From: Eduard Zingerman <eddyz87@gmail.com>
To: bpf@vger.kernel.org, ast@kernel.org, andrii@kernel.org
Cc: daniel@iogearbox.net, martin.lau@linux.dev, kernel-team@fb.com,
yonghong.song@linux.dev, eddyz87@gmail.com, memxor@gmail.com
Subject: [PATCH bpf-next 02/36] bpf: summarize may write stack slots in insn_aux_data
Date: Sat, 26 Sep 2026 07:20:00 -0700 [thread overview]
Message-ID: <20260926-scev-minimal-rebase-v1-2-c8e5ab5ba79f@gmail.com> (raw)
In-Reply-To: <20260926-scev-minimal-rebase-v1-0-c8e5ab5ba79f@gmail.com>
SCEV needs may-write information to invalidate stack expressions after
indirect writes. Liveness tracks this per function instance,
but SCEV is not callchain-sensitive and needs a summary across
calling contexts.
For each instruction, union the current-frame may_write masks from all
analyzed instances. Represent 8-byte slots as a summary of constituent
halves. Store the summary in insn_aux_data and expose it via a helper.
Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
---
include/linux/bpf_verifier.h | 6 ++++++
kernel/bpf/liveness.c | 41 +++++++++++++++++++++++++++++++++++++++++
2 files changed, 47 insertions(+)
diff --git a/include/linux/bpf_verifier.h b/include/linux/bpf_verifier.h
index c775bd757706..c6d617581e84 100644
--- a/include/linux/bpf_verifier.h
+++ b/include/linux/bpf_verifier.h
@@ -662,6 +662,11 @@ struct bpf_insn_aux_data {
};
struct btf_struct_meta *kptr_struct_meta;
u64 map_key_state; /* constant (32 bit) key tracking for maps */
+ /*
+ * Per-instruction summary of stack slots in the current frame
+ * that this instruction may write to.
+ */
+ DECLARE_BITMAP(may_write_mask, MAX_BPF_STACK_SLOTS);
int ctx_field_size; /* the ctx field size for load insn, maybe 0 */
u32 seen; /* this insn was processed by the verifier at env->pass_cnt */
bool nospec; /* do not execute this instruction speculatively */
@@ -1728,6 +1733,7 @@ int bpf_compute_subprog_arg_access(struct bpf_verifier_env *env);
int bpf_stack_liveness_init(struct bpf_verifier_env *env);
void bpf_stack_liveness_free(struct bpf_verifier_env *env);
int bpf_live_stack_query_init(struct bpf_verifier_env *env, struct bpf_verifier_state *st);
+const unsigned long *bpf_may_write_mask(struct bpf_verifier_env *env, u32 insn_idx);
bool bpf_stack_slot_alive(struct bpf_verifier_env *env, u32 frameno, u32 spi);
int bpf_compute_live_registers(struct bpf_verifier_env *env);
diff --git a/kernel/bpf/liveness.c b/kernel/bpf/liveness.c
index cc3ad75aa1e2..c871744ca5a8 100644
--- a/kernel/bpf/liveness.c
+++ b/kernel/bpf/liveness.c
@@ -718,6 +718,45 @@ static int cmp_instances(const void *pa, const void *pb)
return 0;
}
+/* OR the 8-byte slots touched by a half-slot (4-byte) mask into @slots. */
+static void half_spis_to_slots(unsigned long *slots, const unsigned long *mask, u32 nbits)
+{
+ u32 slot;
+
+ for (slot = 0; slot < MAX_BPF_STACK_SLOTS && slot * 2 + 1 < nbits; slot++)
+ if (test_bit(slot * 2, mask) || test_bit(slot * 2 + 1, mask))
+ __set_bit(slot, slots);
+}
+
+/*
+ * Precompute, for each instruction, the OR of may_write masks over its top
+ * frame across all func_instances reaching it, stash it in the insn_aux_data.
+ */
+static void compute_may_write_masks(struct bpf_verifier_env *env)
+{
+ struct bpf_insn_aux_data *aux = env->insn_aux_data;
+ struct bpf_liveness *liveness = env->liveness;
+ struct func_instance *instance;
+ struct frame_masks *fm;
+ u32 nbits;
+ int bkt, i;
+
+ hash_for_each(liveness->func_instances, bkt, instance, hl_node) {
+ fm = instance->frames[instance->depth];
+ if (!fm)
+ continue;
+ nbits = frame_mask_bits(fm);
+ for (i = 0; i < instance->insn_cnt; i++)
+ half_spis_to_slots(aux[instance->subprog_start + i].may_write_mask,
+ rel_mask(fm, i, FM_MAY_WRITE), nbits);
+ }
+}
+
+const unsigned long *bpf_may_write_mask(struct bpf_verifier_env *env, u32 insn_idx)
+{
+ return env->insn_aux_data[insn_idx].may_write_mask;
+}
+
/* print use/def slots for all instances ordered by callsite first, then by depth */
static int print_instances(struct bpf_verifier_env *env)
{
@@ -2352,6 +2391,8 @@ int bpf_compute_subprog_arg_access(struct bpf_verifier_env *env)
goto out;
}
+ compute_may_write_masks(env);
+
if (env->log.level & BPF_LOG_LEVEL2)
err = print_instances(env);
--
2.55.0
next prev parent reply other threads:[~2026-09-26 14:20 UTC|newest]
Thread overview: 80+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-26 14:19 [PATCH bpf-next 00/36] bpf: use scalar evolution to widen bounded loops Eduard Zingerman
2026-09-26 14:19 ` [PATCH bpf-next 01/36] bpf: track may_write flags in liveness Eduard Zingerman
2026-09-26 15:51 ` Alexei Starovoitov
2026-09-27 8:43 ` Eduard Zingerman
2026-09-27 20:42 ` bot+bpf-ci
2026-09-26 14:20 ` Eduard Zingerman [this message]
2026-09-26 15:51 ` [PATCH bpf-next 02/36] bpf: summarize may write stack slots in insn_aux_data Alexei Starovoitov
2026-09-29 20:12 ` Eduard Zingerman
2026-09-27 20:42 ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 03/36] bpf: summarize live " Eduard Zingerman
2026-09-26 14:33 ` sashiko-bot
2026-09-27 20:26 ` bot+bpf-ci
2026-09-29 18:16 ` Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 04/36] bpf: summarize regs that may hold a frame pointer " Eduard Zingerman
2026-09-27 20:27 ` bot+bpf-ci
2026-09-29 20:21 ` Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 05/36] bpf: record write effects for atomic operations in liveness.c Eduard Zingerman
2026-09-27 20:27 ` bot+bpf-ci
2026-09-29 20:26 ` Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 06/36] bpf: add tnum_alignment() Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 07/36] bpf: add cnum{32,64}_union() Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 08/36] bpf: add cnum64_intersect_linear() Eduard Zingerman
2026-09-26 14:34 ` sashiko-bot
2026-09-29 21:46 ` Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 09/36] bpf: add bpf_set_reg_range() Eduard Zingerman
2026-09-26 14:36 ` sashiko-bot
2026-09-26 14:20 ` [PATCH bpf-next 10/36] bpf: add bpf_mark_reg_known_scalar() Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 11/36] bpf: add bpf_reg_union() Eduard Zingerman
2026-09-27 20:42 ` bot+bpf-ci
2026-09-30 0:09 ` Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 12/36] bpf: expose comparison opcode transformations Eduard Zingerman
2026-09-27 20:26 ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 13/36] bpf: allow subrange relations for PTR_TO_STACK in regsafe() Eduard Zingerman
2026-09-27 20:42 ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 14/36] bpf: representation for intervals with steps Eduard Zingerman
2026-09-26 14:35 ` sashiko-bot
2026-09-26 14:20 ` [PATCH bpf-next 15/36] bpf: varying offset access support for PTR_TO_BTF_ID pointers Eduard Zingerman
2026-09-26 14:37 ` sashiko-bot
2026-09-27 20:42 ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 16/36] bpf: save DFS postorder numbers for program instructions Eduard Zingerman
2026-09-26 14:31 ` sashiko-bot
2026-09-26 14:20 ` [PATCH bpf-next 17/36] bpf: move the live-register and SCC printout to a standalone function Eduard Zingerman
2026-09-27 20:26 ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 18/36] bpf: compute immediate dominators Eduard Zingerman
2026-09-26 15:54 ` Alexei Starovoitov
2026-09-27 20:42 ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 19/36] bpf: compute loop hierarchy Eduard Zingerman
2026-09-27 20:43 ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 20/36] bpf: add a min-heap for ordered analysis worklists Eduard Zingerman
2026-09-27 20:26 ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 21/36] bpf: record basic-block ends in insn_aux_data Eduard Zingerman
2026-09-27 20:26 ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 22/36] bpf: add bpf_split_cur_state() Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 23/36] bpf: allow precision backtracking between overlapping checkpoints Eduard Zingerman
2026-09-27 20:27 ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 24/36] bpf: compute scalar evolution expressions for loops Eduard Zingerman
2026-09-26 14:38 ` sashiko-bot
2026-09-27 20:43 ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 25/36] bpf: use SCEV to widen bounded loops Eduard Zingerman
2026-09-26 14:42 ` sashiko-bot
2026-09-27 20:43 ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 26/36] bpf: avoid widening registers that hinder exact stack-slot tracking Eduard Zingerman
2026-09-26 14:46 ` sashiko-bot
2026-09-27 20:43 ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 27/36] selftests/bpf: __msg_next tag for matching messages on consecutive lines Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 28/36] selftests/bpf: test for stack-pointer subrange pruning Eduard Zingerman
2026-09-26 14:32 ` sashiko-bot
2026-09-27 20:26 ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 29/36] selftests/bpf: tests for may_write stack-liveness tracking Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 30/36] selftests/bpf: tests for may_def marks of atomic RMW operations Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 31/36] selftests/bpf: tests for register base/step arithmetic Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 32/36] selftests/bpf: tests for register base/step state pruning Eduard Zingerman
2026-09-27 20:27 ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 33/36] selftests/bpf: tests for varying offset access to PTR_TO_BTF_ID Eduard Zingerman
2026-09-27 20:42 ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 34/36] selftests/bpf: tests for loop hierarchy computation Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 35/36] selftests/bpf: tests for immediate dominator computation Eduard Zingerman
2026-09-27 20:27 ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 36/36] selftests/bpf: cover SCEV analysis and loop widening Eduard Zingerman
2026-09-27 20:42 ` bot+bpf-ci
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260926-scev-minimal-rebase-v1-2-c8e5ab5ba79f@gmail.com \
--to=eddyz87@gmail.com \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=kernel-team@fb.com \
--cc=martin.lau@linux.dev \
--cc=memxor@gmail.com \
--cc=yonghong.song@linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox