Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751781AbdHOLxC (ORCPT ); Tue, 15 Aug 2017 07:53:02 -0400 Received: from www62.your-server.de ([213.133.104.62]:58578 "EHLO www62.your-server.de" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751196AbdHOLxA (ORCPT ); Tue, 15 Aug 2017 07:53:00 -0400 Message-ID: <5992E090.5040103@iogearbox.net> Date: Tue, 15 Aug 2017 13:52:48 +0200 From: Daniel Borkmann User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:31.0) Gecko/20100101 Thunderbird/31.7.0 MIME-Version: 1.0 To: Edward Cree , davem@davemloft.net, Alexei Starovoitov , Alexei Starovoitov CC: netdev@vger.kernel.org, linux-kernel@vger.kernel.org, iovisor-dev Subject: Re: [PATCH net-next] bpf/verifier: track liveness for pruning References: <262cf31a-b70d-3dca-c687-8bcc77726011@solarflare.com> In-Reply-To: <262cf31a-b70d-3dca-c687-8bcc77726011@solarflare.com> Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 7bit X-Authenticated-Sender: daniel@iogearbox.net Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 1722 Lines: 49 On 08/14/2017 07:55 PM, Edward Cree wrote: > State of a register doesn't matter if it wasn't read in reaching an exit; > a write screens off all reads downstream of it from all explored_states > upstream of it. > This allows us to prune many more branches; here are some processed insn > counts for some Cilium programs: > Program before after > bpf_lb_opt_-DLB_L3.o 6515 3361 > bpf_lb_opt_-DLB_L4.o 8976 5176 > bpf_lb_opt_-DUNKNOWN.o 2960 1137 > bpf_lxc_opt_-DDROP_ALL.o 95412 48537 > bpf_lxc_opt_-DUNKNOWN.o 141706 79048 > bpf_netdev.o 24251 17995 > bpf_overlay.o 10999 9385 > > The runtime is also improved; here are 'time' results in ms: > Program before after > bpf_lb_opt_-DLB_L3.o 24 6 > bpf_lb_opt_-DLB_L4.o 26 11 > bpf_lb_opt_-DUNKNOWN.o 11 2 > bpf_lxc_opt_-DDROP_ALL.o 1288 152 > bpf_lxc_opt_-DUNKNOWN.o 1768 257 > bpf_netdev.o 62 31 > bpf_overlay.o 15 13 > > Signed-off-by: Edward Cree Awesome work! [...] > if (arg_type == ARG_ANYTHING) { > if (is_pointer_value(env, regno)) { > @@ -1639,10 +1675,13 @@ static int check_call(struct bpf_verifier_env *env, int func_id, int insn_idx) > } > > /* reset caller saved regs */ > - for (i = 0; i < CALLER_SAVED_REGS; i++) > + for (i = 0; i < CALLER_SAVED_REGS; i++) { > mark_reg_not_init(regs, caller_saved[i]); > + check_reg_arg(env, i, DST_OP_NO_MARK); Don't we need the same in check_ld_abs() since we treat it similar to a function call? > + } > > /* update return register */ > + check_reg_arg(env, BPF_REG_0, DST_OP_NO_MARK); [...]