/states.c:stacksafe() {
...
case STACK_DYNPTR:
old_reg = &old->stack[spi].spilled_ptr;
cur_reg = &cur->stack[spi].spilled_ptr;
if (old_reg->dynptr.type != cur_reg->dynptr.type ||
old_reg->dynptr.first_slot != cur_reg->dynptr.first_slot ||
!check_ids(old_reg->id, cur_reg->id, idmap) ||
!check_ids(old_reg->parent_id, cur_reg->parent_id, idmap))
return false;
break;
...
}
If a BPF program conditionally spills a locally created dynptr
(type_unknown=false) or an unknown argument dynptr (type_unknown=true) to
the same stack slot, could the verifier incorrectly treat the states as
equivalent and prune the unknown dynptr path? This might allow bypassing
the packet pointer invalidation logic when writing to unknown dynptrs,
potentially leading to a use-after-free of packet pointers.
> /* A dynptr is 16 bytes so it takes up 2 stack slots.
> * We need to track which slot is the first slot
> * to protect against cases where the user may try to
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260916050830.8774-1-emil@etsalapatis.com?part=9
next prev parent reply other threads:[~2026-09-16 5:22 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-16 5:08 [PATCH bpf 00/11] skb/arena bugfixes Emil Tsalapatis
2026-09-16 5:08 ` [PATCH bpf 01/11] bpf: Fix bounds check for skb-backed dynptrs Emil Tsalapatis
2026-09-16 11:52 ` Jiayuan Chen
2026-09-16 23:08 ` Jakub Kicinski
2026-09-16 5:08 ` [PATCH bpf 02/11] selftests/bpf: Test dynptr slices past end of skb Emil Tsalapatis
2026-09-16 5:18 ` sashiko-bot
2026-09-16 5:08 ` [PATCH bpf 03/11] bpf: Fix bpf_sock context code generation Emil Tsalapatis
2026-09-16 12:21 ` Jiayuan Chen
2026-09-16 5:08 ` [PATCH bpf 04/11] selftests/bpf: Add selftests for rx_queue_mapping context access Emil Tsalapatis
2026-09-16 5:08 ` [PATCH bpf 05/11] bpf: Reject pkt arguments in mutating subprogs Emil Tsalapatis
2026-09-16 5:57 ` Amery Hung
2026-09-16 5:58 ` Amery Hung
2026-09-16 18:41 ` Emil Tsalapatis
2026-09-16 19:26 ` Amery Hung
2026-09-16 5:08 ` [PATCH bpf 06/11] selftests/bpf: Test rejection of pkt args to " Emil Tsalapatis
2026-09-16 5:08 ` [PATCH bpf 07/11] bpf: Prevent variable arena/non-arena register contents Emil Tsalapatis
2026-09-16 5:08 ` [PATCH bpf 08/11] selftests/bpf: Test for mixed arena/nonarena code paths Emil Tsalapatis
2026-09-16 5:17 ` sashiko-bot
2026-09-16 5:08 ` [PATCH bpf 09/11] bpf: Track whether dynptr type is known Emil Tsalapatis
2026-09-16 5:22 ` sashiko-bot [this message]
2026-09-16 18:41 ` Emil Tsalapatis
2026-09-16 5:08 ` [PATCH bpf 10/11] bpf: Track skb memory invalidation by packet-backed dynptrs Emil Tsalapatis
2026-09-16 5:08 ` [PATCH bpf 11/11] selftests/bpf: Test dynptr slice invalidation on skb clobber Emil Tsalapatis
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260916052228.CFE9F1F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=emil@etsalapatis.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox