mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-07-22 02:17:36 -04:00
bpf: Fix partial copy of non-linear test_run output
For non-linear test_run output, bpf_test_finish() derives the linear
data copy length from copy_size - frag_size. This only matches the
linear data length when copy_size is the full packet size.
When userspace provides a short data_out buffer, copy_size is clamped to
that buffer size. If copy_size is smaller than frag_size, the computed
length becomes negative and bpf_test_finish() returns -ENOSPC before
copying the packet prefix or updating data_size_out.
Compute the linear data length from the packet layout instead, and clamp
the linear copy length to copy_size. This preserves the expected
partial-copy semantics: return -ENOSPC, copy the packet prefix that fits
in data_out, and report the full packet length through data_size_out.
Fixes: 7855e0db15 ("bpf: test_run: add xdp_shared_info pointer in bpf_test_finish signature")
Signed-off-by: Sun Jian <sun.jian.kdev@gmail.com>
Acked-by: Paul Chaignon <paul.chaignon@gmail.com>
Link: https://lore.kernel.org/r/20260617093557.63880-2-sun.jian.kdev@gmail.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
This commit is contained in:
committed by
Alexei Starovoitov
parent
3eb21c8691
commit
b5f3534268
@@ -452,12 +452,8 @@ static int bpf_test_finish(const union bpf_attr *kattr,
|
||||
}
|
||||
|
||||
if (data_out) {
|
||||
int len = sinfo ? copy_size - frag_size : copy_size;
|
||||
|
||||
if (len < 0) {
|
||||
err = -ENOSPC;
|
||||
goto out;
|
||||
}
|
||||
u32 head_len = size - frag_size;
|
||||
u32 len = min(copy_size, head_len);
|
||||
|
||||
if (copy_to_user(data_out, data, len))
|
||||
goto out;
|
||||
|
||||
Reference in New Issue
Block a user