BPF List
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Eduard Zingerman" <eddyz87@gmail.com>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf-next 26/36] bpf: avoid widening registers that hinder exact stack-slot tracking
Date: Sat, 26 Sep 2026 14:46:40 +0000	[thread overview]
Message-ID: <20260926144640.C4AFE1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260926-scev-minimal-rebase-v1-26-c8e5ab5ba79f@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] bpf: bpf_needs_fixed_stack_off misses dynptr consumers, rejecting valid loops
--

commit a3ca958d64fafcbcf31deb9929c54958bdb72868
Author: Eduard Zingerman <eddyz87@gmail.com>

bpf: avoid widening registers that hinder exact stack-slot tracking

This commit adds logic to prevent loop-widening for registers that are
used as base addresses for stack access instructions that require exact
tracking (such as spills, fills, and calls constructing stack objects).

> diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
> index 9f56ffe09ebac..327bfc00da5f5 100644
> --- a/kernel/bpf/verifier.c
> +++ b/kernel/bpf/verifier.c
> @@ -14087,6 +14087,46 @@ static bool kfunc_spin_allowed(struct bpf_verifier_env *env, s32 func_id, s16 of
[ ... ]
> +bool bpf_needs_fixed_stack_off(struct bpf_verifier_env *env, int insn_idx)
> +{
> +	const struct bpf_insn *insn = &env->prog->insnsi[insn_idx];
> +	u32 *flags, btf_id;
> +
> +	if (bpf_helper_call(insn)) {
> +		return insn->imm == BPF_FUNC_dynptr_from_mem ||
> +		       insn->imm == BPF_FUNC_ringbuf_reserve_dynptr;
> +	}

[Severity: Medium]
Does this logic miss helper functions that consume dynptrs (like
BPF_FUNC_dynptr_read, BPF_FUNC_dynptr_write, or BPF_FUNC_ringbuf_submit_dynptr)?

Since process_dynptr_func() relies on dynptr_get_spi(), which in turn
requires constant stack offsets via stack_slot_obj_get_spi(), wouldn't
omitting these dynptr consumers here cause a regression? If the verifier
widens the loop variable used for a dynptr array index, the stack offset
becomes non-constant and the verifier will erroneously reject valid programs
that read or write stack-based dynptrs in a loop.

> +
> +	/* vmlinux kfuncs only */
> +	if (!bpf_pseudo_kfunc_call(insn) || insn->off != 0)
> +		return false;
> +	btf_id = insn->imm;
[ ... ]
> +	if (btf_id == special_kfunc_list[KF_bpf_dynptr_from_skb] ||
> +	    btf_id == special_kfunc_list[KF_bpf_dynptr_from_xdp] ||
> +	    btf_id == special_kfunc_list[KF_bpf_dynptr_from_skb_meta] ||
> +	    btf_id == special_kfunc_list[KF_bpf_dynptr_from_file])
> +		return true;

[Severity: Medium]
Similarly, does this miss kfuncs that consume or clone dynptrs (such as
KF_bpf_dynptr_clone and KF_bpf_dynptr_slice)?

If a loop variable is used to compute a dynptr address passed to these
kfuncs, the loop variable will be widened, leading to the same verification
regression when stack_slot_obj_get_spi() is called with a non-constant stack
offset.

> +
> +	return false;
> +}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260926-scev-minimal-rebase-v1-0-c8e5ab5ba79f@gmail.com?part=26

  reply	other threads:[~2026-09-26 14:46 UTC|newest]

