This series fixes pointer-state propagation for commuted scalar += pointer arithmetic in the verifier.
Patch 1 keeps the full pointer register state when the pointer operand is the source of the add, which preserves fields such as the stack frame number and parent id instead of copying only type and id. Patch 2 builds on that state propagation and moves the untrusted PTR_TO_MEM early return after it, so scalar += untrusted_pointer is modeled as PTR_TO_MEM and remains usable through the probe-read path. Patch 3 adds verifier selftests for stack frame number preservation, readonly-untrusted memory access, and dynptr data-slice invalidation. Changes in v3: - Preserve the complete pointer register state with verifier-env scratch storage, addressing Eduard's comment that copying selected fields is fragile and avoiding a temporary bpf_reg_state on the verifier stack. - Keep the existing RUN(verifier_basic_stack) dispatch unchanged and add the stack regression directly to the existing verifier_basic_stack program. - Keep the original operand direction inside adjust_ptr_min_max_vals() by saving the scalar operand in env->fake_reg[0]. - Move untrusted PTR_TO_MEM handling after the unified pointer-state copy so the commuted form remains PTR_TO_MEM before the early return. - Add readonly-untrusted and dynptr selftest coverage, responding to the bpf-ci/static review finding that the untrusted pointer case needs a regression test. - Clear the original dynptr data-slice register after deriving the commuted alias so the regression test isolates parent-id propagation. - Make the readonly-untrusted return value endian-neutral by loading an int. - Rebase to bpf-next base a23a71823352. v2: https://lore.kernel.org/bpf/[email protected]/ v1: https://lore.kernel.org/bpf/[email protected]/ Yiyang Chen (3): bpf: Preserve pointer state for commuted arithmetic bpf: Propagate untrusted pointer state in commuted arithmetic selftests/bpf: Cover commuted pointer state propagation kernel/bpf/verifier.c | 35 +++++++++------- .../testing/selftests/bpf/progs/dynptr_fail.c | 31 ++++++++++++++ .../bpf/progs/mem_rdonly_untrusted.c | 17 ++++++++ .../bpf/progs/verifier_basic_stack.c | 41 +++++++++++++++++++ 4 files changed, 110 insertions(+), 14 deletions(-) base-commit: a23a71823352e2d792dcaae25f1ebb744acbfc0b -- 2.34.1

