Received: by 2002:a05:7412:40d:b0:e2:908c:2ebd with SMTP id 13csp357059rdf; Tue, 21 Nov 2023 04:57:27 -0800 (PST) X-Google-Smtp-Source: AGHT+IHBOxuXURCzCaVsDHEC4toC7wg7xQsfCB+ZDx+3N2/XIb55EsU3uU/bJY9IzwjIQDmTNmEA X-Received: by 2002:a05:6a21:1444:b0:187:9f36:c30a with SMTP id oc4-20020a056a21144400b001879f36c30amr7099385pzb.39.1700571446784; Tue, 21 Nov 2023 04:57:26 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1700571446; cv=none; d=google.com; s=arc-20160816; b=JosxtgaOK9F/uBkwl7v+dLb+CSlq98M4X/fbyf+t7EysPGoNsrCctz4H1lIpkdtujl 3uewicqmj9eHMKYHGZgIWneZIFYdsgpvi8cowgrTgpG8OPoeaW3wEBM/eUbx8USx6ZU2 Jt9aoh4N+GESR0TsH5MORmMBMzKM28cep6V5+2F22IlnMgJZGiWzOO1acsQSh9itxAcb 8kdtiyjXNd5PIreoXhMuyoCvi3Unxx3XEaKxyPzcEG8L3vWUZBF57JX5xJtZiZZntxHT Y0bj9QGclESr5168mtg5CjCJHlsGsRiVBv7t1gWHJ1bq4cRl+6cteIvnkuA5lE3CCakQ wUlw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:cc:to:subject:message-id:date:from:mime-version :dkim-signature; bh=KaNbwqPl61g5/VVIpWWsVaeAPw/KN3S1vGwln5onZww=; fh=fx/6d6y3JYhAXIHv3k8iVL8razJQmB1D2Yoyd+YmUwA=; b=yioUfvgalpg9P6vJXRyOLOFF5U1Y9Vgqs4oiuTci6gt8H3cnda+VTOPHVFx4uEGF66 NW3tvMBF1ra7cBVoyj0bqpS0TkdsOE6U5E64LfzHve1BnkZ8rx0PajxdI5RSljr64/XQ BtaIt5SgFOGGFECa4GsfT9uFm104Xj/zy0EazxNCeeAX/yY6yvQZU52CM23p0TmF8HPm rn4ZEqdJd7DZGBwLzd9m0MjTPikWPPN9voOU0V496n2196SbB16fAIA3k4rNYgyoHPS1 G8ZFNADHVYSSavjhjle2n4hYXkpj6tHCVkU+7voTlCS90w6xZ2eLl8fgD3AkX+/Cmqyf hjIg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20230601 header.b=Rhi2T9V2; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::3:3 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from lipwig.vger.email (lipwig.vger.email. [2620:137:e000::3:3]) by mx.google.com with ESMTPS id kk1-20020a17090b4a0100b0027000086c93si10632606pjb.102.2023.11.21.04.57.26 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 21 Nov 2023 04:57:26 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::3:3 as permitted sender) client-ip=2620:137:e000::3:3; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20230601 header.b=Rhi2T9V2; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::3:3 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: from out1.vger.email (depot.vger.email [IPv6:2620:137:e000::3:0]) by lipwig.vger.email (Postfix) with ESMTP id 41AA8806E3C6; Tue, 21 Nov 2023 04:57:24 -0800 (PST) X-Virus-Status: Clean X-Virus-Scanned: clamav-milter 0.103.11 at lipwig.vger.email Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S233718AbjKUM5N (ORCPT + 99 others); Tue, 21 Nov 2023 07:57:13 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:46050 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S233613AbjKUM5N (ORCPT ); Tue, 21 Nov 2023 07:57:13 -0500 Received: from mail-yb1-xb35.google.com (mail-yb1-xb35.google.com [IPv6:2607:f8b0:4864:20::b35]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 57E96D4D; Tue, 21 Nov 2023 04:57:09 -0800 (PST) Received: by mail-yb1-xb35.google.com with SMTP id 3f1490d57ef6-da041ffef81so5495043276.0; Tue, 21 Nov 2023 04:57:09 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1700571428; x=1701176228; darn=vger.kernel.org; h=cc:to:subject:message-id:date:from:mime-version:from:to:cc:subject :date:message-id:reply-to; bh=KaNbwqPl61g5/VVIpWWsVaeAPw/KN3S1vGwln5onZww=; b=Rhi2T9V2Cys87iWNYNZK+K8ZZdgZ9bwbqG1rVsk/iyK21JY0RifkrQS6G028pcWMC9 EHZ2tQCLp67268d1p+reoQp50STTAV4G/pppOk4OUdTsqfqRmnIe0cU4QwcrVVLQ8SrL k+cmsj5Bn0Wb1zompdVJCfw268T6Usy2UMVbiUdwhxdgUC+ym+ITGDzL8RpKveQ4BB2l