summaryrefslogtreecommitdiff
path: root/tools/perf/scripts/python
diff options
context:
space:
mode:
authorEduard Zingerman <eddyz87@gmail.com>2026-07-31 12:43:29 -0700
committerEduard Zingerman <eddyz87@gmail.com>2026-07-31 12:45:36 -0700
commit80f3c3eb43847a5065f2025b0fbd45c478910ae8 (patch)
treec19165a83744d63b7cc086b5f17c9349dd6af5a9 /tools/perf/scripts/python
parent0ce37745d4bfbc493f718169c3974898ffec8ee7 (diff)
parent21596761ff370f05460ad0f9078786082bbfa87d (diff)
Merge branch 'bpf-preserve-pointer-state-for-commuted-arithmetic'
Yiyang Chen says: ==================== bpf: Preserve pointer state for commuted arithmetic This series fixes pointer-state propagation for commuted scalar += pointer arithmetic in the verifier. Patch 1 simplifies sanitize_err() before the pointer-state change. Patch 2 keeps the full pointer register state when the pointer operand is the source of the add, preserving fields such as the stack frame number and parent id. Patch 3 moves the untrusted PTR_TO_MEM early return after state propagation, so scalar += untrusted_pointer remains usable through the probe-read path. Patch 4 adds verifier selftests for stack frame number preservation, readonly-untrusted memory access, and dynptr data-slice invalidation. Changes in v4: - Target the bpf fixes tree because the affected behavior is present in released kernels. - Add Eduard's sanitize_err() cleanup and revised pointer-state patch, reusing the caller's temporary offset register instead of verifier-env scratch storage. - Correct the stack-frame Fixes tag to the BPF-to-BPF call verification commit identified by Shung-Hsi. - Fix the dynptr test comment style and retain the source-register clear so the test isolates parent-id propagation. - Carry Daniel Wade's Tested-by and Eduard's selftest Acked-by from the v3 thread. - Rebase to bpf base 0ce37745d4bf. Changes in v3: - Preserve the complete pointer register state with verifier-env scratch storage, addressing Eduard's comment that copying selected fields is fragile and avoiding a temporary bpf_reg_state on the verifier stack. - Keep the existing RUN(verifier_basic_stack) dispatch unchanged and add the stack regression directly to the existing verifier_basic_stack program. - Keep the original operand direction inside adjust_ptr_min_max_vals() by saving the scalar operand in env->fake_reg[0]. - Move untrusted PTR_TO_MEM handling after the unified pointer-state copy so the commuted form remains PTR_TO_MEM before the early return. - Add readonly-untrusted and dynptr selftest coverage, responding to the bpf-ci/static review finding that the untrusted pointer case needs a regression test. - Clear the original dynptr data-slice register after deriving the commuted alias so the regression test isolates parent-id propagation. - Make the readonly-untrusted return value endian-neutral by loading an int. - Rebase to bpf-next base a23a71823352. v3: https://lore.kernel.org/bpf/cover.1784696371.git.chenyy23@mails.tsinghua.edu.cn/ v2: https://lore.kernel.org/bpf/cover.1784563950.git.chenyy23@mails.tsinghua.edu.cn/ v1: https://lore.kernel.org/bpf/cover.1784563939.git.chenyy23@mails.tsinghua.edu.cn/ --- ==================== Link: https://patch.msgid.link/20260729-c3-035-public-bpf-v4-v4-0-8ee297e2346b@mails.tsinghua.edu.cn Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
Diffstat (limited to 'tools/perf/scripts/python')
0 files changed, 0 insertions, 0 deletions