On Thu, 2026-07-23 at 12:25 +0800, Shung-Hsi Yu wrote: ...
> The sole purpose of having orig_off_reg seem to be for satisfying the > 'off_reg == dst_reg' conditional in sanitize_err(). If that's the case, > maybe it is better to change sanitize_err to accept an ptr_is_dst_reg > argument too. > > And given now that we are starting to make more use of scratch register > states, it seems better to get rid the likes of 'off_reg == dst_reg' all > together, and simply have ptr_is_dst_reg passed down by > adjust_scalar_min_max_vals(). > > > diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c > index 52be0a118cce..72d49f2a57a3 100644 > --- a/kernel/bpf/verifier.c > +++ b/kernel/bpf/verifier.c > @@ -13505,13 +13505,13 @@ static int sanitize_ptr_alu(struct bpf_verifier_env > *env, > const struct bpf_reg_state *off_reg, > struct bpf_reg_state *dst_reg, > struct bpf_sanitize_info *info, > - const bool commit_window) > + const bool commit_window, > + const bool ptr_is_dst_reg) That's a bit invasive. I think the simplest thing to do is to drop off_reg and dst_reg parameters from sanitize_err() and re-derive the information about which one is a pointer. ...

