Re: [PATCH bpf-next v7 1/6] bpf: Track verifier instruction stats for each subprogram

Eduard Zingerman <[email protected]>
Newsgroups org.kernel.vger.bpf
Message-ID <[email protected]>
On Sat, 2026-08-08 at 08:25 +0200, Kumar Kartikeya Dwivedi wrote:
> The verifier currently records one instruction count for the main program
> and each global subprogram checked independently. Static subprograms are
> explored within callers, so their verification cost cannot be reported
> separately.
> 
> Track both self and inclusive instruction counts for every subprogram.
> Charge each processed instruction as self work to the current subprogram and
> to a path-local subtotal in its function frame. When a function returns, add
> the callee subtotal to its inclusive count and to its parent subtotal. Fold
> any remaining frames when a path terminates or is pruned.
> 
> Instruction subtotals are accounting state, not semantic verifier state.
> Clear them when a verifier state is copied so work before a path fork is
> charged once, rather than again when a saved branch is explored. If copying
> a saved state fails before all frames are allocated, skip missing frames
> while folding the current path.
> 
> This generic frame accounting also records self and inclusive totals when an
> asynchronous callback starts as a fresh frame-zero state. It does not yet
> charge that independently explored callback path back to the main or global
> exploration root which scheduled it. That will be done in subsequent
> changes.
> 
> This does not change the verification statistics output format. It only
> prepares the counters for per-subprogram reporting.
> 
> Signed-off-by: Kumar Kartikeya Dwivedi <[email protected]>
> ---

Acked-by: Eduard Zingerman <[email protected]>

>  include/linux/bpf_verifier.h |  5 +++-
>  kernel/bpf/verifier.c        | 55 ++++++++++++++++++++++++++++++------
>  2 files changed, 50 insertions(+), 10 deletions(-)
> 
> diff --git a/include/linux/bpf_verifier.h b/include/linux/bpf_verifier.h
> index a2a40caca0a0..f16ee6602179 100644
> --- a/include/linux/bpf_verifier.h
> +++ b/include/linux/bpf_verifier.h
> @@ -385,6 +385,8 @@ struct bpf_func_state {
>  	 *                           | number of simulations is tracked in frame N
>  	 */
>  	u32 callback_depth;
> +	/* Instructions processed in this frame and callees on the current path. */
> +	u32 insns_subtotal;

Another possibility is to have the array of counters in the
bpf_verifier_env itself. But I don't want to push for another respin.

>  	/* The following fields should be last. See copy_func_state() */
>  	/* The state of the stack. Each element of the array describes BPF_REG_SIZE

...
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.