From: bot+bpf-ci@kernel.org
To: alexis.lothore@bootlin.com,ast@kernel.org,daniel@iogearbox.net,john.fastabend@gmail.com,andrii@kernel.org,martin.lau@linux.dev,eddyz87@gmail.com,memxor@gmail.com,song@kernel.org,yonghong.song@linux.dev,jolsa@kernel.org,tglx@kernel.org,bp@alien8.de,dave.hansen@linux.intel.com,x86@kernel.org,hpa@zytor.com,shuah@kernel.org,mingo@redhat.com,andreyknvl@gmail.com,emil@etsalapatis.com,ihor.solodrai@linux.dev,laoar.shao@gmail.com
Cc: ebpf@linuxfoundation.org,bastien.curutchet@bootlin.com,thomas.petazzoni@bootlin.com,bpf@vger.kernel.org,linux-kernel@vger.kernel.org,linux-kselftest@vger.kernel.org,alexis.lothore@bootlin.com,ast@kernel.org,andrii@kernel.org,daniel@iogearbox.net,martin.lau@kernel.org,eddyz87@gmail.com,yonghong.song@linux.dev,mason@kernel.org,ihor.solodrai@linux.dev
Subject: Re: [PATCH bpf-next v9 1/8] bpf: mark instructions accessing program stack
Date: Thu, 3 Sep 2026 15:18:23 +0000 (UTC) [thread overview]
Message-ID: <a7574349d8f15510aea8acfcd95bee2b5fc18c3bf6c27ac9362f0090011b6c17@mail.kernel.org> (raw)
In-Reply-To: <20260903-kasan-v9-1-2407fe99255a@bootlin.com>
[-- Attachment #1: Type: text/plain, Size: 2992 bytes --]
> diff --git a/kernel/bpf/fixups.c b/kernel/bpf/fixups.c
> index 65b441e4a3517..73fb3ffc18e33 100644
> --- a/kernel/bpf/fixups.c
> +++ b/kernel/bpf/fixups.c
> @@ -213,7 +213,8 @@ static int get_callee_stack_depth(struct bpf_verifier_env *env,
> * [0, off) and [off, end) to new locations, so the patched range stays zero
> */
> static void adjust_insn_aux_data(struct bpf_verifier_env *env,
> - struct bpf_prog *new_prog, u32 off, u32 cnt)
> + struct bpf_prog *new_prog, u32 off, u32 cnt,
> + struct bpf_insn *original_insn)
> {
> struct bpf_insn_aux_data *data = env->insn_aux_data;
> struct bpf_insn *insn = new_prog->insnsi;
> @@ -227,8 +228,15 @@ static void adjust_insn_aux_data(struct bpf_verifier_env *env,
> */
> data[off].zext_dst = bpf_insn_def32(new_prog, insn + off + cnt - 1) >= 0;
>
> - if (cnt == 1)
> + if (cnt == 1) {
> + /*
> + * A non-memory accessing insn could have been replaced by a
> + * memory accessing insn, systematically mark it for non-stack
> + * access
> + */
> + data[off].non_stack_access = bpf_is_mem_insn(insn + off);
> return;
> + }
This isn't a bug, but does the comment explain why the marking needs to be
unconditionally reset here? The statement is an assignment that both sets
and clears the flag depending on the result, but the comment only mentions
the setting direction.
> prog_len = new_prog->len;
> env->insn_aux_data_len = prog_len;
>
> @@ -239,8 +247,25 @@ static void adjust_insn_aux_data(struct bpf_verifier_env *env,
> /* Expand insni[off]'s seen count to the patched range. */
> data[i].seen = old_seen;
> data[i].zext_dst = bpf_insn_def32(new_prog, insn + i) >= 0;
> + if (!memcmp(insn + i, original_insn, sizeof(struct bpf_insn))) {
> + data[i].non_stack_access =
> + data[off + cnt - 1].non_stack_access;
> + data[off + cnt - 1].non_stack_access = false;
> + } else if (bpf_is_mem_insn(insn + i)) {
> + data[i].non_stack_access = true;
> + }
This isn't a bug, but could off + cnt - 1 be hoisted into a local here?
It appears eight times in this function now, and the two-line wrapped
assignment above exists only because the index expression is long.
> }
>
> + /*
> + * Last slot instruction could be a newly generated
> + * BPF_ST/BPF_LDX/BPF_STX, systematically mark it for non-stack access
> + * if it is not the original instruction, otherwise keep the
> + * original marking
> + */
> + if (bpf_is_mem_insn(insn + off + cnt - 1) &&
> + memcmp(insn + off + cnt - 1, original_insn, sizeof(struct bpf_insn)))
> + data[off + cnt - 1].non_stack_access = true;
This isn't a bug, but does this comment add information beyond the if
condition below it? The comment reads as a prose transcription of the
conditional.
---
AI reviewed your patch. Please fix the bug or email reply why it's not a bug.
See: https://github.com/kernel-patches/vmtest/blob/master/ci/claude/README.md
CI run summary: https://github.com/kernel-patches/bpf/actions/runs/33766012402
next prev parent reply other threads:[~2026-09-03 15:18 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-03 13:51 [PATCH bpf-next v9 0/8] bpf: add support for KASAN checks in JITed programs Alexis Lothoré (eBPF Foundation)
2026-09-03 13:51 ` [PATCH bpf-next v9 1/8] bpf: mark instructions accessing program stack Alexis Lothoré (eBPF Foundation)
2026-09-03 15:18 ` bot+bpf-ci [this message]
2026-09-03 13:51 ` [PATCH bpf-next v9 2/8] bpf: add BPF_JIT_KASAN for KASAN instrumentation of JITed programs Alexis Lothoré (eBPF Foundation)
2026-09-03 13:51 ` [PATCH bpf-next v9 3/8] bpf, x86: refactor BPF_ST management in do_jit Alexis Lothoré (eBPF Foundation)
2026-09-03 13:51 ` [PATCH bpf-next v9 4/8] bpf, x86: emit KASAN checks in x86 JITed programs Alexis Lothoré (eBPF Foundation)
2026-09-03 15:18 ` bot+bpf-ci
2026-09-03 13:51 ` [PATCH bpf-next v9 5/8] bpf, x86: enable KASAN for JITed programs on x86 Alexis Lothoré (eBPF Foundation)
2026-09-03 13:51 ` [PATCH bpf-next v9 6/8] selftests/bpf: make cmdline_contains stricter Alexis Lothoré (eBPF Foundation)
2026-09-03 13:51 ` [PATCH bpf-next v9 7/8] selftests/bpf: add helpers for KASAN in JIT testing Alexis Lothoré (eBPF Foundation)
2026-09-03 13:51 ` [PATCH bpf-next v9 8/8] selftests/bpf: add tests to validate KASAN on JIT programs Alexis Lothoré (eBPF Foundation)
2026-09-04 9:02 ` [PATCH bpf-next v9 0/8] bpf: add support for KASAN checks in JITed programs Kumar Kartikeya Dwivedi
2026-09-04 17:00 ` patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=a7574349d8f15510aea8acfcd95bee2b5fc18c3bf6c27ac9362f0090011b6c17@mail.kernel.org \
--to=bot+bpf-ci@kernel.org \
--cc=alexis.lothore@bootlin.com \
--cc=andreyknvl@gmail.com \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bastien.curutchet@bootlin.com \
--cc=bp@alien8.de \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=dave.hansen@linux.intel.com \
--cc=ebpf@linuxfoundation.org \
--cc=eddyz87@gmail.com \
--cc=emil@etsalapatis.com \
--cc=hpa@zytor.com \
--cc=ihor.solodrai@linux.dev \
--cc=john.fastabend@gmail.com \
--cc=jolsa@kernel.org \
--cc=laoar.shao@gmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-kselftest@vger.kernel.org \
--cc=martin.lau@kernel.org \
--cc=martin.lau@linux.dev \
--cc=mason@kernel.org \
--cc=memxor@gmail.com \
--cc=mingo@redhat.com \
--cc=shuah@kernel.org \
--cc=song@kernel.org \
--cc=tglx@kernel.org \
--cc=thomas.petazzoni@bootlin.com \
--cc=x86@kernel.org \
--cc=yonghong.song@linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®