Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1659883

[RFC PATCH net-next 0/5] bpf: rewrite value tracking in verifier

From Edward Cree <ecree@solarflare.com>
Newsgroups linux.kernel
Subject [RFC PATCH net-next 0/5] bpf: rewrite value tracking in verifier
Date 2017-06-07 17:00 +0200
Message-ID <tPKBd-7Z0-25@gated-at.bofh.it> (permalink)
Organization linux.* mail to news gateway

Show all headers | View raw


This series simplifies alignment tracking, generalises bounds tracking and
 fixes some bounds-tracking bugs in the BPF verifier.  Pointer arithmetic on
 packet pointers, stack pointers, map value pointers and context pointers has
 been unified, and bounds on these pointers are only checked when the pointer
 is dereferenced.
Operations on pointers which destroy all relation to the original pointer
 (such as multiplies and shifts) are disallowed if !env->allow_ptr_leaks,
 otherwise they convert the pointer to an unknown scalar and feed it to the
 normal scalar arithmetic handling.
Pointer types have been unified with the corresponding adjusted-pointer types
 where those existed (e.g. PTR_TO_MAP_VALUE[_ADJ] or FRAME_PTR vs
 PTR_TO_STACK); similarly, CONST_IMM and UNKNOWN_VALUE have been unified into
 SCALAR_VALUE.
Pointer types (except CONST_PTR_TO_MAP, PTR_TO_MAP_VALUE_OR_NULL and
 PTR_TO_PACKET_END, which do not allow arithmetic) have a 'fixed offset' and
 a 'variable offset'; the former is used when e.g. adding an immediate or a
 known-constant register, as long as it does not overflow.  Otherwise the
 latter is used, and any operation creating a new variable offset creates a
 new 'id' (and, for PTR_TO_PACKET, clears the 'range').
SCALAR_VALUEs use the 'variable offset' fields to track the range of possible
 values; the 'fixed offset' should never be set on a scalar.

Patch 2/5 is rather on the big side, but since it changes the contents and
 semantics of a fairly central data structure, I'm not really sure how to go
 about splitting it up further without producing broken intermediate states.

With the changes in patch 5/5, all tools/testing/selftests/bpf/test_verifier
 tests pass.

Edward Cree (5):
  selftests/bpf: add test for mixed signed and unsigned bounds checks
  bpf/verifier: rework value tracking
  bpf/verifier: feed pointer-to-unknown-scalar casts into scalar ALU
    path
  bpf/verifier: track signed and unsigned min/max values
  selftests/bpf: change test_verifier expectations

 include/linux/bpf.h                         |   34 +-
 include/linux/bpf_verifier.h                |   56 +-
 include/linux/tnum.h                        |   58 +
 kernel/bpf/Makefile                         |    2 +-
 kernel/bpf/tnum.c                           |  163 +++
 kernel/bpf/verifier.c                       | 1852 ++++++++++++++++-----------
 tools/testing/selftests/bpf/test_verifier.c |  248 ++--
 7 files changed, 1482 insertions(+), 931 deletions(-)
 create mode 100644 include/linux/tnum.h
 create mode 100644 kernel/bpf/tnum.c

Back to linux.kernel | Previous | NextNext in thread | Find similar | Unroll thread


