BPF List
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Amery Hung" <ameryhung@gmail.com>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf-next v2 08/11] bpf: Check subprog dynptr arguments in the common path
Date: Mon, 28 Sep 2026 18:28:22 +0000	[thread overview]
Message-ID: <20260928182823.0EFEF1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260928181414.644158-9-ameryhung@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Low] bpf: dead code and unreachable diagnostic in process_dynptr_func()
--

commit a02951e0de8834e87c650bf3681861699a204241
Author: Amery Hung <ameryhung@gmail.com>

bpf: Check subprog dynptr arguments in the common path

This commit routes subprog dynptr arguments through check_func_arg() to ensure
register types, offsets, and dynptr states are validated in a common order. It
also updates a related selftest to maintain consistent failure states across
different compilers.

> diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
> index efb20e50c974a..075002f6a59fe 100644
> --- a/kernel/bpf/verifier.c
> +++ b/kernel/bpf/verifier.c
> @@ -10883,7 +10883,7 @@ static int btf_check_func_arg_match(struct bpf_verifier_env *env, int subprog,
>  		nslots = btf_arg_slots(t);
>  
>  		if (arg_type == ARG_SCALAR || arg_type == ARG_IGNORE ||
> -		    arg_type == ARG_PTR_TO_CTX ||
> +		    arg_type == ARG_PTR_TO_CTX || arg_type == ARG_PTR_TO_DYNPTR ||
>  		    base_type(arg_type) == ARG_PTR_TO_ARENA) {

[Severity: Low]
Does routing this through check_func_arg() render the register type validation
in process_dynptr_func() redundant and unreachable?

Since check_func_arg() calls check_reg_type() before process_dynptr_func(),
the requirement for PTR_TO_STACK or CONST_PTR_TO_DYNPTR is already enforced
earlier in the flow.

This makes the custom error block in process_dynptr_func() dead code:

kernel/bpf/verifier.c:process_dynptr_func() {
	...
	if (reg->type != PTR_TO_STACK && reg->type != CONST_PTR_TO_DYNPTR) {
		verbose(env,
			"%s expected pointer to stack or const struct bpf_dynptr\n",
			reg_arg_name(env, argno));
		...
		return -EINVAL;
	}
	...
}

The selftest updates in this patch seem to confirm this, as the expected
error message is changed from this custom diagnostic to the generic one
produced by check_reg_type().

>  			ret = check_func_arg(env, arg, slot, 0, &meta, env->insn_idx);
>  			if (ret)
> @@ -10912,15 +10912,6 @@ static int btf_check_func_arg_match(struct bpf_verifier_env *env, int subprog,
>  					reg_arg_name(env, argno));
>  				return -EINVAL;
>  			}
> -		} else if (arg_type == ARG_PTR_TO_DYNPTR) {
> -			ret = check_func_arg_reg_off(env, reg, argno, ARG_PTR_TO_DYNPTR);
> -			if (ret)
> -				return ret;
> -
> -			ret = process_dynptr_func(env, reg, argno, env->insn_idx,
> -						  arg_type, &meta);
> -			if (ret)
> -				return ret;
>  		} else if (base_type(arg_type) == ARG_PTR_TO_BTF_ID) {
>  			int err;

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260928181414.644158-1-ameryhung@gmail.com?part=8

  reply	other threads:[~2026-09-28 18:28 UTC|newest]

Thread overview: 14+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-28 18:14 [PATCH bpf-next v2 00/11] Unify subprog argument checks Amery Hung
2026-09-28 18:14 ` [PATCH bpf-next v2 01/11] bpf: Fix kfunc BTF parameter lookups after wide arguments Amery Hung
2026-09-28 18:14 ` [PATCH bpf-next v2 02/11] bpf: Identify subprog calls in argument metadata Amery Hung
2026-09-28 18:14 ` [PATCH bpf-next v2 03/11] bpf: Build argument prototypes for subprog calls Amery Hung
2026-09-28 18:14 ` [PATCH bpf-next v2 04/11] bpf: Check subprog scalar arguments in the common path Amery Hung
2026-09-28 18:14 ` [PATCH bpf-next v2 05/11] bpf: Check global subprog untrusted " Amery Hung
2026-09-28 18:14 ` [PATCH bpf-next v2 06/11] bpf: Check subprog context " Amery Hung
2026-09-28 18:14 ` [PATCH bpf-next v2 07/11] bpf: Check subprog arena " Amery Hung
2026-09-28 18:14 ` [PATCH bpf-next v2 08/11] bpf: Check subprog dynptr " Amery Hung
2026-09-28 18:28   ` sashiko-bot [this message]
2026-09-28 18:33     ` Amery Hung
2026-09-28 18:14 ` [PATCH bpf-next v2 09/11] bpf: Check global subprog BTF-ID " Amery Hung
2026-09-28 18:14 ` [PATCH bpf-next v2 10/11] bpf: Check global subprog memory " Amery Hung
2026-09-28 18:14 ` [PATCH bpf-next v2 11/11] bpf: Check all subprog " Amery Hung

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260928182823.0EFEF1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=ameryhung@gmail.com \
    --cc=bpf@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox