mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-08-28 01:43:47 -04:00
bpf: Fix func_info_aux desync after dead code elimination
The verifier keeps per-subprogram metadata in three parallel arrays: subprog_info, func_info, and func_info_aux. Dead code elimination can remove whole subprograms, and adjust_subprog_starts_after_remove() shifts subprog_info and func_info to close the gap, but leaves func_info_aux in place. From that point on, func_info_aux[i] no longer describes subprogram i. Shift func_info_aux together with func_info so the three arrays stay aligned after subprogram removal. Reported-by: Sashiko <sashiko-bot@kernel.org> Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com> Signed-off-by: Andrii Nakryiko <andrii@kernel.org> Link: https://lore.kernel.org/bpf/20260808064523.DE3E71F000E9@smtp.kernel.org Link: https://lore.kernel.org/bpf/20260812231506.3558128-1-memxor@gmail.com
This commit is contained in:
committed by
Andrii Nakryiko
parent
806c1a1852
commit
aacd13e1eb
@@ -402,13 +402,17 @@ static int adjust_subprog_starts_after_remove(struct bpf_verifier_env *env,
|
||||
sizeof(*env->subprog_info) * move);
|
||||
env->subprog_cnt -= j - i;
|
||||
|
||||
/* remove func_info */
|
||||
/* remove func_info and its aux */
|
||||
if (aux->func_info) {
|
||||
move = aux->func_info_cnt - j;
|
||||
|
||||
memmove(aux->func_info + i,
|
||||
aux->func_info + j,
|
||||
sizeof(*aux->func_info) * move);
|
||||
if (aux->func_info_aux)
|
||||
memmove(aux->func_info_aux + i,
|
||||
aux->func_info_aux + j,
|
||||
sizeof(*aux->func_info_aux) * move);
|
||||
aux->func_info_cnt -= j - i;
|
||||
/* func_info->insn_off is set after all code rewrites,
|
||||
* in adjust_btf_func() - no need to adjust
|
||||
|
||||
Reference in New Issue
Block a user