BPF List
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Rahad Bhuiya" <rahadbhuiya2021@gmail.com>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf-next] bpf: fix symmetric register-form NULL-pointer check in check_cond_jmp_op()
Date: Thu, 08 Oct 2026 06:44:57 +0000	[thread overview]
Message-ID: <sashiko-outbox-163713@kernel.org> (raw)
In-Reply-To: <20261008063322.530-1-rahadbhuiya2021@gmail.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [Medium] bpf: symmetric NULL check fix is unreachable for unprivileged programs
- [Low] bpf: multi-line comments violate subsystem style guidelines
--

commit e76939eba1acc9b00715cb7f09c40f2d50cb02ae
Author: Rahad Bhuiya <rahadbhuiya2021@gmail.com>

bpf: fix symmetric register-form NULL-pointer check in check_cond_jmp_op()
    
This commit addresses an issue in the BPF verifier where symmetric NULL pointer
checks (e.g., if (0 == ptr)) were not propagating the nullness state correctly.
It adds logic to handle the case where the destination register is zero and
the source register is a nullable pointer, updating the branches accordingly.

> diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
> index 353bde9ae2274..e4ae8f6481620 100644
> --- a/kernel/bpf/verifier.c
> +++ b/kernel/bpf/verifier.c

[ ... ]

> @@ -18248,6 +18248,26 @@ static int check_cond_jmp_op(struct bpf_verifier_env *env,
>  				      opcode == BPF_JNE);
>  		mark_ptr_or_null_regs(other_branch, insn->dst_reg,
>  				      opcode == BPF_JEQ);
> +	} else if (!is_jmp32 && BPF_SRC(insn->code) == BPF_X &&
> +		   (opcode == BPF_JEQ || opcode == BPF_JNE) &&
> +		   type_may_be_null(src_reg->type) &&
> +		   bpf_register_is_null(dst_reg)) {

[Severity: Medium]
Will this fix be reachable for unprivileged BPF programs?

In unprivileged mode (env->allow_ptr_leaks == false), an early security check
in check_cond_jmp_op() rejects conditional jumps where src_reg is a pointer,
unless both operands are packet pointers:

    if (!(reg_is_pkt_pointer_any(dst_reg) && reg_is_pkt_pointer_any(src_reg)) &&
        is_pointer_value(env, insn->src_reg)) {
        verbose(env, "R%d pointer comparison prohibited\n", insn->src_reg);
        return -EACCES;
    }

Because this check happens before the newly added block, unprivileged BPF
programs attempting symmetric NULL checks might still be unconditionally
rejected, rendering the fix incomplete for those users.

> +		/* Symmetric case: src_reg is the nullable pointer, dst_reg is
> +		 * a register whose value is known to be zero.  This arises when

[Severity: Low]
This isn't a bug, but does this multi-line comment violate the BPF subsystem
style guidelines?

The BPF guidelines mandate that multi-line comments must have the opening /*
on its own line, with the comment text starting on the subsequent line.

> +		 * the programmer writes the comparison in reversed operand order,
> +		 * e.g. "if (0 == map_val)" or "if (r0 == map_val)" where r0 has
> +		 * been proven zero by the verifier.
> +		 *
> +		 * The zero is a property of this execution path, so dst_reg
> +		 * must be marked precise before we propagate nullness.
> +		 */
> +		err = mark_chain_precision(env, insn->dst_reg);
> +		if (err)
> +			return err;

[ ... ]

> diff --git a/tools/testing/selftests/bpf/progs/verifier_null_ptr_symmetric.c b/tools/testing/selftests/bpf/progs/verifier_null_ptr_symmetric.c
> new file mode 100644
> index 0000000000000..475aa3dc3bd25
> --- /dev/null
> +++ b/tools/testing/selftests/bpf/progs/verifier_null_ptr_symmetric.c
> @@ -0,0 +1,162 @@
> +// SPDX-License-Identifier: GPL-2.0
> +/* Verifier selftests for symmetric register-form NULL-pointer checks.
> + *
> + * The BPF verifier's check_cond_jmp_op() handles "if R == 0" NULL checks by

[Severity: Low]
This isn't a bug, but does this comment also violate the multi-line comment
style for the BPF subsystem?

The opening /* should be on its own line, with the text beginning on the
subsequent line.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261008063322.530-1-rahadbhuiya2021@gmail.com?part=1

  reply	other threads:[~2026-10-08  6:44 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-08  6:33 [PATCH bpf-next] bpf: fix symmetric register-form NULL-pointer check in check_cond_jmp_op() Rahad Bhuiya
2026-10-08  6:44 ` sashiko-bot [this message]
2026-10-08  6:57 ` [PATCH bpf-next v2] " Rahad Bhuiya
2026-10-08 18:53   ` [PATCH bpf-next v3] " Rahad Bhuiya
2026-10-08 19:52     ` bot+bpf-ci
2026-10-09  4:38     ` [PATCH bpf-next v4] " Rahad Bhuiya
2026-10-09  5:57       ` bot+bpf-ci
2026-10-09  8:32       ` Rahad Bhuiya
2026-10-09  9:56       ` Alexei Starovoitov

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=sashiko-outbox-163713@kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=rahadbhuiya2021@gmail.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox