mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-09-12 04:53:18 -04:00
bpf: mark a NULL kfunc argument precise
check_kfunc_arg() allows bpf_register_is_null() for nullable arguments
w/o marking the underlying scalar register precise. Hence a checkpoint
created on such a path would prune against arbitrary scalar value.
Fixes: 3bda08b636 ("bpf: Allow NULL buffers in bpf_dynptr_slice(_rw)")
Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
Link: https://lore.kernel.org/r/20260904-register-is-null-precise-fixes-v1-5-0f5a360ff15d@gmail.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
This commit is contained in:
committed by
Alexei Starovoitov
parent
100f4cc0d5
commit
506ada8962
@@ -12733,8 +12733,12 @@ static int check_kfunc_args(struct bpf_verifier_env *env, struct bpf_call_arg_me
|
||||
if (reg_is_referenced(env, reg))
|
||||
update_ref_obj(&meta->ref_obj, reg);
|
||||
|
||||
if (bpf_register_is_null(reg) && type_may_be_null(kf_arg_type))
|
||||
if (bpf_register_is_null(reg) && type_may_be_null(kf_arg_type)) {
|
||||
ret = mark_arg_precision(env, argno);
|
||||
if (ret)
|
||||
return ret;
|
||||
continue;
|
||||
}
|
||||
|
||||
if (is_kfunc_arg_map(btf, &args[i])) {
|
||||
ref_id = *reg2btf_ids[CONST_PTR_TO_MAP];
|
||||
|
||||
Reference in New Issue
Block a user