YO4/ebdR75yMUO0fYHn9h6zLeJdZj02qnpxvRTclKooFWy4RnA+QevIyEVfph2YQSsfg Xm/+rXNrgF1Aw72YST+fK8eG6D3fPWY2PaP8zerZKLYkO35Gm2gevMCh8ASQR8vDqTSq brHg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1700571428; x=1701176228; h=cc:to:subject:message-id:date:from:mime-version:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=KaNbwqPl61g5/VVIpWWsVaeAPw/KN3S1vGwln5onZww=; b=KBm1/zyeJb+Co36jY6IttTp58BcwXgTq6k+0gqdQEpmVZ5T2/Mj1xAErFVuXWiPHVI IgXm9loF7IWUTrhzZKDk7cH2IBPA1FQm8rNucz262FXhzyCzJTzwHJD39SjCe5lBrGey +ktz4Ae+2f40vQAwmvgS0KU9d6HoNqp7xxBOvjhm6GjUUZHJTVgzzheurso6jZ3mr4HC sol35t0hYgmeo7sjJknyZ/vnNP3kuhJCtoDGWJfRj3BhTUHfVOmwOroMtnEpUk5l6KaA 3+c27kUG3B0/dHQXRlDo+JeIiAOVqyWsf0gx8SlkvToBQXCo92qILtljg2EZvhDsuIia bYHw== X-Gm-Message-State: AOJu0Yzo7Ph6yyqy9eWX2fmiY2EjM7pCZ8g8lnnEKuOTXYr/mBZ4/WgI HM3BR6s/5slzsb3slaQ4EuReIVC7qc7nysjp9g== X-Received: by 2002:a25:a565:0:b0:da0:c49a:5fe4 with SMTP id h92-20020a25a565000000b00da0c49a5fe4mr10432141ybi.24.1700571428454; Tue, 21 Nov 2023 04:57:08 -0800 (PST) MIME-Version: 1.0 From: Hao Sun Date: Tue, 21 Nov 2023 13:56:57 +0100 Message-ID: Subject: [Bug Report] bpf: reg invariant voilation after JSET To: Andrii Nakryiko , Alexei Starovoitov , Daniel Borkmann , John Fastabend , Martin KaFai Lau , Song Liu , Yonghong Song , KP Singh , Stanislav Fomichev , Jiri Olsa Cc: bpf , Linux Kernel Mailing List Content-Type: text/plain; charset="UTF-8" X-Spam-Status: No, score=-0.6 required=5.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,FREEMAIL_FORGED_FROMDOMAIN,FREEMAIL_FROM, HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,SPF_HELO_NONE, SPF_PASS,T_SCC_BODY_TEXT_LINE autolearn=unavailable autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lipwig.vger.email Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org X-Greylist: Sender passed SPF test, not delayed by milter-greylist-4.6.4 (lipwig.vger.email [0.0.0.0]); Tue, 21 Nov 2023 04:57:24 -0800 (PST) Hi, The following program (reduced) breaks reg invariant: C Repro: https://pastebin.com/raw/FmM9q9D4 -------- Verifier Log -------- func#0 @0 0: R1=ctx() R10=fp0 0: (18) r8 = 0x3d ; R8_w=61 2: (85) call bpf_ktime_get_ns#5 ; R0_w=scalar() 3: (ce) if w8 s< w0 goto pc+1 ; R0_w=scalar(smax32=61) R8_w=61 4: (95) exit from 3 to 5: R0_w=scalar(smin=0x800000000000003e,smax=0x7fffffff7fffffff,umin=smin32=umin32=62,umax=0xffffffff7fffffff,umax32=0x7fffffff,var_off=(0x0; 0xffffffff7fffffff)) R8_w=61 R10=fp0 5: R0_w=scalar(smin=0x800000000000003e,smax=0x7fffffff7fffffff,umin=smin32=umin32=62,umax=0xffffffff7fffffff,umax32=0x7fffffff,var_off=(0x0; 0xffffffff7fffffff)) R8_w=61 R10=fp0 5: (45) if r0 & 0xfffffff7 goto pc+2 REG INVARIANTS VIOLATION (false_reg1): range bounds violation u64=[0x3e, 0x8] s64=[0x3e, 0x8] u32=[0x3e, 0x8] s32=[0x3e, 0x8] var_off=(0x0, 0x8) 5: R0_w=scalar(var_off=(0x0; 0x8)) 6: (dd) if r0 s<= r8 goto pc+1 REG INVARIANTS VIOLATION (false_reg1): range bounds violation u64=[0x0, 0x8] s64=[0x3e, 0x8] u32=[0x0, 0x8] s32=[0x0, 0x8] var_off=(0x0, 0x8) 6: R0_w=scalar(var_off=(0x0; 0x8)) R8_w=61 7: (bc) w1 = w0 ; R0=scalar(var_off=(0x0; 0x8)) R1=scalar(smin=smin32=0,smax=umax=smax32=umax32=8,var_off=(0x0; 0x8)) 8: (95) exit from 6 to 8: safe from 5 to 8: safe processed 10 insns (limit 1000000) max_states_per_insn 0 total_states 1 peak_states 1 mark_read 1 The tnum after #5 is correct, but the ranges are incorrect, which seems a bug in reg_bounds_sync(). Thoughts? Best Hao Sun