selftests/bpf: Cover stack nospec slot indexing

Add a verifier test for the fixed-offset stack write case where two 4-byte
stores initialize opposite halves of the same stack slot.

The test runs through the unprivileged loader lane and expects both
half-slot writes to emit nospec in the translated program.

Acked-by: Luis Gerhorst <luis.gerhorst@fau.de>
Signed-off-by: Nuoqi Gui <gnq25@mails.tsinghua.edu.cn>
Link: https://lore.kernel.org/r/20260618-f01-11-stack-nospec-slot-index-v3-2-780297041721@mails.tsinghua.edu.cn
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
This commit is contained in:
Nuoqi Gui 2026-06-18 01:50:27 +08:00 committed by Alexei Starovoitov
parent d1d53aa30a
commit a93ae7ed59

View File

@ -976,4 +976,26 @@ l0_%=: exit; \
: __clobber_all);
}
SEC("socket")
__description("unpriv: Spectre v4 stack write slot index")
__success __success_unpriv
__retval(0)
#ifdef SPEC_V4
__xlated_unpriv("r0 = 0")
__xlated_unpriv("*(u32 *)(r10 -4) = r0")
__xlated_unpriv("nospec")
__xlated_unpriv("*(u32 *)(r10 -8) = r0")
__xlated_unpriv("nospec")
__xlated_unpriv("exit")
#endif
__naked void stack_write_nospec_slot_index(void)
{
asm volatile (" \
r0 = 0; \
*(u32 *)(r10 - 4) = r0; \
*(u32 *)(r10 - 8) = r0; \
exit; \
" ::: __clobber_all);
}
char _license[] SEC("license") = "GPL";