Lines Matching full:old
301 /* check %cur's range satisfies %old's */
302 static bool range_within(const struct bpf_reg_state *old, in range_within() argument
305 return cnum64_is_subset(old->r64, cur->r64) && in range_within()
306 cnum32_is_subset(old->r32, cur->r32); in range_within()
309 /* If in the old state two registers had the same id, then they need to have
311 * the old state, so we need to track the mapping from old to new ids.
312 * Once we have seen that, say, a reg with old id 5 had new id 9, any subsequent
313 * regs with old id 5 must also have new id 9 for the new state to be safe. But
314 * regs with a different old id could still have new id 9, we don't care about
316 * So we look through our idmap to see if this old id has been seen before. If
332 if (map[i].old == old_id) in check_ids()
340 map[idmap->cnt].old = old_id; in check_ids()
358 * When old_id == 0, the old register is independent - not linked to any
360 * making it more restrictive. Since the old state didn't rely on any ID
366 * requirements of linked registers in old.
368 * Example: if old has r6.id=X and r7.id=X (linked), but cur has r6.id=0
374 * base id (flag stripped) must both map consistently. Example: old has
530 * However, if the old MAYBE_NULL register then got NULL checked, in regsafe()
587 * Also verify that new value satisfies old value range knowledge. in regsafe()
613 /* If the new min/max/var_off satisfy the old ones and in regsafe()
624 /* We must have at least as much range as the old ptr in regsafe()
626 * still safe. This is true even if old range < old off, in regsafe()
643 /* new val must satisfy old val knowledge */ in regsafe()
701 static bool stacksafe(struct bpf_verifier_env *env, struct bpf_func_state *old, in stacksafe() argument
711 for (i = 0; i < old->allocated_stack; i++) { in stacksafe()
718 u8 old_type = old->stack[spi].slot_type[i % BPF_REG_SIZE]; in stacksafe()
731 if (old->stack[spi].slot_type[i % BPF_REG_SIZE] == STACK_INVALID || in stacksafe()
732 old->stack[spi].slot_type[i % BPF_REG_SIZE] == STACK_POISON) in stacksafe()
736 old->stack[spi].slot_type[i % BPF_REG_SIZE] == STACK_MISC) in stacksafe()
752 old_reg = scalar_reg_for_stack(env, &old->stack[spi], im); in stacksafe()
762 /* if old state was safe with misc data in the stack in stacksafe()
766 if (old->stack[spi].slot_type[i % BPF_REG_SIZE] == STACK_MISC && in stacksafe()
769 if (old->stack[spi].slot_type[i % BPF_REG_SIZE] != in stacksafe()
771 /* Ex: old explored (safe) state has STACK_SPILL in in stacksafe()
779 /* Both old and cur are having same slot_type */ in stacksafe()
780 switch (old->stack[spi].slot_type[BPF_REG_SIZE - 1]) { in stacksafe()
792 if (!regsafe(env, &old->stack[spi].spilled_ptr, in stacksafe()
797 old_reg = &old->stack[spi].spilled_ptr; in stacksafe()
806 old_reg = &old->stack[spi].spilled_ptr; in stacksafe()
823 old_reg = &old->stack[spi].spilled_ptr; in stacksafe()
843 * Compare stack arg slots between old and current states.
846 static bool stack_arg_safe(struct bpf_verifier_env *env, struct bpf_func_state *old, in stack_arg_safe() argument
852 nslots = max(old->out_stack_arg_cnt, cur->out_stack_arg_cnt); in stack_arg_safe()
857 old_arg = i < old->out_stack_arg_cnt ? in stack_arg_safe()
858 &old->stack_arg_regs[i] : ¬_init; in stack_arg_safe()
868 static bool refsafe(struct bpf_verifier_state *old, struct bpf_verifier_state *cur, in refsafe() argument
873 if (old->acquired_refs != cur->acquired_refs) in refsafe()
876 if (old->active_locks != cur->active_locks) in refsafe()
879 if (old->active_preempt_locks != cur->active_preempt_locks) in refsafe()
882 if (old->active_rcu_locks != cur->active_rcu_locks) in refsafe()
885 if (!check_ids(old->active_irq_id, cur->active_irq_id, idmap)) in refsafe()
888 if (!check_ids(old->active_lock_id, cur->active_lock_id, idmap) || in refsafe()
889 old->active_lock_ptr != cur->active_lock_ptr) in refsafe()
892 for (i = 0; i < old->acquired_refs; i++) { in refsafe()
893 if (!check_ids(old->refs[i].id, cur->refs[i].id, idmap) || in refsafe()
894 old->refs[i].type != cur->refs[i].type) in refsafe()
896 switch (old->refs[i].type) { in refsafe()
898 if (!check_ids(old->refs[i].parent_id, cur->refs[i].parent_id, idmap)) in refsafe()
906 if (old->refs[i].ptr != cur->refs[i].ptr) in refsafe()
910 WARN_ONCE(1, "Unhandled enum type for reference state: %d\n", old->refs[i].type); in refsafe()
924 * execution popped from the state stack. If it sees an old state that has
937 * valid slots than old one that already passed validation, it means
944 static bool func_states_equal(struct bpf_verifier_env *env, struct bpf_func_state *old, in func_states_equal() argument
950 if (old->callback_depth > cur->callback_depth) in func_states_equal()
953 if (!old->no_stack_arg_load && cur->no_stack_arg_load) in func_states_equal()
958 !regsafe(env, &old->regs[i], &cur->regs[i], in func_states_equal()
962 if (!stacksafe(env, old, cur, &env->idmap_scratch, exact)) in func_states_equal()
965 if (!stack_arg_safe(env, old, cur, &env->idmap_scratch, exact)) in func_states_equal()
980 struct bpf_verifier_state *old, in states_equal() argument
987 if (old->curframe != cur->curframe) in states_equal()
995 if (old->speculative && !cur->speculative) in states_equal()
998 if (old->in_sleepable != cur->in_sleepable) in states_equal()
1001 if (!refsafe(old, cur, &env->idmap_scratch)) in states_equal()
1007 for (i = 0; i <= old->curframe; i++) { in states_equal()
1008 insn_idx = bpf_frame_insn_idx(old, i); in states_equal()
1009 if (old->frame[i]->callsite != cur->frame[i]->callsite) in states_equal()
1011 if (!func_states_equal(env, old->frame[i], cur->frame[i], insn_idx, exact)) in states_equal()
1021 const struct bpf_verifier_state *old, in propagate_precision() argument
1030 for (fr = old->curframe; fr >= 0; fr--) { in propagate_precision()
1031 state = old->frame[fr]; in propagate_precision()
1113 static bool states_maybe_looping(struct bpf_verifier_state *old, in states_maybe_looping() argument
1119 if (old->curframe != fr) in states_maybe_looping()
1122 fold = old->frame[fr]; in states_maybe_looping()
1189 static bool iter_active_depths_differ(struct bpf_verifier_state *old, struct bpf_verifier_state *cu… in iter_active_depths_differ() argument
1195 for (fr = old->curframe; fr >= 0; fr--) { in iter_active_depths_differ()
1196 state = old->frame[fr]; in iter_active_depths_differ()
1379 verbose(env, "old state:"); in bpf_is_state_visited()