[PATCH bpf-next v2 0/2] bpf: Reject mixed arena and ordinary atomic paths

From: Yiyang Chen

Date: Sun Aug 16 2026 - 06:57:30 EST


Atomic RMW instructions use a single aux pointer type to select their final
instruction encoding. The verifier currently records that type only for
PTR_TO_ARENA, allowing a second path with an ordinary pointer to reach the
same instruction before fixups rewrite it to BPF_PROBE_ATOMIC.

Patch 1 records the destination type for every atomic RMW path so the existing
pointer mismatch check rejects incompatible uses of one instruction.

Patch 2 adds a verifier regression test with PTR_TO_ARENA and
PTR_TO_STACK paths converging on one atomic add.

Yiyang Chen (2):
bpf: Check pointer type for all atomic RMW paths
selftests/bpf: Cover mixed arena and stack atomics

Signed-off-by: Yiyang Chen <chenyy23@xxxxxxxxxxxxxxxxxxxxx>
---
Changes in v2:
- Remove the arena global and extra map from the selftest; reuse the existing
arena map and a stack destination.
- Construct the arena pointer from a scalar and encode the cast with
__imm_insn.
- Rebase onto bpf-next commit c93cbdb13f99.
- Link to v1: https://lore.kernel.org/r/20260813-bpf-next-038-mixed-atomic-v1-v1-0-e79aadb46a8a@xxxxxxxxxxxxxxxxxxxxx

---
Yiyang Chen (2):
bpf: Check pointer type for all atomic RMW paths
selftests/bpf: Cover mixed arena and stack atomics

kernel/bpf/verifier.c | 8 ++---
tools/testing/selftests/bpf/progs/verifier_arena.c | 39 ++++++++++++++++++++++
2 files changed, 42 insertions(+), 5 deletions(-)
---
base-commit: c93cbdb13f995f87b5356329b3fe551c80bb482d
--
2.43.0