From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from mails.dpdk.org (mails.dpdk.org [217.70.189.124]) by smtp.lore.kernel.org (Postfix) with ESMTP id CB994CD4851 for ; Tue, 19 May 2026 09:32:23 +0000 (UTC) Received: from mails.dpdk.org (localhost [127.0.0.1]) by mails.dpdk.org (Postfix) with ESMTP id 33BCD40677; Tue, 19 May 2026 11:32:00 +0200 (CEST) Received: from frasgout.his.huawei.com (frasgout.his.huawei.com [185.176.79.56]) by mails.dpdk.org (Postfix) with ESMTP id 59F5B40612; Tue, 19 May 2026 11:31:54 +0200 (CEST) Received: from mail.maildlp.com (unknown [172.18.224.83]) by frasgout.his.huawei.com (SkyGuard) with ESMTPS id 4gKTv76SghzJ46bN; Tue, 19 May 2026 17:31:15 +0800 (CST) Received: from frapema500003.china.huawei.com (unknown [7.182.19.114]) by mail.maildlp.com (Postfix) with ESMTPS id 3709E40577; Tue, 19 May 2026 17:31:54 +0800 (CST) Received: from localhost.localdomain (10.220.239.45) by frapema500003.china.huawei.com (7.182.19.114) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1544.11; Tue, 19 May 2026 11:31:53 +0200 From: Marat Khalili To: Konstantin Ananyev CC: , Subject: [PATCH v2 06/25] bpf/validate: fix BPF_ADD of pointer to a scalar Date: Tue, 19 May 2026 10:31:09 +0100 Message-ID: <20260519093131.52022-7-marat.khalili@huawei.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260519093131.52022-1-marat.khalili@huawei.com> References: <20260506173846.64914-1-marat.khalili@huawei.com> <20260519093131.52022-1-marat.khalili@huawei.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Content-Type: text/plain X-Originating-IP: [10.220.239.45] X-ClientProxiedBy: frapema500002.china.huawei.com (7.182.19.148) To frapema500003.china.huawei.com (7.182.19.114) X-BeenThere: dev@dpdk.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: DPDK patches and discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: dev-bounces@dpdk.org Function `eval_add` preserved type of the destination register even when a pointer was added to it. If it contained scalar, it remained a scalar, and if it contained pointer, it remained a pointer. E.g. consider the following program with the current validation code: Tested program: 0: mov r0, #0x0 1: mov r3, #0x0 2: add r3, r1 ; tested instruction 3: ldxdw r2, [r3 + 16] 4: mov r0, #0x1 5: exit After the tested instruction validator considers r3 to be scalar and fails validation with the error: BPF: evaluate(): destination is not a pointer at pc: 3 However, this code is valid as long as program argument points to a valid memory area at least 24 bytes long which we read at offset 16. When adding pointer to a scalar set type of the result to pointer of the same type. When adding pointer to a pointer set type of the result to scalar and value to unknown. The test will be added in subsequent commits since it depends on other fixes. Fixes: 8021917293d0 ("bpf: add extra validation for input BPF program") Cc: stable@dpdk.org Signed-off-by: Marat Khalili Acked-by: Konstantin Ananyev --- Depends-on: series-38149 ("bpf: introduce extensible load API") lib/bpf/bpf_validate.c | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/lib/bpf/bpf_validate.c b/lib/bpf/bpf_validate.c index 8dac908c39..41dca2fb76 100644 --- a/lib/bpf/bpf_validate.c +++ b/lib/bpf/bpf_validate.c @@ -647,8 +647,20 @@ eval_apply_mask(struct bpf_reg_val *rv, uint64_t mask) static void eval_add(struct bpf_reg_val *rd, const struct bpf_reg_val *rs, uint64_t msk) { + struct bpf_reg_val rs_buf; struct bpf_reg_val rv; + if (RTE_BPF_ARG_PTR_TYPE(rs->v.type) != 0) { + if (RTE_BPF_ARG_PTR_TYPE(rd->v.type) != 0) { + /* treat sum of pointers as sum of two unknown scalars */ + eval_fill_max_bound(&rs_buf, msk); + *rd = rs_buf; + rs = &rs_buf; + } else + /* scalar + pointer is a pointer of the same type */ + rd->v = rs->v; + } + rv.u.min = (rd->u.min + rs->u.min) & msk; rv.u.max = (rd->u.max + rs->u.max) & msk; rv.s.min = ((uint64_t)rd->s.min + (uint64_t)rs->s.min) & msk; -- 2.43.0