BPF List
 help / color / mirror / Atom feed
* [PATCH bpf v3 0/2] Compare stack frames in exact register states
@ 2026-09-19  0:43 Kumar Kartikeya Dwivedi
  2026-09-19  0:43 ` [PATCH bpf v3 1/2] bpf: Compare stack frames in regs_exact() Kumar Kartikeya Dwivedi
  2026-09-19  0:43 ` [PATCH bpf v3 2/2] selftests/bpf: Cover frame changes in bounded loops Kumar Kartikeya Dwivedi
  0 siblings, 2 replies; 6+ messages in thread
From: Kumar Kartikeya Dwivedi @ 2026-09-19  0:43 UTC (permalink / raw)
  To: bpf
  Cc: Alexei Starovoitov, Andrii Nakryiko, Daniel Borkmann,
	Eduard Zingerman, Emil Tsalapatis, Nicholas Carlini, kkd,
	kernel-team

regs_exact() compares register values and their ID relationships, but it
does not compare frameno. regsafe() checks frameno for ordinary
PTR_TO_STACK comparisons, while its EXACT path returns through regs_exact()
before reaching that check. Infinite-loop detection can therefore mistake
pointers to the same offset in different stack frames for the same pointer
and reject a finite loop.

Move frameno into bpf_reg_state's type-specific metadata union so the
existing regs_exact() prefix comparison covers it. This avoids a separate
PTR_TO_STACK case and keeps the structure at 80 bytes. Adjust the
states_maybe_looping() comparison boundary for the new layout.

The selftest keeps a stack pointer live in a register across a loop
whose only change at the header is the pointer's frame number. On the
unfixed tree, the program is rejected with "infinite loop detected". With
the fix, it loads and returns the expected value.

Changelog:
----------
v2 -> v3
v2: https://lore.kernel.org/bpf/20260918011313.3053497-1-memxor@gmail.com

 * Rebase on bpf/master.
 * Drop the redundant spilled-pointer test, since existing tests already
   cover the stacksafe() -> regsafe() path. (Eduard)
 * Place asm labels on their own line in the selftest. (Eduard)
 * Collect Acked-by and Tested-by tags.

v1 -> v2
v1: https://lore.kernel.org/bpf/20260914161340.3419141-1-memxor@gmail.com

 * Rebase on bpf/master.
 * Move frameno into the type-specific metadata union so regs_exact()'s
   existing prefix comparison covers it without growing bpf_reg_state.

Kumar Kartikeya Dwivedi (2):
  bpf: Compare stack frames in regs_exact()
  selftests/bpf: Cover frame changes in bounded loops

 include/linux/bpf_verifier.h                  | 16 ++++-----
 kernel/bpf/states.c                           |  7 ++--
 .../selftests/bpf/progs/verifier_loops1.c     | 36 +++++++++++++++++++
 3 files changed, 46 insertions(+), 13 deletions(-)


base-commit: b4e875d397da451fb4e9c573ff4b86db53caba05
-- 
2.53.0


^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-09-19  1:42 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-19  0:43 [PATCH bpf v3 0/2] Compare stack frames in exact register states Kumar Kartikeya Dwivedi
2026-09-19  0:43 ` [PATCH bpf v3 1/2] bpf: Compare stack frames in regs_exact() Kumar Kartikeya Dwivedi
2026-09-19  1:08   ` sashiko-bot
2026-09-19  1:26     ` Kumar Kartikeya Dwivedi
2026-09-19  0:43 ` [PATCH bpf v3 2/2] selftests/bpf: Cover frame changes in bounded loops Kumar Kartikeya Dwivedi
2026-09-19  1:42   ` bot+bpf-ci

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox