BPF List
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Eduard Zingerman" <eddyz87@gmail.com>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf-next 08/36] bpf: add cnum64_intersect_linear()
Date: Sat, 26 Sep 2026 14:34:02 +0000	[thread overview]
Message-ID: <20260926143403.113531F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260926-scev-minimal-rebase-v1-8-c8e5ab5ba79f@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] bpf: cnum64_intersect_linear over-expands intervals that wrap the signed boundary
--

commit 07e53bba30487c590757dc2ec233d2811a607b9a
Author: Eduard Zingerman <eddyz87@gmail.com>

bpf: add cnum64_intersect_linear()

This commit introduces cnum64_intersect_linear() to intersect a cnum64
interval with integers congruent to 'base' modulo 'step'. It tightens the
interval using signed bounds to keep residues consistent. This is a building
block for tracking scalar registers with values known to lie on a line.

> diff --git a/kernel/bpf/cnum.c b/kernel/bpf/cnum.c
> index 86142cb2aee5f..2bff2c7e0cdf5 100644
> --- a/kernel/bpf/cnum.c
> +++ b/kernel/bpf/cnum.c
[ ... ]
> @@ -118,3 +119,38 @@ struct cnum64 cnum64_cnum32_intersect(struct cnum64 a, struct cnum32 b)
>  	}
>  	return t;
>  }
> +
> +/* Intersect 'in' with the set of integers defined by equation 'base + step * k'. */
> +struct cnum64 cnum64_intersect_linear(struct cnum64 in, u16 base, u16 step)
> +{
> +	s64 smin = cnum64_smin(in);
> +	s64 smax = cnum64_smax(in);
> +	s64 lo, hi;
> +	u16 d;
> +
> +	if (step <= 1 || cnum64_is_empty(in))
> +		return in;
> +	/*
> +	 * Round smin up to the next value congruent to 'base' modulo 'step',
> +	 * i.e. increase smin by d = (base - smin) mod step:
> +	 *
> +	 *                 |<---- d ---->|
> +	 *     |-----------|=============|...
> +	 * base+step*k    smin       base+step*(k+1)
> +	 */
> +	d = imod(base - imod(smin, step), step);
> +	if ((u64)smax - (u64)smin < d)
> +		return CNUM64_EMPTY;
> +	lo = smin + d;
> +	/*
> +	 * Round smax down to the previous value congruent to 'base' modulo 'step',
> +	 * i.e. decrease smax by d = (smax - base) mod step:
> +	 *
> +	 *     |<--- d --->|
> +	 *  ...|===========|-------------|
> +	 * base+step*k    smax       base+step*(k+1)
> +	 */
> +	d = imod(imod(smax, step) - base, step);
> +	hi = smax - d;
> +	return cnum64_from_srange(lo, hi);

[Severity: Medium]
Does this code improperly expand intervals that wrap the signed boundary?

For such intervals, cnum64_smin() returns S64_MIN and cnum64_smax() returns
S64_MAX. The function then calculates 'lo' near S64_MIN and 'hi' near
S64_MAX, returning cnum64_from_srange(lo, hi).

This replaces a potentially small wrapping interval with a massive contiguous
range spanning nearly the entire 64-bit space, violating the intersection
property (A ∩ B ⊆ A). While this over-approximation is sound, it could cause
the verifier to lose precision and falsely reject valid BPF programs.

> +}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260926-scev-minimal-rebase-v1-0-c8e5ab5ba79f@gmail.com?part=8

  reply	other threads:[~2026-09-26 14:34 UTC|newest]

