Re: [PATCH bpf-next v2 2/2] selftests/bpf: Cover mixed arena and stack atomics

Eduard Zingerman <[email protected]>
Newsgroups org.kernel.vger.linux-kselftest,org.kernel.vger.bpf,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On Sun, 2026-08-16 at 10:56 +0000, Yiyang Chen wrote:
> Add a verifier test with one atomic RMW instruction reached through
> PTR_TO_ARENA and PTR_TO_STACK paths. The verifier must reject the
> shared instruction with the existing incompatible-pointer diagnostic.
> 
> Signed-off-by: Yiyang Chen <[email protected]>
> ---
>  tools/testing/selftests/bpf/progs/verifier_arena.c | 39 ++++++++++++++++++++++
>  1 file changed, 39 insertions(+)
> 
> diff --git a/tools/testing/selftests/bpf/progs/verifier_arena.c b/tools/testing/selftests/bpf/progs/verifier_arena.c
> index b241bbcf54a8a..b22bab33301ab 100644
> --- a/tools/testing/selftests/bpf/progs/verifier_arena.c
> +++ b/tools/testing/selftests/bpf/progs/verifier_arena.c
> @@ -637,6 +637,45 @@ int non_arena_ptr_add_to_arena_ptr(void *ctx)
>  
>  #endif
>  
> +static const struct bpf_insn addr_space_cast_insn = {
> +	.code = 0xbf,
> +	.dst_reg = BPF_REG_7,
> +	.src_reg = BPF_REG_7,
> +	.off = 1,
> +	.imm = 1,
> +};
> +
> +SEC("socket")
> +__description("arena and stack atomic at the same instruction")
> +__failure __msg("same insn cannot be used with different pointers")
> +__arch_x86_64
> +__load_if_JITed()
> +__naked void mixed_arena_stack_atomic(void)
> +{
> +	asm volatile ("					\
> +	r1 = %[arena] ll;				\
> +	r6 = r10;					\
> +	r6 += -8;					\
> +	r9 = 0;					\
> +	*(u64 *)(r6 + 0) = r9;			\
> +	r7 = 8192;					\
> +	.8byte %[addr_space_cast];			\

I'm going to fix this to:

	r7 = addr_space_cast(r7, 0, 1);			\

as in the test case above.
Waiting for CI [1].

[1] https://github.com/kernel-patches/bpf/pull/13325

> +	call %[bpf_get_prandom_u32];			\
> +	if w0 != 0 goto 1f;				\
> +	r8 = r6;					\
> +	goto 2f;					\
> +1:	r8 = r7;					\
> +2:	r9 = 1;					\
> +	lock *(u64 *)(r8 + 0) += r9;			\
> +	r0 = 0;					\
> +	exit;						\
> +"	:
> +	: __imm_addr(arena),
> +	  __imm_insn(addr_space_cast, addr_space_cast_insn),
> +	  __imm(bpf_get_prandom_u32)
> +	: __clobber_all);
> +}
> +
>  static __noinline
>  u32 __arena *check_arena_arg_nonglobal(u32 __arena *arg)
>  {
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.