]> git.baikalelectronics.ru Git - kernel.git/commit
bpf: Propagate expected_attach_type when verifying freplace programs
authorToke Høiland-Jørgensen <toke@redhat.com>
Fri, 24 Apr 2020 13:34:27 +0000 (15:34 +0200)
committerAlexei Starovoitov <ast@kernel.org>
Sat, 25 Apr 2020 00:34:30 +0000 (17:34 -0700)
commit84995f290f4a934c5f82f9ef9e323fad186ca54b
tree9995324e00de4c15279caa5de4d23663b1d935bf
parentfabddde6b132d1adc42c967d82c7867c49a14bd7
bpf: Propagate expected_attach_type when verifying freplace programs

For some program types, the verifier relies on the expected_attach_type of
the program being verified in the verification process. However, for
freplace programs, the attach type was not propagated along with the
verifier ops, so the expected_attach_type would always be zero for freplace
programs.

This in turn caused the verifier to sometimes make the wrong call for
freplace programs. For all existing uses of expected_attach_type for this
purpose, the result of this was only false negatives (i.e., freplace
functions would be rejected by the verifier even though they were valid
programs for the target they were replacing). However, should a false
positive be introduced, this can lead to out-of-bounds accesses and/or
crashes.

The fix introduced in this patch is to propagate the expected_attach_type
to the freplace program during verification, and reset it after that is
done.

Fixes: aa9f2e08f7b4 ("bpf: Introduce dynamic program extensions")
Signed-off-by: Toke Høiland-Jørgensen <toke@redhat.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://lore.kernel.org/bpf/158773526726.293902.13257293296560360508.stgit@toke.dk
kernel/bpf/verifier.c