BPF List
 help / color / mirror / Atom feed
From: "Kumar Kartikeya Dwivedi" <memxor@gmail.com>
To: "Alexei Starovoitov" <alexei.starovoitov@gmail.com>,
	<bpf@vger.kernel.org>
Cc: <daniel@iogearbox.net>, <andrii@kernel.org>, <eddyz87@gmail.com>
Subject: Re: [PATCH bpf-next 0/8] bpf: Fixes for may_goto, insn patching and iterator loops
Date: Fri, 25 Sep 2026 03:23:27 +0200	[thread overview]
Message-ID: <DLO069N8F55X.3AC0XSELJEC43@gmail.com> (raw)
In-Reply-To: <20260924233130.1213812-1-alexei.starovoitov@gmail.com>

On Fri Sep 25, 2026 at 1:31 AM CEST, Alexei Starovoitov wrote:
> From: Alexei Starovoitov <ast@kernel.org>
>
> Fixes for four bugs in may_goto, in patching of insns and in
> convergence of iterator loops, each followed by its tests.
>
> Patch 1: arch_bpf_timed_may_goto() on x86 computes the address of count
> and timestamp as rbp + offset. The prog with private stack keeps its
> stack in r9, so bpf_check_timed_may_goto() reads and writes the kernel
> stack, where r0-r5 have just been saved.
>
> Patch 3: [ST, ST, first insn] that inits may_goto count and
> [nospec, insn] move the insn down inside its own patch.
> bpf_adj_branches() doesn't look inside the patch, so a call, ld_imm64
> of a func or a jump that points backward lands short of its target
> by the number of insns in front of it.
>
> Patch 5: may_goto is expanded into a conditional jump with off + 5,
> off + 2 or off - 1 stored into 16 bits without a range check.
> may_goto +32763 jumps backward when it expires.
>
> Patch 7: states_equal() matches ids through idmap, so the loop is
> assumed to converge at bpf_iter_*_next() when the iterator was
> destroyed and created again since the old state. The prog that never
> ends is accepted.
>
> On x86-64 without the fixes may_goto_priv_stack, may_goto_far/32767,
> may_goto_far/-32768, both new tests of verifier_may_goto_1, "nospec in
> front of a call" (unpriv) and four "iter: remake ... jump to next"
> tests fail. With the fixes they pass.
>
> veristat on selftests, 5477 progs: no prog changes its verdict except
> the new "iter: remake" ones. Patch 7 adds insns to 16 progs that
> call bpf_iter_*_next() in a loop: 11010007 -> 11011495 insns in total,
> test_copy_from_user_dynptr 342 -> 470 is the largest in percent.
>
> Signed-off-by: Alexei Starovoitov <ast@kernel.org>
>

For the set:
Acked-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>

  parent reply	other threads:[~2026-09-25  1:23 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-24 23:31 [PATCH bpf-next 0/8] bpf: Fixes for may_goto, insn patching and iterator loops Alexei Starovoitov
2026-09-24 23:31 ` [PATCH bpf-next 1/8] bpf, x86: Fix timed may_goto with private stack Alexei Starovoitov
2026-09-24 23:31 ` [PATCH bpf-next 2/8] selftests/bpf: Add test for " Alexei Starovoitov
2026-09-24 23:31 ` [PATCH bpf-next 3/8] bpf: Adjust pc-relative insn copied into its own patch Alexei Starovoitov
2026-09-24 23:31 ` [PATCH bpf-next 4/8] selftests/bpf: Add tests for " Alexei Starovoitov
2026-09-24 23:31 ` [PATCH bpf-next 5/8] bpf: Fix overflow of jump offset in may_goto expansion Alexei Starovoitov
2026-09-24 23:31 ` [PATCH bpf-next 6/8] selftests/bpf: Add tests for may_goto with far target Alexei Starovoitov
2026-09-25  0:01   ` bot+bpf-ci
2026-09-25  0:11     ` Alexei Starovoitov
2026-09-24 23:31 ` [PATCH bpf-next 7/8] bpf: Don't converge a loop on an iterator that was created anew Alexei Starovoitov
2026-09-24 23:31 ` [PATCH bpf-next 8/8] selftests/bpf: Add tests for iterator created anew in its loop Alexei Starovoitov
2026-09-25  1:23 ` Kumar Kartikeya Dwivedi [this message]
2026-09-25  1:30 ` [PATCH bpf-next 0/8] bpf: Fixes for may_goto, insn patching and iterator loops patchwork-bot+netdevbpf

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=DLO069N8F55X.3AC0XSELJEC43@gmail.com \
    --to=memxor@gmail.com \
    --cc=alexei.starovoitov@gmail.com \
    --cc=andrii@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=daniel@iogearbox.net \
    --cc=eddyz87@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox