From: Qiliang Yuan <odys.yuan@gmail.com>
To: Alexei Starovoitov <ast@kernel.org>,
Daniel Borkmann <daniel@iogearbox.net>,
John Fastabend <john.fastabend@gmail.com>,
Andrii Nakryiko <andrii@kernel.org>,
Eduard Zingerman <eddyz87@gmail.com>,
Kumar Kartikeya Dwivedi <memxor@gmail.com>,
Martin KaFai Lau <martin.lau@linux.dev>,
Song Liu <song@kernel.org>,
Yonghong Song <yonghong.song@linux.dev>,
Jiri Olsa <jolsa@kernel.org>,
Emil Tsalapatis <emil@etsalapatis.com>,
Ihor Solodrai <ihor.solodrai@linux.dev>,
Shuah Khan <shuah@kernel.org>
Cc: bpf@vger.kernel.org, linux-kernel@vger.kernel.org,
linux-kselftest@vger.kernel.org,
Qiliang Yuan <odys.yuan@gmail.com>
Subject: [PATCH bpf-next 3/4] bpf: Drop the constant delta from bpf_do_misc_fixups()
Date: Thu, 01 Oct 2026 17:35:34 +0800 [thread overview]
Message-ID: <20261001-bpf-verifier-patch-batch-v1-3-a12df8a09160@gmail.com> (raw)
In-Reply-To: <20261001-bpf-verifier-patch-batch-v1-0-a12df8a09160@gmail.com>
Nothing changes the program while bpf_do_misc_fixups() walks it anymore,
so delta is always 0 in the loop. Index instructions and aux data by i
alone.
Signed-off-by: Qiliang Yuan <odys.yuan@gmail.com>
---
kernel/bpf/fixups.c | 68 ++++++++++++++++++++++++++---------------------------
1 file changed, 34 insertions(+), 34 deletions(-)
diff --git a/kernel/bpf/fixups.c b/kernel/bpf/fixups.c
index 4b96f4ee9b3d8..0e8c61ede9a5b 100644
--- a/kernel/bpf/fixups.c
+++ b/kernel/bpf/fixups.c
@@ -2044,7 +2044,7 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
struct bpf_insn *insn_buf = env->insn_buf;
struct bpf_prog *new_prog;
struct bpf_map *map_ptr;
- int i, ret, cnt, delta = 0, cur_subprog = 0;
+ int i, ret, cnt, cur_subprog = 0;
struct bpf_subprog_info *subprogs = env->subprog_info;
u16 stack_depth = subprogs[cur_subprog].stack_depth;
u16 stack_depth_extra = 0;
@@ -2076,7 +2076,7 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
goto next_insn;
}
- if (env->insn_aux_data[i + delta].needs_zext)
+ if (env->insn_aux_data[i].needs_zext)
/* Convert BPF_CLASS(insn->code) == BPF_ALU64 to 32-bit ALU */
insn->code = BPF_ALU | BPF_OP(insn->code) | BPF_SRC(insn->code);
@@ -2099,7 +2099,7 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
cnt = patch - insn_buf;
- insn = bpf_patch_list_add(env, i + delta, insn_buf, cnt);
+ insn = bpf_patch_list_add(env, i, insn_buf, cnt);
if (IS_ERR(insn))
return PTR_ERR(insn);
goto next_insn;
@@ -2186,7 +2186,7 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
cnt = patch - insn_buf;
}
- insn = bpf_patch_list_add(env, i + delta, insn_buf, cnt);
+ insn = bpf_patch_list_add(env, i, insn_buf, cnt);
if (IS_ERR(insn))
return PTR_ERR(insn);
goto next_insn;
@@ -2212,7 +2212,7 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
*patch++ = BPF_MOV64_IMM(insn->dst_reg, 0);
cnt = patch - insn_buf;
- insn = bpf_patch_list_add(env, i + delta, insn_buf, cnt);
+ insn = bpf_patch_list_add(env, i, insn_buf, cnt);
if (IS_ERR(insn))
return PTR_ERR(insn);
goto next_insn;
@@ -2228,7 +2228,7 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
return -EFAULT;
}
- insn = bpf_patch_list_add(env, i + delta, insn_buf, cnt);
+ insn = bpf_patch_list_add(env, i, insn_buf, cnt);
if (IS_ERR(insn))
return PTR_ERR(insn);
goto next_insn;
@@ -2243,7 +2243,7 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
bool issrc, isneg, isimm;
u32 off_reg;
- aux = &env->insn_aux_data[i + delta];
+ aux = &env->insn_aux_data[i];
if (!aux->alu_state ||
aux->alu_state == BPF_ALU_NON_POINTER)
goto next_insn;
@@ -2277,7 +2277,7 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
*patch++ = BPF_ALU64_IMM(BPF_MUL, off_reg, -1);
cnt = patch - insn_buf;
- insn = bpf_patch_list_add(env, i + delta, insn_buf, cnt);
+ insn = bpf_patch_list_add(env, i, insn_buf, cnt);
if (IS_ERR(insn))
return PTR_ERR(insn);
goto next_insn;
@@ -2316,7 +2316,7 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
cnt = may_goto_expand(insn_buf, insn->off, stack_off_cnt,
tail, ARRAY_SIZE(tail));
- insn = bpf_patch_list_add(env, i + delta, insn_buf, cnt);
+ insn = bpf_patch_list_add(env, i, insn_buf, cnt);
if (IS_ERR(insn))
return PTR_ERR(insn);
goto next_insn;
@@ -2331,7 +2331,7 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
cnt = may_goto_expand(insn_buf, insn->off, stack_off,
tail, ARRAY_SIZE(tail));
- insn = bpf_patch_list_add(env, i + delta, insn_buf, cnt);
+ insn = bpf_patch_list_add(env, i, insn_buf, cnt);
if (IS_ERR(insn))
return PTR_ERR(insn);
goto next_insn;
@@ -2343,7 +2343,7 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
insn->src_reg == BPF_PSEUDO_MAP_IDX_VALUE)) {
struct bpf_map *map;
- aux = &env->insn_aux_data[i + delta];
+ aux = &env->insn_aux_data[i];
map = env->used_maps[aux->map_index];
if (map->map_type != BPF_MAP_TYPE_PERCPU_ARRAY)
goto next_insn;
@@ -2364,7 +2364,7 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
cnt = 2;
i++;
- insn = bpf_patch_list_add(env, i + delta, insn_buf, cnt);
+ insn = bpf_patch_list_add(env, i, insn_buf, cnt);
if (IS_ERR(insn))
return PTR_ERR(insn);
goto next_insn;
@@ -2375,13 +2375,13 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
if (insn->src_reg == BPF_PSEUDO_CALL)
goto next_insn;
if (insn->src_reg == BPF_PSEUDO_KFUNC_CALL) {
- ret = bpf_fixup_kfunc_call(env, insn, insn_buf, i + delta, &cnt);
+ ret = bpf_fixup_kfunc_call(env, insn, insn_buf, i, &cnt);
if (ret)
return ret;
if (cnt == 0)
goto next_insn;
- insn = bpf_patch_list_add(env, i + delta, insn_buf, cnt);
+ insn = bpf_patch_list_add(env, i, insn_buf, cnt);
if (IS_ERR(insn))
return PTR_ERR(insn);
goto next_insn;
@@ -2418,7 +2418,7 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
insn->imm = 0;
insn->code = BPF_JMP | BPF_TAIL_CALL;
- aux = &env->insn_aux_data[i + delta];
+ aux = &env->insn_aux_data[i];
if (env->bpf_capable && !prog->blinding_requested &&
prog->jit_requested &&
!bpf_map_key_poisoned(aux) &&
@@ -2428,7 +2428,7 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
.reason = BPF_POKE_REASON_TAIL_CALL,
.tail_call.map = aux->map_ptr_state.map_ptr,
.tail_call.key = bpf_map_key_immediate(aux),
- .insn_idx = i + delta,
+ .insn_idx = i,
};
ret = bpf_jit_add_poke_descriptor(prog, &desc);
@@ -2464,13 +2464,13 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
map)->index_mask);
insn_buf[2] = *insn;
cnt = 3;
- insn = bpf_patch_list_add(env, i + delta, insn_buf, cnt);
+ insn = bpf_patch_list_add(env, i, insn_buf, cnt);
if (IS_ERR(insn))
return PTR_ERR(insn);
goto next_insn;
}
- aux = &env->insn_aux_data[i + delta];
+ aux = &env->insn_aux_data[i];
if (aux->arg_prog) {
/* The verifier will process callback_fn as many times as necessary
* with different maps and the register states prepared by
@@ -2494,14 +2494,14 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
insn_buf[2] = *insn;
cnt = 3;
- insn = bpf_patch_list_add(env, i + delta, insn_buf, cnt);
+ insn = bpf_patch_list_add(env, i, insn_buf, cnt);
if (IS_ERR(insn))
return PTR_ERR(insn);
goto patch_call_imm;
}
/* bpf_per_cpu_ptr() and bpf_this_cpu_ptr() */
- if (env->insn_aux_data[i + delta].call_with_percpu_alloc_ptr) {
+ if (env->insn_aux_data[i].call_with_percpu_alloc_ptr) {
/* patch with 'r1 = *(u64 *)(r1 + 0)' since for percpu data,
* bpf_mem_alloc() returns a ptr to the percpu data ptr.
*/
@@ -2509,7 +2509,7 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
insn_buf[1] = *insn;
cnt = 2;
- insn = bpf_patch_list_add(env, i + delta, insn_buf, cnt);
+ insn = bpf_patch_list_add(env, i, insn_buf, cnt);
if (IS_ERR(insn))
return PTR_ERR(insn);
goto patch_call_imm;
@@ -2529,7 +2529,7 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
insn->imm == BPF_FUNC_redirect_map ||
insn->imm == BPF_FUNC_for_each_map_elem ||
insn->imm == BPF_FUNC_map_lookup_percpu_elem)) {
- aux = &env->insn_aux_data[i + delta];
+ aux = &env->insn_aux_data[i];
if (bpf_map_ptr_poisoned(aux))
goto patch_call_imm;
@@ -2548,7 +2548,7 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
if (bpf_map_is_percpu_map(map_ptr->map_type))
prog->jit_required = true;
- insn = bpf_patch_list_add(env, i + delta, insn_buf, cnt);
+ insn = bpf_patch_list_add(env, i, insn_buf, cnt);
if (IS_ERR(insn))
return PTR_ERR(insn);
goto next_insn;
@@ -2626,7 +2626,7 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
BPF_REG_0, 0);
cnt = 3;
- insn = bpf_patch_list_add(env, i + delta, insn_buf, cnt);
+ insn = bpf_patch_list_add(env, i, insn_buf, cnt);
if (IS_ERR(insn))
return PTR_ERR(insn);
goto next_insn;
@@ -2651,7 +2651,7 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
insn_buf[0] = BPF_ALU32_REG(BPF_XOR, BPF_REG_0, BPF_REG_0);
cnt = 1;
#endif
- insn = bpf_patch_list_add(env, i + delta, insn_buf, cnt);
+ insn = bpf_patch_list_add(env, i, insn_buf, cnt);
if (IS_ERR(insn))
return PTR_ERR(insn);
goto next_insn;
@@ -2666,7 +2666,7 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
insn_buf[2] = BPF_LDX_MEM(BPF_DW, BPF_REG_0, BPF_REG_0, 0);
cnt = 3;
- insn = bpf_patch_list_add(env, i + delta, insn_buf, cnt);
+ insn = bpf_patch_list_add(env, i, insn_buf, cnt);
if (IS_ERR(insn))
return PTR_ERR(insn);
goto next_insn;
@@ -2696,7 +2696,7 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
insn_buf[cnt++] = BPF_JMP_A(1);
insn_buf[cnt++] = BPF_MOV64_IMM(BPF_REG_0, -EINVAL);
- insn = bpf_patch_list_add(env, i + delta, insn_buf, cnt);
+ insn = bpf_patch_list_add(env, i, insn_buf, cnt);
if (IS_ERR(insn))
return PTR_ERR(insn);
goto next_insn;
@@ -2724,7 +2724,7 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
cnt = 1;
}
