Files
linux/include/linux
Martin KaFai Lau 3990ed4c42 bpf: Stop caching subprog index in the bpf_pseudo_func insn
This patch is to fix an out-of-bound access issue when jit-ing the
bpf_pseudo_func insn (i.e. ld_imm64 with src_reg == BPF_PSEUDO_FUNC)

In jit_subprog(), it currently reuses the subprog index cached in
insn[1].imm.  This subprog index is an index into a few array related
to subprogs.  For example, in jit_subprog(), it is an index to the newly
allocated 'struct bpf_prog **func' array.

The subprog index was cached in insn[1].imm after add_subprog().  However,
this could become outdated (and too big in this case) if some subprogs
are completely removed during dead code elimination (in
adjust_subprog_starts_after_remove).  The cached index in insn[1].imm
is not updated accordingly and causing out-of-bound issue in the later
jit_subprog().

Unlike bpf_pseudo_'func' insn, the current bpf_pseudo_'call' insn
is handling the DCE properly by calling find_subprog(insn->imm) to
figure out the index instead of caching the subprog index.
The existing bpf_adj_branches() will adjust the insn->imm
whenever insn is added or removed.

Instead of having two ways handling subprog index,
this patch is to make bpf_pseudo_func works more like
bpf_pseudo_call.

First change is to stop caching the subprog index result
in insn[1].imm after add_subprog().  The verification
process will use find_subprog(insn->imm) to figure
out the subprog index.

Second change is in bpf_adj_branches() and have it to
adjust the insn->imm for the bpf_pseudo_func insn also
whenever insn is added or removed.

Third change is in jit_subprog().  Like the bpf_pseudo_call handling,
bpf_pseudo_func temporarily stores the find_subprog() result
in insn->off.  It is fine because the prog's insn has been finalized
at this point.  insn->off will be reset back to 0 later to avoid
confusing the userspace prog dump tool.

Fixes: 69c087ba62 ("bpf: Add bpf_for_each_map_elem() helper")
Signed-off-by: Martin KaFai Lau <kafai@fb.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://lore.kernel.org/bpf/20211106014014.651018-1-kafai@fb.com
2021-11-06 12:54:12 -07:00
..
2021-09-02 22:49:16 +02:00
2021-07-21 19:54:21 -07:00
2021-02-02 00:16:57 +01:00
2021-09-20 12:43:34 +01:00
2021-01-23 14:57:21 +01:00
2021-10-14 14:15:46 +01:00
2021-08-29 14:47:42 +03:00
2021-05-06 19:24:11 -07:00
2021-10-07 16:51:57 +02:00
2021-04-14 16:30:30 +03:00
2021-10-18 14:43:23 -06:00
2021-10-29 06:50:52 -06:00
2021-05-24 21:13:05 -07:00
2021-01-24 14:27:17 +01:00
2021-02-26 09:41:03 -08:00
2021-04-08 16:04:20 -07:00
2021-09-08 15:32:35 -07:00
2021-01-21 14:06:00 -07:00
2021-08-26 16:52:03 -07:00
2021-07-20 09:20:49 -07:00
2021-09-07 21:17:28 +02:00
2021-03-22 03:57:39 +01:00
2021-08-26 15:32:28 -04:00
2021-07-27 11:00:36 +02:00
2021-09-06 07:20:56 -04:00
2021-04-12 15:04:23 +02:00
2021-06-25 19:57:01 -04:00
2021-07-26 15:09:44 +02:00
2021-07-27 20:11:45 +01:00
2021-07-27 20:11:44 +01:00
2021-10-18 07:49:38 -04:00
2021-10-18 07:49:38 -04:00
2021-02-11 13:24:44 -08:00
2021-08-05 11:46:42 +01:00
2021-04-30 11:20:40 -07:00
2021-10-18 06:17:36 -06:00
2021-10-05 06:54:16 -05:00
2021-07-27 17:05:06 +01:00
2021-07-27 09:29:15 +02:00
2021-01-21 16:16:10 +00:00
2021-06-01 10:29:21 +01:00
2021-02-26 09:41:03 -08:00
2021-10-18 07:49:39 -04:00
2021-09-23 11:01:12 -04:00
2021-06-17 13:09:27 -04:00
2021-06-15 17:46:57 +02:00
2021-07-01 11:06:02 -07:00
2021-10-18 07:49:39 -04:00
2021-09-27 09:27:29 -04:00
2021-10-18 07:49:41 -04:00
2021-07-01 11:06:05 -07:00
2021-08-23 13:19:12 +02:00
2021-09-27 09:27:31 -04:00
2021-09-17 13:52:17 +01:00
2021-10-18 07:49:39 -04:00
2021-09-27 09:27:29 -04:00
2021-10-18 07:49:41 -04:00
2021-02-26 09:40:59 -08:00
2021-02-03 19:05:50 +01:00
2021-06-16 17:20:40 -05:00
2021-07-06 10:37:46 -05:00
2021-06-07 14:11:47 -07:00
2021-01-24 14:27:17 +01:00
2021-08-18 22:08:24 +02:00
2021-03-06 12:40:22 +01:00
2021-02-26 09:41:03 -08:00
2021-09-02 21:38:56 +02:00
2021-10-07 16:51:57 +02:00
2021-10-18 07:49:39 -04:00
2021-03-17 14:16:15 -05:00
2021-01-16 23:19:26 +01:00
2021-08-17 17:50:51 +02:00
2021-10-30 16:37:28 +02:00
2021-03-18 12:58:27 -04:00
2021-10-26 14:58:45 +01:00
2021-05-10 16:03:35 -07:00
2021-08-06 13:41:48 -07:00
2021-08-19 09:02:55 +09:00
2021-06-24 15:49:32 +02:00
2021-10-18 07:49:40 -04:00
2021-07-01 11:06:03 -07:00
2021-10-07 13:51:11 +02:00
2021-07-27 12:17:21 +02:00
2021-07-27 12:12:08 +02:00
2021-02-13 17:17:53 +01:00
2021-09-08 15:32:35 -07:00
2021-03-30 17:06:49 -07:00
2021-09-15 09:22:35 -06:00
2021-01-21 16:16:10 +00:00
2021-08-10 11:50:55 -04:00
2021-02-09 12:15:07 +01:00
2021-08-11 06:44:24 -04:00
2021-01-21 14:06:00 -07:00
2021-03-30 13:42:33 -04:00
2021-01-24 14:27:17 +01:00
2021-10-19 23:44:30 +08:00
2021-02-08 22:58:55 +01:00