From: David Windsor <dwindsor@gmail.com>
To: bpf@vger.kernel.org
Cc: ast@kernel.org, daniel@iogearbox.net, john.fastabend@gmail.com,
andrii@kernel.org, martin.lau@linux.dev, eddyz87@gmail.com,
song@kernel.org, yonghong.song@linux.dev, kpsingh@kernel.org,
sdf@fomichev.me, haoluo@google.com, jolsa@kernel.org,
shuah@kernel.org, linux-kernel@vger.kernel.org,
linux-kselftest@vger.kernel.org, yunwei356@gmail.com,
David Windsor <dwindsor@gmail.com>
Subject: [PATCH bpf 1/2] bpf: Fix state pruning regression in bpf_loop() callbacks
Date: Thu, 8 Oct 2026 19:36:22 -0400 [thread overview]
Message-ID: <20261008233623.4011127-1-dwindsor@gmail.com> (raw)
Commit f597664454bd ("bpf: bpf_scc_visit instance and backedges
accumulation for bpf_loop()") left dead stack slots in cached callback
states while SCC backedges were pending, defeating state pruning and
causing previously valid programs to hit the verifier instruction limit. On
affected kernels, ActPlane fails to load with -E2BIG.
Removing the incomplete_read_marks() check from clean_live_states() is
safe because zero-branch states have already had their stack read/write
effects propagated into the liveness masks consumed by
clean_verifier_state(). Pending SCC backedges only defer verifier-state
precision propagation and cannot add stack-liveness requirements after
cleanup.
Fixes: f597664454bd ("bpf: bpf_scc_visit instance and backedges accumulation for bpf_loop()")
Signed-off-by: David Windsor <dwindsor@gmail.com>
diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
index e3814152b52f8139a5565b2e4ac1b80d82d1ea65..1e300ca71a8a833eb4c2a340b4f94342f54af5f2 100644
--- a/kernel/bpf/verifier.c
+++ b/kernel/bpf/verifier.c
@@ -19791,8 +19791,6 @@ static void clean_live_states(struct bpf_verifier_env *env, int insn,
if (sl->state.cleaned)
/* all regs in this state in all frames were already marked */
continue;
- if (incomplete_read_marks(env, &sl->state))
- continue;
clean_verifier_state(env, &sl->state);
}
}
--
2.53.0
next reply other threads:[~2026-10-08 23:36 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-08 23:36 David Windsor [this message]
2026-10-08 23:36 ` [PATCH bpf 2/2] selftests/bpf: cover bpf_loop() state pruning regression David Windsor
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261008233623.4011127-1-dwindsor@gmail.com \
--to=dwindsor@gmail.com \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=eddyz87@gmail.com \
--cc=haoluo@google.com \
--cc=john.fastabend@gmail.com \
--cc=jolsa@kernel.org \
--cc=kpsingh@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-kselftest@vger.kernel.org \
--cc=martin.lau@linux.dev \
--cc=sdf@fomichev.me \
--cc=shuah@kernel.org \
--cc=song@kernel.org \
--cc=yonghong.song@linux.dev \
--cc=yunwei356@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®