On Wed, 2026-08-19 at 20:58 +0800, Jiayuan Chen wrote: > An unprivileged socket filter does variable pointer arithmetic on a > PTR_TO_MAP_VALUE whose offset collapses to a constant. The Spectre-v1 > speculative path used to snapshot the pointer with a const offset and an > unbounded r32, which tripped reg_bounds_sanity_check() on the following > register move. > > Mark the test __success_unpriv (the speculative path only runs > unprivileged) and flag it BPF_F_TEST_REG_INVARIANTS so the invariant > violation becomes a hard load failure. The unprivileged run fails without > the verifier fix and passes with it: > > verifier_bounds/spec_ptr_alu_const_offset @unpriv:FAIL # without fix > verifier_bounds/spec_ptr_alu_const_offset @unpriv:OK # with fix > > Signed-off-by: Jiayuan Chen <[email protected]> > ---
Tested-by: Eduard Zingerman <[email protected]> ...

