From: Edward Cree <ecree@solarflare.com>
To: <davem@davemloft.net>,
Alexei Starovoitov <alexei.starovoitov@gmail.com>,
Alexei Starovoitov <ast@fb.com>,
Daniel Borkmann <daniel@iogearbox.net>
Cc: <netdev@vger.kernel.org>,
iovisor-dev <iovisor-dev@lists.iovisor.org>,
LKML <linux-kernel@vger.kernel.org>
Subject: [RFC PATCH net-next 0/5] bpf: rewrite value tracking in verifier
Date: Wed, 7 Jun 2017 15:55:57 +0100 [thread overview]
Message-ID: <92db9689-af6a-e172-ba57-195e588f9cc0@solarflare.com> (raw)
This series simplifies alignment tracking, generalises bounds tracking and
fixes some bounds-tracking bugs in the BPF verifier. Pointer arithmetic on
packet pointers, stack pointers, map value pointers and context pointers has
been unified, and bounds on these pointers are only checked when the pointer
is dereferenced.
Operations on pointers which destroy all relation to the original pointer
(such as multiplies and shifts) are disallowed if !env->allow_ptr_leaks,
otherwise they convert the pointer to an unknown scalar and feed it to the
normal scalar arithmetic handling.
Pointer types have been unified with the corresponding adjusted-pointer types
where those existed (e.g. PTR_TO_MAP_VALUE[_ADJ] or FRAME_PTR vs
PTR_TO_STACK); similarly, CONST_IMM and UNKNOWN_VALUE have been unified into
SCALAR_VALUE.
Pointer types (except CONST_PTR_TO_MAP, PTR_TO_MAP_VALUE_OR_NULL and
PTR_TO_PACKET_END, which do not allow arithmetic) have a 'fixed offset' and
a 'variable offset'; the former is used when e.g. adding an immediate or a
known-constant register, as long as it does not overflow. Otherwise the
latter is used, and any operation creating a new variable offset creates a
new 'id' (and, for PTR_TO_PACKET, clears the 'range').
SCALAR_VALUEs use the 'variable offset' fields to track the range of possible
values; the 'fixed offset' should never be set on a scalar.
Patch 2/5 is rather on the big side, but since it changes the contents and
semantics of a fairly central data structure, I'm not really sure how to go
about splitting it up further without producing broken intermediate states.
With the changes in patch 5/5, all tools/testing/selftests/bpf/test_verifier
tests pass.
Edward Cree (5):
selftests/bpf: add test for mixed signed and unsigned bounds checks
bpf/verifier: rework value tracking
bpf/verifier: feed pointer-to-unknown-scalar casts into scalar ALU
path
bpf/verifier: track signed and unsigned min/max values
selftests/bpf: change test_verifier expectations
include/linux/bpf.h | 34 +-
include/linux/bpf_verifier.h | 56 +-
include/linux/tnum.h | 58 +
kernel/bpf/Makefile | 2 +-
kernel/bpf/tnum.c | 163 +++
kernel/bpf/verifier.c | 1852 ++++++++++++++++-----------
tools/testing/selftests/bpf/test_verifier.c | 248 ++--
7 files changed, 1482 insertions(+), 931 deletions(-)
create mode 100644 include/linux/tnum.h
create mode 100644 kernel/bpf/tnum.c
next reply other threads:[~2017-06-07 14:56 UTC|newest]
Thread overview: 25+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-06-07 14:55 Edward Cree [this message]
2017-06-07 14:58 ` [RFC PATCH net-next 1/5] selftests/bpf: add test for mixed signed and unsigned bounds checks Edward Cree
2017-06-07 14:58 ` [RFC PATCH net-next 2/5] bpf/verifier: rework value tracking Edward Cree
2017-06-08 2:32 ` Alexei Starovoitov
2017-06-08 14:53 ` Edward Cree
2017-06-08 16:45 ` Alexei Starovoitov
2017-06-08 19:38 ` Edward Cree
2017-06-08 21:20 ` Alexei Starovoitov
2017-06-09 13:25 ` Daniel Borkmann
2017-06-07 14:58 ` [RFC PATCH net-next 3/5] bpf/verifier: feed pointer-to-unknown-scalar casts into scalar ALU path Edward Cree
2017-06-08 2:35 ` Alexei Starovoitov
2017-06-08 15:25 ` Edward Cree
2017-06-08 16:50 ` Alexei Starovoitov
2017-06-08 17:12 ` Edward Cree
2017-06-08 18:41 ` Alexei Starovoitov
2017-06-08 19:07 ` Edward Cree
2017-06-08 21:17 ` Alexei Starovoitov
2017-06-07 14:59 ` [RFC PATCH net-next 4/5] bpf/verifier: track signed and unsigned min/max values Edward Cree
2017-06-08 2:40 ` Alexei Starovoitov
2017-06-08 15:23 ` Edward Cree
2017-06-08 16:47 ` Alexei Starovoitov
2017-06-07 15:00 ` [RFC PATCH net-next 5/5] selftests/bpf: change test_verifier expectations Edward Cree
2017-06-08 2:43 ` Alexei Starovoitov
2017-06-08 15:27 ` Edward Cree
2017-06-08 20:18 ` [RFC PATCH net-next 0/5] bpf: rewrite value tracking in verifier David Miller
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=92db9689-af6a-e172-ba57-195e588f9cc0@solarflare.com \
--to=ecree@solarflare.com \
--cc=alexei.starovoitov@gmail.com \
--cc=ast@fb.com \
--cc=daniel@iogearbox.net \
--cc=davem@davemloft.net \
--cc=iovisor-dev@lists.iovisor.org \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®