BPF List
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Alexei Starovoitov" <alexei.starovoitov@gmail.com>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf-next v2 02/15] selftests/bpf: Add tests for ALU on pointers with CAP_PERFMON
Date: Fri, 02 Oct 2026 13:08:03 +0000	[thread overview]
Message-ID: <20261002130803.A0FFA1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20261002124714.180012-3-alexei.starovoitov@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] bpf/selftests: test logic fails to verify ^= and *= on pointers
--

commit f742d8e4562c4f3d08b13ad422c226ac60b38d25
Author: Alexei Starovoitov <ast@kernel.org>

selftests/bpf: Add tests for ALU on pointers with CAP_PERFMON

This commit adds BPF selftests to check that various ALU operations
(&=, |=, ^=, >>=, *=) on a pointer to a map value properly produce a scalar
or are rejected as expected depending on capabilities.

> diff --git a/tools/testing/selftests/bpf/progs/verifier_value_illegal_alu.c b/tools/testing/selftests/bpf/progs/verifier_value_illegal_alu.c
> index 9f669cf85c593..31663338866d3 100644
> --- a/tools/testing/selftests/bpf/progs/verifier_value_illegal_alu.c
> +++ b/tools/testing/selftests/bpf/progs/verifier_value_illegal_alu.c
> @@ -165,6 +165,171 @@ __naked void map_ptr_illegal_alu_op(void)
>  	: __clobber_all);
>  }
>  
> +SEC("socket")
> +__description("tag in the low bit of a pointer, and, shift")
> +__success __retval(0)
> +__failure_unpriv __msg_unpriv("R1 bitwise operator &= on pointer")
> +__naked void ptr_tag_and_shift(void)
> +{
> +	asm volatile ("					\
> +	r2 = r10;					\
> +	r2 += -8;					\
> +	r1 = 0;						\
> +	*(u64*)(r2 + 0) = r1;				\
> +	r1 = %[map_hash_48b] ll;			\
> +	call %[bpf_map_lookup_elem];			\
> +	if r0 == 0 goto l0_%=;				\
> +	r1 = r0;					\
> +	r1 &= 1;					\
> +	r2 = r0;					\
> +	r2 >>= 1;					\
> +	r3 = r0;					\
> +	r3 |= 1;					\
> +	r3 ^= 1;					\

[Severity: Medium]
Does this sequence correctly verify the ^= operation on a pointer?

The preceding |= operation converts the pointer in r3 to a scalar, which
means the ^= operation is subsequently performed on a scalar rather than a
pointer.

Additionally, since this program places multiple unprivileged operations
sequentially, wouldn't the verifier abort at the first failure (r1 &= 1),
leaving the unprivileged rejection of the subsequent operations (>>=, |=, ^=)
completely untested?

[ ... ]

> +SEC("socket")
> +__description("number op= pointer")
> +__success __retval(0)
> +__failure_unpriv __msg_unpriv("R1 pointer arithmetic with *= operator")
> +__naked void number_mul_ptr(void)
> +{
> +	asm volatile ("					\
> +	r2 = r10;					\
> +	r2 += -8;					\
> +	r1 = 0;						\
> +	*(u64*)(r2 + 0) = r1;				\
> +	r1 = %[map_hash_48b] ll;			\
> +	call %[bpf_map_lookup_elem];			\
> +	if r0 == 0 goto l0_%=;				\
> +	r1 = 7;						\
> +	r1 *= r0;					\

[Severity: Medium]
Does this actually test the verifier's handling of pointer *= scalar?

The multiplication is applied to a scalar destination (r1) with a pointer
source (r0). Would it be more accurate to test if applying *= to a pointer
destination correctly downgrades the pointer to a scalar?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261002124714.180012-1-alexei.starovoitov@gmail.com?part=2

  reply	other threads:[~2026-10-02 13:08 UTC|newest]

Thread overview: 23+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-02 12:46 [PATCH bpf-next v2 00/15] bpf: Support programs compiled by rust-bpf Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 01/15] bpf: Allow bitwise ops, shifts and mul/div on pointers with CAP_PERFMON Alexei Starovoitov
2026-10-02 13:49   ` bot+bpf-ci
2026-10-02 12:47 ` [PATCH bpf-next v2 02/15] selftests/bpf: Add tests for ALU " Alexei Starovoitov
2026-10-02 13:08   ` sashiko-bot [this message]
2026-10-03 11:48     ` Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 03/15] bpf: Treat load and store through a number as arena access Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 04/15] selftests/bpf: Add tests for arena access through numbers Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 05/15] bpf: Allow names of Rust types and functions in BTF Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 06/15] selftests/bpf: Add tests for " Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 07/15] bpf: Allow arguments without names in static " Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 08/15] selftests/bpf: Add test for arguments without names in static functions Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 09/15] bpf: Allow a variable in DATASEC that is smaller than its type Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 10/15] bpftool: Skip pieces of variables in DATASEC Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 11/15] selftests/bpf: Add tests for a variable that is smaller than its type Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 12/15] libbpf: Keep global data in arena when the object has .arena.data Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 13/15] libbpf: Keep format strings of bpf_printk() in .rodata.str Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 14/15] selftests/bpf: Add test for global data in arena Alexei Starovoitov
2026-10-02 13:49   ` bot+bpf-ci
2026-10-02 12:47 ` [PATCH bpf-next v2 15/15] selftests/bpf: Add test for global data of a program in Rust Alexei Starovoitov
2026-10-03  1:33   ` sashiko-bot
2026-10-03 11:47     ` Alexei Starovoitov
2026-10-03 14:20 ` [PATCH bpf-next v2 00/15] bpf: Support programs compiled by rust-bpf patchwork-bot+netdevbpf

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261002130803.A0FFA1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=alexei.starovoitov@gmail.com \
    --cc=bpf@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox