From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pg1-f177.google.com (mail-pg1-f177.google.com [209.85.215.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1672037F320 for ; Thu, 13 Aug 2026 22:12:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.177 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786659156; cv=none; b=MHYhPtUdi49RrtMlNBmXHgwvqoKB6LStG2kC/K8mtSHSiEhoBgPpS8v6A+h5kmszV3JwUf2LTpPsI7GNcvsedCRIYffHc3q+UJLommhAtbutIEbGZC5pGQLJzBB9EXfPPHkK17paTmf0MS2Nf1RGmyD5DlapiRM5rJxrn/Bxaqg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786659156; c=relaxed/simple; bh=3CLsfbiIgtOoLOgVIe6+RET4gbjRHXqrpuKI1ctgShY=; h=Message-ID:Subject:From:To:Cc:Date:In-Reply-To:References: Content-Type:MIME-Version; b=O299athScHWNITfqk0mFZ9bEyQH5guvWt6CDOa+HncRi9JhCbqHgu0WvSWPnra3Wn6TITeT/2nYju2zs95bqO5IlheHIDR83P9+ssuq8ru8mfTVWOw1UQ8NPu5PDtgCAI7Th1P8M1QI86IZhX+Cv5Ul9npoep+QdFPaAkjTC07w= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=h4LtyT/F; arc=none smtp.client-ip=209.85.215.177 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="h4LtyT/F" Received: by mail-pg1-f177.google.com with SMTP id 41be03b00d2f7-ca88130e09aso181591a12.3 for ; Thu, 13 Aug 2026 15:12:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786659154; x=1787263954; darn=vger.kernel.org; h=mime-version:user-agent:content-transfer-encoding:content-type :references:in-reply-to:date:cc:to:from:subject:message-id:from:to :cc:subject:date:message-id:reply-to:content-type; bh=3CLsfbiIgtOoLOgVIe6+RET4gbjRHXqrpuKI1ctgShY=; b=h4LtyT/Fctb15OWiK7hGa81iLnrt/UiT6sbVDIHbhSIjxxgXurVYCxqtBT+MXoafwF vRwHwY/F0txOpV938gGi/Lv7oUOdQ+Ls9MIucap6cOlYTsQfPHh7ysLYeGKycuQdaXxh 9iPOmZh+R9YXT9cE6Dkx2sV/snDaJqEWCEaFKkcImxOUkUbBQZlcWZy1E4UES23ue1lz k52pwIuHhm4a+bUNYZZoU1KMQEmp0FXwYZjQev8idSeM0zU+09I2SRiVJtfPvZoNKQ2V pkRK2K1pT7Al38Q4jVdKXYqBXR2XRSa0amPsq9ZpEwT1jnrb8UpVmLHvjDSTxAEw74eP 0dSA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786659154; x=1787263954; h=mime-version:user-agent:content-transfer-encoding:content-type :references:in-reply-to:date:cc:to:from:subject:message-id:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=3CLsfbiIgtOoLOgVIe6+RET4gbjRHXqrpuKI1ctgShY=; b=sadBx5Qc5n2cPPjjmjvmCyP6ZIEM5/+bUPdyqwNXebHsZMcizlAJo1ViE3tsOqbViF mpt97fBl62tRD1E2N6843fREBkHApGCg8+r8a5WPSO89ZyJkWdYMpwQOWiWpQV9WSiLm 4eI7W8tMgVkitDzMPlcOPD7UHXOhgA069v3K+NyGQysFqQ68zTmgufHRxEWJZWTIsjOd oZMYqh1X1B1+GTKpVdxxxVJ4ImrUkbYTIY4kZa75pcJ1BFrlxqTv/wtkfrA7HaMv27VR Na+Ni6GKqmXNlUrT+q/L3xul99xCF/80oIODqd/EBKmxxexAYB6zsA+sTFLMjJCAFt4Y zyaA== X-Forwarded-Encrypted: i=1; AHgh+Rqz6b9QhiIceoVzu3uHm/RGwxuQ1dgOHR4VepmyFMrh6o7mtHG3ENfB00bhYP7+hHZ85zTP5SnKCZASa1U=@vger.kernel.org X-Gm-Message-State: AOJu0YzRjDS8lm0PLEw3+a+Fe/dssX/SbsEoXnBbJZU2ly0Hq/QbpWu2 8iJqVkFOBbG5WdWsyOFwGuGWWEO871O1SYz+TuXjtGvd3dSGTecfH3a4 X-Gm-Gg: AR+sD11hqE1W0s1nHMckHCoyqhwCwPWn6/ytcpq+5r6dQYiRrF78jELKoZYKtZnlUeT WlxI/Sm1T93Rr8BsZWu0svRnMogak7L9eFHv0X3JtjJKaPutuKyVDbSHIrpFUVucKDSR/TyOX1i r7gOOyOuBp8e4LOSltI6ujGLDUQQpSK9sFMqcS93rI3aQ/zCfWbfoSNVd9fDpnKKfuMoF2SBkNQ DpYFBJGtEQBSxnI1I+u/9ZGKAT83j2PYsmtAXEfQORJBCAbisSogjDP3FgWcmvF3LKWPMFDRNyc BBZ1UBP3dcL7M8vQnm1WUm0iuCfXSnmwEK+7ns7VP1kyqAtBpU67R4ugHPYjFiKtfZd3qGzkHqB dQnzlU2g9E1gEg0fTsd8A8dyvYZb0cTOECtglyzi9/PcEPfuDqyXcq1JzWHVJyJXA0OWlX68GdK zGRoo+TCWE0QJFW4YXzOZeh70HP6M1McFrxLDsVST4edV0Wp8sMHvAM57zYOr9/mxdT161NXS6W /CPxm/ktqMZ9nX6YA+B9i7IG9wLMK/uwhhsGnZm2A8nkQ== X-Received: by 2002:a05:6a21:6e8e:b0:3c6:61c6:8970 with SMTP id adf61e73a8af0-3cc71a89da7mr1174469637.14.1786659154308; Thu, 13 Aug 2026 15:12:34 -0700 (PDT) Received: from ?IPv6:2a03:83e0:115c:1:2cae:4c28:2903:b6f9? ([2620:10d:c090:500::7:1c5e]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-31f7c8018cdsm5251871eec.13.2026.08.13.15.12.31 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 13 Aug 2026 15:12:33 -0700 (PDT) Message-ID: <36504bb7f4ab5a4a6c24252afe316ac393ea5e3e.camel@gmail.com> Subject: Re: [PATCH bpf-next 1/2] bpf: Check pointer type for all atomic RMW paths From: Eduard Zingerman To: Yiyang Chen , Alexei Starovoitov , Daniel Borkmann , John Fastabend , Andrii Nakryiko , Kumar Kartikeya Dwivedi , Martin KaFai Lau , Song Liu , Yonghong Song , Jiri Olsa , Emil Tsalapatis , Ihor Solodrai , Shuah Khan Cc: bpf@vger.kernel.org, linux-kernel@vger.kernel.org, linux-kselftest@vger.kernel.org Date: Thu, 13 Aug 2026 15:12:30 -0700 In-Reply-To: <20260813-bpf-next-038-mixed-atomic-v1-v1-1-e79aadb46a8a@mails.tsinghua.edu.cn> References: <20260813-bpf-next-038-mixed-atomic-v1-v1-0-e79aadb46a8a@mails.tsinghua.edu.cn> <20260813-bpf-next-038-mixed-atomic-v1-v1-1-e79aadb46a8a@mails.tsinghua.edu.cn> Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable User-Agent: Evolution 3.60.1 (3.60.1-1.fc44) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 On Thu, 2026-08-13 at 12:01 +0000, Yiyang Chen wrote: > Atomic RMW verification records an instruction pointer type only when the > current destination is PTR_TO_ARENA. A second path can therefore reach th= e > same instruction with an ordinary pointer without comparing it against th= e > saved arena type. >=20 > The post-verification fixup uses the saved type to rewrite the instructio= n > to BPF_PROBE_ATOMIC for every path. Record the actual destination type fo= r > all atomic RMW paths so the existing mismatch check rejects incompatible > uses of one instruction. >=20 > Fixes: d503a04f8bc0 ("bpf: Add support for certain atomics in bpf_arena t= o x86 JIT") > Signed-off-by: Yiyang Chen > --- Acked-by: Eduard Zingerman Looks like this was the only missing case for save_aux_ptr_type(). I wonder if we should pull the save_aux_ptr_type() call from it's current positions to do_check_insn() itself. ...