Thread

[RFC PATCH net-next 0/5] bpf: rewrite value tracking in verifier Edward Cree <ecree@solarflare.com> - 2017-06-07 17:00 +0200
  [RFC PATCH net-next 1/5] selftests/bpf: add test for mixed signed and  unsigned bounds checks Edward Cree <ecree@solarflare.com> - 2017-06-07 17:00 +0200
  [RFC PATCH net-next 5/5] selftests/bpf: change test_verifier  expectations Edward Cree <ecree@solarflare.com> - 2017-06-07 17:10 +0200
    Re: [RFC PATCH net-next 5/5] selftests/bpf: change test_verifier  expectations Alexei Starovoitov <alexei.starovoitov@gmail.com> - 2017-06-08 04:50 +0200
      Re: [RFC PATCH net-next 5/5] selftests/bpf: change test_verifier  expectations Edward Cree <ecree@solarflare.com> - 2017-06-08 17:30 +0200
  [RFC PATCH net-next 3/5] bpf/verifier: feed pointer-to-unknown-scalar  casts into scalar ALU path Edward Cree <ecree@solarflare.com> - 2017-06-07 17:10 +0200
    Re: [RFC PATCH net-next 3/5] bpf/verifier: feed  pointer-to-unknown-scalar casts into scalar ALU path Alexei Starovoitov <alexei.starovoitov@gmail.com> - 2017-06-08 04:40 +0200
      Re: [RFC PATCH net-next 3/5] bpf/verifier: feed  pointer-to-unknown-scalar casts into scalar ALU path Edward Cree <ecree@solarflare.com> - 2017-06-08 17:30 +0200
        Re: [RFC PATCH net-next 3/5] bpf/verifier: feed  pointer-to-unknown-scalar casts into scalar ALU path Alexei Starovoitov <alexei.starovoitov@gmail.com> - 2017-06-08 19:00 +0200
          Re: [RFC PATCH net-next 3/5] bpf/verifier: feed  pointer-to-unknown-scalar casts into scalar ALU path Edward Cree <ecree@solarflare.com> - 2017-06-08 19:20 +0200
            Re: [RFC PATCH net-next 3/5] bpf/verifier: feed  pointer-to-unknown-scalar casts into scalar ALU path Alexei Starovoitov <alexei.starovoitov@gmail.com> - 2017-06-08 20:50 +0200
              Re: [RFC PATCH net-next 3/5] bpf/verifier: feed  pointer-to-unknown-scalar casts into scalar ALU path Edward Cree <ecree@solarflare.com> - 2017-06-08 21:10 +0200
                Re: [RFC PATCH net-next 3/5] bpf/verifier: feed  pointer-to-unknown-scalar casts into scalar ALU path Alexei Starovoitov <alexei.starovoitov@gmail.com> - 2017-06-08 23:20 +0200
  Re: [RFC PATCH net-next 2/5] bpf/verifier: rework value tracking Alexei Starovoitov <alexei.starovoitov@gmail.com> - 2017-06-08 04:40 +0200
    Re: [RFC PATCH net-next 2/5] bpf/verifier: rework value tracking Edward Cree <ecree@solarflare.com> - 2017-06-08 17:00 +0200
      Re: [RFC PATCH net-next 2/5] bpf/verifier: rework value tracking Alexei Starovoitov <alexei.starovoitov@gmail.com> - 2017-06-08 18:50 +0200
        Re: [RFC PATCH net-next 2/5] bpf/verifier: rework value tracking Edward Cree <ecree@solarflare.com> - 2017-06-08 21:40 +0200
          Re: [RFC PATCH net-next 2/5] bpf/verifier: rework value tracking Alexei Starovoitov <alexei.starovoitov@gmail.com> - 2017-06-08 23:30 +0200
        Re: [RFC PATCH net-next 2/5] bpf/verifier: rework value tracking Daniel Borkmann <daniel@iogearbox.net> - 2017-06-09 15:30 +0200
  Re: [RFC PATCH net-next 4/5] bpf/verifier: track signed and unsigned  min/max values Alexei Starovoitov <alexei.starovoitov@gmail.com> - 2017-06-08 04:50 +0200
    Re: [RFC PATCH net-next 4/5] bpf/verifier: track signed and unsigned  min/max values Edward Cree <ecree@solarflare.com> - 2017-06-08 17:30 +0200
      Re: [RFC PATCH net-next 4/5] bpf/verifier: track signed and unsigned  min/max values Alexei Starovoitov <alexei.starovoitov@gmail.com> - 2017-06-08 18:50 +0200
  Re: [RFC PATCH net-next 0/5] bpf: rewrite value tracking in  verifier David Miller <davem@davemloft.net> - 2017-06-08 22:20 +0200

csiph-web