From: sashiko-bot@kernel.org
To: "Alexei Starovoitov" <alexei.starovoitov@gmail.com>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf-next v2 02/15] selftests/bpf: Add tests for ALU on pointers with CAP_PERFMON
Date: Fri, 02 Oct 2026 13:08:03 +0000 [thread overview]
Message-ID: <20261002130803.A0FFA1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20261002124714.180012-3-alexei.starovoitov@gmail.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] bpf/selftests: test logic fails to verify ^= and *= on pointers
--
commit f742d8e4562c4f3d08b13ad422c226ac60b38d25
Author: Alexei Starovoitov <ast@kernel.org>
selftests/bpf: Add tests for ALU on pointers with CAP_PERFMON
This commit adds BPF selftests to check that various ALU operations
(&=, |=, ^=, >>=, *=) on a pointer to a map value properly produce a scalar
or are rejected as expected depending on capabilities.
> diff --git a/tools/testing/selftests/bpf/progs/verifier_value_illegal_alu.c b/tools/testing/selftests/bpf/progs/verifier_value_illegal_alu.c
> index 9f669cf85c593..31663338866d3 100644
> --- a/tools/testing/selftests/bpf/progs/verifier_value_illegal_alu.c
> +++ b/tools/testing/selftests/bpf/progs/verifier_value_illegal_alu.c
> @@ -165,6 +165,171 @@ __naked void map_ptr_illegal_alu_op(void)
> : __clobber_all);
> }
>
> +SEC("socket")
> +__description("tag in the low bit of a pointer, and, shift")
> +__success __retval(0)
> +__failure_unpriv __msg_unpriv("R1 bitwise operator &= on pointer")
> +__naked void ptr_tag_and_shift(void)
> +{
> + asm volatile (" \
> + r2 = r10; \
> + r2 += -8; \
> + r1 = 0; \
> + *(u64*)(r2 + 0) = r1; \
> + r1 = %[map_hash_48b] ll; \
> + call %[bpf_map_lookup_elem]; \
> + if r0 == 0 goto l0_%=; \
> + r1 = r0; \
> + r1 &= 1; \
> + r2 = r0; \
> + r2 >>= 1; \
> + r3 = r0; \
> + r3 |= 1; \
> + r3 ^= 1; \
[Severity: Medium]
Does this sequence correctly verify the ^= operation on a pointer?
The preceding |= operation converts the pointer in r3 to a scalar, which
means the ^= operation is subsequently performed on a scalar rather than a
pointer.
Additionally, since this program places multiple unprivileged operations
sequentially, wouldn't the verifier abort at the first failure (r1 &= 1),
leaving the unprivileged rejection of the subsequent operations (>>=, |=, ^=)
completely untested?
[ ... ]
> +SEC("socket")
> +__description("number op= pointer")
> +__success __retval(0)
> +__failure_unpriv __msg_unpriv("R1 pointer arithmetic with *= operator")
> +__naked void number_mul_ptr(void)
> +{
> + asm volatile (" \
> + r2 = r10; \
> + r2 += -8; \
> + r1 = 0; \
> + *(u64*)(r2 + 0) = r1; \
> + r1 = %[map_hash_48b] ll; \
> + call %[bpf_map_lookup_elem]; \
> + if r0 == 0 goto l0_%=; \
> + r1 = 7; \
> + r1 *= r0; \
[Severity: Medium]
Does this actually test the verifier's handling of pointer *= scalar?
The multiplication is applied to a scalar destination (r1) with a pointer
source (r0). Would it be more accurate to test if applying *= to a pointer
destination correctly downgrades the pointer to a scalar?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261002124714.180012-1-alexei.starovoitov@gmail.com?part=2
next prev parent reply other threads:[~2026-10-02 13:08 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-02 12:46 [PATCH bpf-next v2 00/15] bpf: Support programs compiled by rust-bpf Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 01/15] bpf: Allow bitwise ops, shifts and mul/div on pointers with CAP_PERFMON Alexei Starovoitov
2026-10-02 13:49 ` bot+bpf-ci
2026-10-02 12:47 ` [PATCH bpf-next v2 02/15] selftests/bpf: Add tests for ALU " Alexei Starovoitov
2026-10-02 13:08 ` sashiko-bot [this message]
2026-10-03 11:48 ` Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 03/15] bpf: Treat load and store through a number as arena access Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 04/15] selftests/bpf: Add tests for arena access through numbers Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 05/15] bpf: Allow names of Rust types and functions in BTF Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 06/15] selftests/bpf: Add tests for " Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 07/15] bpf: Allow arguments without names in static " Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 08/15] selftests/bpf: Add test for arguments without names in static functions Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 09/15] bpf: Allow a variable in DATASEC that is smaller than its type Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 10/15] bpftool: Skip pieces of variables in DATASEC Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 11/15] selftests/bpf: Add tests for a variable that is smaller than its type Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 12/15] libbpf: Keep global data in arena when the object has .arena.data Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 13/15] libbpf: Keep format strings of bpf_printk() in .rodata.str Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 14/15] selftests/bpf: Add test for global data in arena Alexei Starovoitov
2026-10-02 13:49 ` bot+bpf-ci
2026-10-02 12:47 ` [PATCH bpf-next v2 15/15] selftests/bpf: Add test for global data of a program in Rust Alexei Starovoitov
2026-10-03 1:33 ` sashiko-bot
2026-10-03 11:47 ` Alexei Starovoitov
2026-10-03 14:20 ` [PATCH bpf-next v2 00/15] bpf: Support programs compiled by rust-bpf patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261002130803.A0FFA1F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=alexei.starovoitov@gmail.com \
--cc=bpf@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox