• Puranjay Mohan's avatar
    bpf: verifier: fix addr_space_cast from as(1) to as(0) · f7f5d180
    Puranjay Mohan authored
    The verifier currently converts addr_space_cast from as(1) to as(0) that
    is: BPF_ALU64 | BPF_MOV | BPF_X with off=1 and imm=1
    to
    BPF_ALU | BPF_MOV | BPF_X with imm=1 (32-bit mov)
    
    Because of this imm=1, the JITs that have bpf_jit_needs_zext() == true,
    interpret the converted instruction as BPF_ZEXT_REG(DST) which is a
    special form of mov32, used for doing explicit zero extension on dst.
    These JITs will just zero extend the dst reg and will not move the src to
    dst before the zext.
    
    Fix do_misc_fixups() to set imm=0 when converting addr_space_cast to a
    normal mov32.
    
    The JITs that have bpf_jit_needs_zext() == true rely on the verifier to
    emit zext instructions. Mark dst_reg as subreg when doing cast from
    as(1) to as(0) so the verifier emits a zext instruction after the mov.
    
    Fixes: 6082b6c3 ("bpf: Recognize addr_space_cast instruction in the verifier.")
    Signed-off-by: default avatarPuranjay Mohan <puranjay12@gmail.com>
    Link: https://lore.kernel.org/r/20240321153939.113996-1-puranjay12@gmail.comSigned-off-by: default avatarAlexei Starovoitov <ast@kernel.org>
    f7f5d180
verifier.c 637 KB