BPF List
 help / color / mirror / Atom feed
From: "Alexei Starovoitov" <alexei.starovoitov@gmail.com>
To: <sashiko-reviews@lists.linux.dev>
Cc: <bpf@vger.kernel.org>
Subject: Re: [PATCH bpf-next v2 02/15] selftests/bpf: Add tests for ALU on pointers with CAP_PERFMON
Date: Sat, 03 Oct 2026 11:48:17 +0000	[thread overview]
Message-ID: <DLV6H1CSHK76.14LXBR533VMQJ@gmail.com> (raw)
In-Reply-To: <20261002130803.A0FFA1F000FF@smtp.kernel.org>

On Fri, Oct 02, 2026 at 01:08 PM sashiko-bot@kernel.org <sashiko-bot@kernel.org> wrote:

> Additionally, since this program places multiple unprivileged operations
> sequentially, wouldn't the verifier abort at the first failure (r1 &= 1),
> leaving the unprivileged rejection of the subsequent operations (>>=, |=, ^=)
> completely untested?

Not an issue. Nothing changes for unpriv. to_scalar is false without
allow_ptr_leaks.

>> +	r1 = 7;						\
>> +	r1 *= r0;					\
>
> [Severity: Medium]
> Does this actually test the verifier's handling of pointer *= scalar?
>
> The multiplication is applied to a scalar destination (r1) with a pointer
> source (r0). Would it be more accurate to test if applying *= to a pointer
> destination correctly downgrades the pointer to a scalar?

No. The test is "number op= pointer". That's dst_reg != ptr_reg case.
pointer op= number is covered by other tests in this file.

  reply	other threads:[~2026-10-03 11:48 UTC|newest]

Thread overview: 23+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-02 12:46 [PATCH bpf-next v2 00/15] bpf: Support programs compiled by rust-bpf Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 01/15] bpf: Allow bitwise ops, shifts and mul/div on pointers with CAP_PERFMON Alexei Starovoitov
2026-10-02 13:49   ` bot+bpf-ci
2026-10-02 12:47 ` [PATCH bpf-next v2 02/15] selftests/bpf: Add tests for ALU " Alexei Starovoitov
2026-10-02 13:08   ` sashiko-bot
2026-10-03 11:48     ` Alexei Starovoitov [this message]
2026-10-02 12:47 ` [PATCH bpf-next v2 03/15] bpf: Treat load and store through a number as arena access Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 04/15] selftests/bpf: Add tests for arena access through numbers Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 05/15] bpf: Allow names of Rust types and functions in BTF Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 06/15] selftests/bpf: Add tests for " Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 07/15] bpf: Allow arguments without names in static " Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 08/15] selftests/bpf: Add test for arguments without names in static functions Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 09/15] bpf: Allow a variable in DATASEC that is smaller than its type Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 10/15] bpftool: Skip pieces of variables in DATASEC Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 11/15] selftests/bpf: Add tests for a variable that is smaller than its type Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 12/15] libbpf: Keep global data in arena when the object has .arena.data Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 13/15] libbpf: Keep format strings of bpf_printk() in .rodata.str Alexei Starovoitov
2026-10-02 12:47 ` [PATCH bpf-next v2 14/15] selftests/bpf: Add test for global data in arena Alexei Starovoitov
2026-10-02 13:49   ` bot+bpf-ci
2026-10-02 12:47 ` [PATCH bpf-next v2 15/15] selftests/bpf: Add test for global data of a program in Rust Alexei Starovoitov
2026-10-03  1:33   ` sashiko-bot
2026-10-03 11:47     ` Alexei Starovoitov
2026-10-03 14:20 ` [PATCH bpf-next v2 00/15] bpf: Support programs compiled by rust-bpf patchwork-bot+netdevbpf

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=DLV6H1CSHK76.14LXBR533VMQJ@gmail.com \
    --to=alexei.starovoitov@gmail.com \
    --cc=bpf@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox