[PATCH bpf-next v2] bpf: Skip redundant destroy_if_dynptr_stack_slot calls in check_stack_write_var_off
From: Ömer Mete Kaya
Date: Sun Sep 27 2026 - 19:37:32 EST
bpf_get_spi() maps 8 consecutive byte offsets to the same slot index.
When iterating over a variable-offset stack write range byte by byte,
destroy_if_dynptr_stack_slot() can be called up to 8 times for the same
slot, even though it operates per-slot.
Skip iterations where the slot index matches the previous byte's slot
index to avoid the redundant calls.
Signed-off-by: Ömer Mete Kaya <omermetekaya0@xxxxxxxxx>
---
Changes in v2:
- Fix multi-line comment style: move opening /* to its own line.
Reported by Sashiko AI review.
kernel/bpf/verifier.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)
diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
index fec5a1ae6a4d..6bc5bc56f0d3 100644
--- a/kernel/bpf/verifier.c
+++ b/kernel/bpf/verifier.c
@@ -3824,9 +3824,14 @@ static int check_stack_write_var_off(struct bpf_verifier_env *env,
writing_zero = true;
for (i = min_off; i < max_off; i++) {
- int spi;
+ int spi = bpf_get_spi(i);
- spi = bpf_get_spi(i);
+ /*
+ * bpf_get_spi() maps 8 consecutive byte offsets to the same
+ * slot index; skip redundant calls for the same slot.
+ */
+ if (i != min_off && spi == bpf_get_spi(i - 1))
+ continue;
err = destroy_if_dynptr_stack_slot(env, state, spi);
if (err)
return err;
--
2.55.0