- insn = bpf_patch_list_add(env, i + delta, insn_buf, cnt);
+ insn = bpf_patch_list_add(env, i, insn_buf, cnt);
if (IS_ERR(insn))
return PTR_ERR(insn);
goto next_insn;
@@ -2746,7 +2746,7 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
cnt = 2;
}
- insn = bpf_patch_list_add(env, i + delta, insn_buf, cnt);
+ insn = bpf_patch_list_add(env, i, insn_buf, cnt);
if (IS_ERR(insn))
return PTR_ERR(insn);
goto next_insn;
@@ -2758,7 +2758,7 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
/* Load IP address from ctx - 16 */
insn_buf[0] = BPF_LDX_MEM(BPF_DW, BPF_REG_0, BPF_REG_1, -16);
- insn = bpf_patch_list_add(env, i + delta, insn_buf, 1);
+ insn = bpf_patch_list_add(env, i, insn_buf, 1);
if (IS_ERR(insn))
return PTR_ERR(insn);
goto next_insn;
@@ -2810,7 +2810,7 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
insn_buf[10] = BPF_MOV64_IMM(BPF_REG_0, -ENOENT);
cnt = 11;
- insn = bpf_patch_list_add(env, i + delta, insn_buf, cnt);
+ insn = bpf_patch_list_add(env, i, insn_buf, cnt);
if (IS_ERR(insn))
return PTR_ERR(insn);
goto next_insn;
@@ -2824,7 +2824,7 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
insn_buf[1] = BPF_ATOMIC_OP(BPF_DW, BPF_XCHG, BPF_REG_1, BPF_REG_0, 0);
cnt = 2;
- insn = bpf_patch_list_add(env, i + delta, insn_buf, cnt);
+ insn = bpf_patch_list_add(env, i, insn_buf, cnt);
if (IS_ERR(insn))
return PTR_ERR(insn);
goto next_insn;
@@ -2842,7 +2842,7 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
}
insn->imm = BPF_CALL_IMM(fn->func);
next_insn:
- if (subprogs[cur_subprog + 1].start == i + delta + 1) {
+ if (subprogs[cur_subprog + 1].start == i + 1) {
subprogs[cur_subprog].stack_depth += stack_depth_extra;
subprogs[cur_subprog].stack_extra = stack_depth_extra;
@@ -2857,7 +2857,7 @@ int bpf_do_misc_fixups(struct bpf_verifier_env *env)
stack_depth_extra = 0;
}
i++;
- insn = &prog->insnsi[i + delta];
+ insn = &prog->insnsi[i];
}
ret = bpf_patch_list_commit(env);
--
2.43.0
next prev parent reply other threads:[~2026-10-01 9:35 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-01 9:35 [PATCH bpf-next 0/4] bpf: Apply the rewrites of bpf_do_misc_fixups() at once Qiliang Yuan
2026-10-01 9:35 ` [PATCH bpf-next 1/4] bpf: Add a list of deferred instruction patches Qiliang Yuan
2026-10-01 10:27 ` bot+bpf-ci
2026-10-01 9:35 ` [PATCH bpf-next 2/4] bpf: Queue the rewrites of bpf_do_misc_fixups() and apply them at once Qiliang Yuan
2026-10-01 10:27 ` bot+bpf-ci
2026-10-01 9:35 ` Qiliang Yuan [this message]
2026-10-01 9:35 ` [PATCH bpf-next 4/4] selftests/bpf: Test jumps around patches of bpf_do_misc_fixups() Qiliang Yuan
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261001-bpf-verifier-patch-batch-v1-3-a12df8a09160@gmail.com \
--to=odys.yuan@gmail.com \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=eddyz87@gmail.com \
--cc=emil@etsalapatis.com \
--cc=ihor.solodrai@linux.dev \
--cc=john.fastabend@gmail.com \
--cc=jolsa@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-kselftest@vger.kernel.org \
--cc=martin.lau@linux.dev \
--cc=memxor@gmail.com \
--cc=shuah@kernel.org \
--cc=song@kernel.org \
--cc=yonghong.song@linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®