Thread overview: 80+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-26 14:19 [PATCH bpf-next 00/36] bpf: use scalar evolution to widen bounded loops Eduard Zingerman
2026-09-26 14:19 ` [PATCH bpf-next 01/36] bpf: track may_write flags in liveness Eduard Zingerman
2026-09-26 15:51   ` Alexei Starovoitov
2026-09-27  8:43     ` Eduard Zingerman
2026-09-27 20:42   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 02/36] bpf: summarize may write stack slots in insn_aux_data Eduard Zingerman
2026-09-26 15:51   ` Alexei Starovoitov
2026-09-29 20:12     ` Eduard Zingerman
2026-09-27 20:42   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 03/36] bpf: summarize live " Eduard Zingerman
2026-09-26 14:33   ` sashiko-bot
2026-09-27 20:26   ` bot+bpf-ci
2026-09-29 18:16     ` Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 04/36] bpf: summarize regs that may hold a frame pointer " Eduard Zingerman
2026-09-27 20:27   ` bot+bpf-ci
2026-09-29 20:21     ` Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 05/36] bpf: record write effects for atomic operations in liveness.c Eduard Zingerman
2026-09-27 20:27   ` bot+bpf-ci
2026-09-29 20:26     ` Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 06/36] bpf: add tnum_alignment() Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 07/36] bpf: add cnum{32,64}_union() Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 08/36] bpf: add cnum64_intersect_linear() Eduard Zingerman
2026-09-26 14:34   ` sashiko-bot [this message]
2026-09-29 21:46     ` Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 09/36] bpf: add bpf_set_reg_range() Eduard Zingerman
2026-09-26 14:36   ` sashiko-bot
2026-09-26 14:20 ` [PATCH bpf-next 10/36] bpf: add bpf_mark_reg_known_scalar() Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 11/36] bpf: add bpf_reg_union() Eduard Zingerman
2026-09-27 20:42   ` bot+bpf-ci
2026-09-30  0:09     ` Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 12/36] bpf: expose comparison opcode transformations Eduard Zingerman
2026-09-27 20:26   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 13/36] bpf: allow subrange relations for PTR_TO_STACK in regsafe() Eduard Zingerman
2026-09-27 20:42   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 14/36] bpf: representation for intervals with steps Eduard Zingerman
2026-09-26 14:35   ` sashiko-bot
2026-09-26 14:20 ` [PATCH bpf-next 15/36] bpf: varying offset access support for PTR_TO_BTF_ID pointers Eduard Zingerman
2026-09-26 14:37   ` sashiko-bot
2026-09-27 20:42   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 16/36] bpf: save DFS postorder numbers for program instructions Eduard Zingerman
2026-09-26 14:31   ` sashiko-bot
2026-09-26 14:20 ` [PATCH bpf-next 17/36] bpf: move the live-register and SCC printout to a standalone function Eduard Zingerman
2026-09-27 20:26   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 18/36] bpf: compute immediate dominators Eduard Zingerman
2026-09-26 15:54   ` Alexei Starovoitov
2026-09-27 20:42   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 19/36] bpf: compute loop hierarchy Eduard Zingerman
2026-09-27 20:43   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 20/36] bpf: add a min-heap for ordered analysis worklists Eduard Zingerman
2026-09-27 20:26   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 21/36] bpf: record basic-block ends in insn_aux_data Eduard Zingerman
2026-09-27 20:26   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 22/36] bpf: add bpf_split_cur_state() Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 23/36] bpf: allow precision backtracking between overlapping checkpoints Eduard Zingerman
2026-09-27 20:27   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 24/36] bpf: compute scalar evolution expressions for loops Eduard Zingerman
2026-09-26 14:38   ` sashiko-bot
2026-09-27 20:43   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 25/36] bpf: use SCEV to widen bounded loops Eduard Zingerman
2026-09-26 14:42   ` sashiko-bot
2026-09-27 20:43   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 26/36] bpf: avoid widening registers that hinder exact stack-slot tracking Eduard Zingerman
2026-09-26 14:46   ` sashiko-bot
2026-09-27 20:43   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 27/36] selftests/bpf: __msg_next tag for matching messages on consecutive lines Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 28/36] selftests/bpf: test for stack-pointer subrange pruning Eduard Zingerman
2026-09-26 14:32   ` sashiko-bot
2026-09-27 20:26   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 29/36] selftests/bpf: tests for may_write stack-liveness tracking Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 30/36] selftests/bpf: tests for may_def marks of atomic RMW operations Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 31/36] selftests/bpf: tests for register base/step arithmetic Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 32/36] selftests/bpf: tests for register base/step state pruning Eduard Zingerman
2026-09-27 20:27   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 33/36] selftests/bpf: tests for varying offset access to PTR_TO_BTF_ID Eduard Zingerman
2026-09-27 20:42   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 34/36] selftests/bpf: tests for loop hierarchy computation Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 35/36] selftests/bpf: tests for immediate dominator computation Eduard Zingerman
2026-09-27 20:27   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 36/36] selftests/bpf: cover SCEV analysis and loop widening Eduard Zingerman
2026-09-27 20:42   ` bot+bpf-ci

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260926143403.113531F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=eddyz87@gmail.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox