1*cedebd74SHao Sun // SPDX-License-Identifier: GPL-2.0
2*cedebd74SHao Sun 
3*cedebd74SHao Sun #include "vmlinux.h"
4*cedebd74SHao Sun #include <bpf/bpf_helpers.h>
5*cedebd74SHao Sun #include "bpf_misc.h"
6*cedebd74SHao Sun 
7*cedebd74SHao Sun char _license[] SEC("license") = "GPL";
8*cedebd74SHao Sun 
9*cedebd74SHao Sun struct {
10*cedebd74SHao Sun 	__uint(type, BPF_MAP_TYPE_HASH);
11*cedebd74SHao Sun 	__uint(max_entries, 1);
12*cedebd74SHao Sun 	__type(key, u64);
13*cedebd74SHao Sun 	__type(value, u64);
14*cedebd74SHao Sun } m_hash SEC(".maps");
15*cedebd74SHao Sun 
16*cedebd74SHao Sun SEC("?raw_tp")
17*cedebd74SHao Sun __failure __msg("R8 invalid mem access 'map_value_or_null")
jeq_infer_not_null_ptr_to_btfid(void * ctx)18*cedebd74SHao Sun int jeq_infer_not_null_ptr_to_btfid(void *ctx)
19*cedebd74SHao Sun {
20*cedebd74SHao Sun 	struct bpf_map *map = (struct bpf_map *)&m_hash;
21*cedebd74SHao Sun 	struct bpf_map *inner_map = map->inner_map_meta;
22*cedebd74SHao Sun 	u64 key = 0, ret = 0, *val;
23*cedebd74SHao Sun 
24*cedebd74SHao Sun 	val = bpf_map_lookup_elem(map, &key);
25*cedebd74SHao Sun 	/* Do not mark ptr as non-null if one of them is
26*cedebd74SHao Sun 	 * PTR_TO_BTF_ID (R9), reject because of invalid
27*cedebd74SHao Sun 	 * access to map value (R8).
28*cedebd74SHao Sun 	 *
29*cedebd74SHao Sun 	 * Here, we need to inline those insns to access
30*cedebd74SHao Sun 	 * R8 directly, since compiler may use other reg
31*cedebd74SHao Sun 	 * once it figures out val==inner_map.
32*cedebd74SHao Sun 	 */
33*cedebd74SHao Sun 	asm volatile("r8 = %[val];\n"
34*cedebd74SHao Sun 		     "r9 = %[inner_map];\n"
35*cedebd74SHao Sun 		     "if r8 != r9 goto +1;\n"
36*cedebd74SHao Sun 		     "%[ret] = *(u64 *)(r8 +0);\n"
37*cedebd74SHao Sun 		     : [ret] "+r"(ret)
38*cedebd74SHao Sun 		     : [inner_map] "r"(inner_map), [val] "r"(val)
39*cedebd74SHao Sun 		     : "r8", "r9");
40*cedebd74SHao Sun 
41*cedebd74SHao Sun 	return ret;
42*cedebd74SHao Sun }
43