Thread overview: 80+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-26 14:19 [PATCH bpf-next 00/36] bpf: use scalar evolution to widen bounded loops Eduard Zingerman
2026-09-26 14:19 ` [PATCH bpf-next 01/36] bpf: track may_write flags in liveness Eduard Zingerman
2026-09-26 15:51   ` Alexei Starovoitov
2026-09-27  8:43     ` Eduard Zingerman
2026-09-27 20:42   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 02/36] bpf: summarize may write stack slots in insn_aux_data Eduard Zingerman
2026-09-26 15:51   ` Alexei Starovoitov
2026-09-29 20:12     ` Eduard Zingerman
2026-09-27 20:42   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 03/36] bpf: summarize live " Eduard Zingerman
2026-09-26 14:33   ` sashiko-bot
2026-09-27 20:26   ` bot+bpf-ci
2026-09-29 18:16     ` Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 04/36] bpf: summarize regs that may hold a frame pointer " Eduard Zingerman
2026-09-27 20:27   ` bot+bpf-ci
2026-09-29 20:21     ` Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 05/36] bpf: record write effects for atomic operations in liveness.c Eduard Zingerman
2026-09-27 20:27   ` bot+bpf-ci
2026-09-29 20:26     ` Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 06/36] bpf: add tnum_alignment() Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 07/36] bpf: add cnum{32,64}_union() Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 08/36] bpf: add cnum64_intersect_linear() Eduard Zingerman
2026-09-26 14:34   ` sashiko-bot
2026-09-29 21:46     ` Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 09/36] bpf: add bpf_set_reg_range() Eduard Zingerman
2026-09-26 14:36   ` sashiko-bot
2026-09-26 14:20 ` [PATCH bpf-next 10/36] bpf: add bpf_mark_reg_known_scalar() Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 11/36] bpf: add bpf_reg_union() Eduard Zingerman
2026-09-27 20:42   ` bot+bpf-ci
2026-09-30  0:09     ` Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 12/36] bpf: expose comparison opcode transformations Eduard Zingerman
2026-09-27 20:26   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 13/36] bpf: allow subrange relations for PTR_TO_STACK in regsafe() Eduard Zingerman
2026-09-27 20:42   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 14/36] bpf: representation for intervals with steps Eduard Zingerman
2026-09-26 14:35   ` sashiko-bot
2026-09-26 14:20 ` [PATCH bpf-next 15/36] bpf: varying offset access support for PTR_TO_BTF_ID pointers Eduard Zingerman
2026-09-26 14:37   ` sashiko-bot
2026-09-27 20:42   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 16/36] bpf: save DFS postorder numbers for program instructions Eduard Zingerman
2026-09-26 14:31   ` sashiko-bot
2026-09-26 14:20 ` [PATCH bpf-next 17/36] bpf: move the live-register and SCC printout to a standalone function Eduard Zingerman
2026-09-27 20:26   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 18/36] bpf: compute immediate dominators Eduard Zingerman
2026-09-26 15:54   ` Alexei Starovoitov
2026-09-27 20:42   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 19/36] bpf: compute loop hierarchy Eduard Zingerman
2026-09-27 20:43   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 20/36] bpf: add a min-heap for ordered analysis worklists Eduard Zingerman
2026-09-27 20:26   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 21/36] bpf: record basic-block ends in insn_aux_data Eduard Zingerman
2026-09-27 20:26   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 22/36] bpf: add bpf_split_cur_state() Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 23/36] bpf: allow precision backtracking between overlapping checkpoints Eduard Zingerman
2026-09-27 20:27   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 24/36] bpf: compute scalar evolution expressions for loops Eduard Zingerman
2026-09-26 14:38   ` sashiko-bot
2026-09-27 20:43   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 25/36] bpf: use SCEV to widen bounded loops Eduard Zingerman
2026-09-26 14:42   ` sashiko-bot
2026-09-27 20:43   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 26/36] bpf: avoid widening registers that hinder exact stack-slot tracking Eduard Zingerman
2026-09-26 14:46   ` sashiko-bot [this message]
2026-09-27 20:43   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 27/36] selftests/bpf: __msg_next tag for matching messages on consecutive lines Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 28/36] selftests/bpf: test for stack-pointer subrange pruning Eduard Zingerman
2026-09-26 14:32   ` sashiko-bot
2026-09-27 20:26   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 29/36] selftests/bpf: tests for may_write stack-liveness tracking Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 30/36] selftests/bpf: tests for may_def marks of atomic RMW operations Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 31/36] selftests/bpf: tests for register base/step arithmetic Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 32/36] selftests/bpf: tests for register base/step state pruning Eduard Zingerman
2026-09-27 20:27   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 33/36] selftests/bpf: tests for varying offset access to PTR_TO_BTF_ID Eduard Zingerman
2026-09-27 20:42   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 34/36] selftests/bpf: tests for loop hierarchy computation Eduard Zingerman
2026-09-26 14:20 ` [PATCH bpf-next 35/36] selftests/bpf: tests for immediate dominator computation Eduard Zingerman
2026-09-27 20:27   ` bot+bpf-ci
2026-09-26 14:20 ` [PATCH bpf-next 36/36] selftests/bpf: cover SCEV analysis and loop widening Eduard Zingerman
2026-09-27 20:42   ` bot+bpf-ci

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260926144640.C4AFE1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=eddyz87@gmail.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox