Re: [PATCH bpf v4 2/4] bpf: Preserve pointer state for commuted arithmetic
Shung-Hsi Yu <[email protected]>
| Newsgroups | org.kernel.vger.linux-kselftest,org.kernel.vger.bpf,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <amsJ3D8P46GcsKwp@u94a> |
On Wed, Jul 29, 2026 at 03:18:28PM +0000, Yiyang Chen via B4 Relay wrote: > From: Yiyang Chen <[email protected]> > > When scalar += pointer is handled in adjust_ptr_min_max_vals(), the > destination register inherits the pointer state from the source pointer. > Copying only selected fields is fragile because pointer provenance is > tracked by several bpf_reg_state fields. > > Use the caller's temporary offset register to preserve the scalar operand > while replacing the destination with the full pointer state. This preserves > the frame number for PTR_TO_STACK registers and keeps parent identity > fields consistent. > > Fixes: f4d7e40a5b71 ("bpf: introduce function calls (verification)") > Signed-off-by: Yiyang Chen <[email protected]> > Tested-by: Daniel Wade <[email protected]> > Signed-off-by: Eduard Zingerman <[email protected]> Acked-by: Shung-Hsi Yu <[email protected]>