bpf/verifier: Fix states_equal() comparison of pointer and UNKNOWN
An UNKNOWN_VALUE is not supposed to be derived from a pointer, unless
pointer leaks are allowed. Therefore, states_equal() must not treat
a state with a pointer in a register as "equal" to a state with an
UNKNOWN_VALUE in that register.
This appears to have been fixed upstream as part of commit
f1174f77b50c "bpf/verifier: rework value tracking", and can be
detected by the bpf/verifier sub-test "pointer/scalar confusion in
state equality check (way 1)" in mainline.
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
Cc: Edward Cree <ecree@solarflare.com>
Cc: Jann Horn <jannh@google.com>
Cc: Alexei Starovoitov <ast@kernel.org>
Gbp-Pq: Topic bugfix/all
Gbp-Pq: Name bpf-verifier-fix-states_equal-comparison-of-pointer-and-unknown.patch