On Thu, 2026-07-23 at 12:25 +0800, Shung-Hsi Yu wrote:

...

> The sole purpose of having orig_off_reg seem to be for satisfying the
> 'off_reg == dst_reg' conditional in sanitize_err(). If that's the case,
> maybe it is better to change sanitize_err to accept an ptr_is_dst_reg
> argument too.
> 
> And given now that we are starting to make more use of scratch register
> states, it seems better to get rid the likes of 'off_reg == dst_reg' all
> together, and simply have ptr_is_dst_reg passed down by
> adjust_scalar_min_max_vals().
> 
> 
> diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
> index 52be0a118cce..72d49f2a57a3 100644
> --- a/kernel/bpf/verifier.c
> +++ b/kernel/bpf/verifier.c
> @@ -13505,13 +13505,13 @@ static int sanitize_ptr_alu(struct bpf_verifier_env 
> *env,
>                           const struct bpf_reg_state *off_reg,
>                           struct bpf_reg_state *dst_reg,
>                           struct bpf_sanitize_info *info,
> -                         const bool commit_window)
> +                         const bool commit_window,
> +                         const bool ptr_is_dst_reg)

That's a bit invasive. I think the simplest thing to do is to drop
off_reg and dst_reg parameters from sanitize_err() and re-derive the
information about which one is a pointer.

...

Reply via email to