On 2026/7/22 19:10, Pu Lehui wrote:
> 
> 
> On 2026/7/22 12:21, Feng Jiang wrote:
>> Add a test that checks R0-R5 are preserved across
>> arch_bpf_timed_may_goto() calls.
>>
>> Use bpf_get_prandom_u32() to avoid the verifier removing the checks
>> via DCE.
>>
>> Suggested-by: Björn Töpel <[email protected]>
>> Signed-off-by: Feng Jiang <[email protected]>
>> ---
>>   .../selftests/bpf/progs/verifier_may_goto_1.c      | 57 
>> ++++++++++++++++++++++
>>   1 file changed, 57 insertions(+)
>>
>> diff --git a/tools/testing/selftests/bpf/progs/verifier_may_goto_1.c 
>> b/tools/testing/selftests/bpf/progs/verifier_may_goto_1.c
>> index 4bdf4256a41e..98d59108d097 100644
>> --- a/tools/testing/selftests/bpf/progs/verifier_may_goto_1.c
>> +++ b/tools/testing/selftests/bpf/progs/verifier_may_goto_1.c
>> @@ -106,4 +106,61 @@ __naked void may_goto_batch_2(void)
>>       : __clobber_all);
>>   }
>>   +/*
>> + * Use bpf_get_prandom_u32() to prevent DCE from removing the checks.
>> + * retval: 0=all ok, 1-6=R0-R5 clobbered.
>> + */
>> +SEC("raw_tp")
>> +__description("timed may_goto preserves R0-R5")
>> +__arch_x86_64
>> +__arch_arm64
>> +__arch_riscv64
>> +__success
>> +__retval(0)
> 
> __arch_s390x is also supported timed_may_goto

Will add it in v5.

> 
>> +__naked void timed_may_goto_preserves_regs(void)
>> +{
>> +    asm volatile (
>> +    "call %[bpf_get_prandom_u32];"
>> +    "r6 = r0;"
>> +    "r0 = 0x1111;"
>> +    "r0 += r6;"
>> +    "r1 = 0x2222;"
>> +    "r1 += r6;"
>> +    "r2 = 0x3333;"
>> +    "r2 += r6;"
>> +    "r3 = 0x4444;"
>> +    "r3 += r6;"
>> +    "r4 = 0x5555;"
>> +    "r4 += r6;"
>> +    "r5 = 0x6666;"
>> +    "r5 += r6;"
>> +    ".8byte %[may_goto];"
>> +    ".8byte %[loop];"
>> +    "r0 -= r6;"
>> +    "r1 -= r6;"
>> +    "r2 -= r6;"
>> +    "r3 -= r6;"
>> +    "r4 -= r6;"
>> +    "r5 -= r6;"
>> +    "if r0 != 0x1111 goto 1f;"
>> +    "if r1 != 0x2222 goto 2f;"
>> +    "if r2 != 0x3333 goto 3f;"
>> +    "if r3 != 0x4444 goto 4f;"
>> +    "if r4 != 0x5555 goto 5f;"
>> +    "if r5 != 0x6666 goto 6f;"
>> +    "r0 = 0;"
>> +    "exit;"
>> +    "1: r0 = 1; exit;"
>> +    "2: r0 = 2; exit;"
>> +    "3: r0 = 3; exit;"
>> +    "4: r0 = 4; exit;"
>> +    "5: r0 = 5; exit;"
>> +    "6: r0 = 6; exit;"
>> +    :
>> +    : __imm(bpf_get_prandom_u32),
>> +      __imm_insn(may_goto, BPF_RAW_INSN(BPF_JMP | BPF_JCOND, 0, 0, 1, 0)),
>> +      __imm_insn(loop, BPF_RAW_INSN(BPF_JMP | BPF_JA, 0, 0, -2, 0))
>> +    : __clobber_all);
>> +}
>> +
>>   char _license[] SEC("license") = "GPL";
>>
> 
> not work, pls take a look

The __retval(0) annotation enables the test_run path in test_laoder.
do_prog_test_run() sets data_in/data_out/repeat by default,
which bpf_prog_test_run_raw_tp() rejects with EINVAL. Switching to
SEC("syscall") makes test_loader use empty opts. Will fix it in v5.

> 
> root@(none):/mnt/bpf# ./test_progs -v -a verifier_may_goto_1
> bpf_testmod.ko is already unloaded.
> Loading bpf_testmod.ko...
> [   26.123549] bpf_testmod: loading out-of-tree module taints kernel.
> [   26.127885] bpf_testmod: module verification failed: signature and/or 
> required key missing - tainting kernel
> Successfully loaded bpf_testmod.ko.
> tester_init:PASS:tester_log_buf 0 nsec
> process_subtest:PASS:obj_open_mem 0 nsec
> process_subtest:PASS:specs_alloc 0 nsec
> run_subtest:PASS:obj_open_mem 0 nsec
> run_subtest:PASS:unexpected_load_failure 0 nsec
> VERIFIER LOG:
> =============
> processed 43 insns (limit 1000000) max_states_per_insn 0 total_states 4 
> peak_states 5 mark_read 0
> =============
> do_prog_test_run:FAIL:1114 FAIL: Unexpected bpf_prog_test_run error: 22 
> (Invalid argument) #660/1   verifier_may_goto_1/timed may_goto preserves 
> R0-R5:FAIL
> #660     verifier_may_goto_1:FAIL
> Summary: 0/0 PASSED, 0 SKIPPED, 1 FAILED
> Successfully unloaded bpf_testmod.ko.

-- 
With Best Regards,
Feng Jiang


Reply via email to