• Yonghong Song's avatar
    bpf: Fix a bug when getting subprog 0 jited image in check_attach_btf_id · e9eeec58
    Yonghong Song authored
    For jited bpf program, if the subprogram count is 1, i.e.,
    there is no callees in the program, prog->aux->func will be NULL
    and prog->bpf_func points to image address of the program.
    
    If there is more than one subprogram, prog->aux->func is populated,
    and subprogram 0 can be accessed through either prog->bpf_func or
    prog->aux->func[0]. Other subprograms should be accessed through
    prog->aux->func[subprog_id].
    
    This patch fixed a bug in check_attach_btf_id(), where
    prog->aux->func[subprog_id] is used to access any subprogram which
    caused a segfault like below:
      [79162.619208] BUG: kernel NULL pointer dereference, address:
      0000000000000000
      ......
      [79162.634255] Call Trace:
      [79162.634974]  ? _cond_resched+0x15/0x30
      [79162.635686]  ? kmem_cache_alloc_trace+0x162/0x220
      [79162.636398]  ? selinux_bpf_prog_alloc+0x1f/0x60
      [79162.637111]  bpf_prog_load+0x3de/0x690
      [79162.637809]  __do_sys_bpf+0x105/0x1740
      [79162.638488]  do_syscall_64+0x5b/0x180
      [79162.639147]  entry_SYSCALL_64_after_hwframe+0x44/0xa9
      ......
    
    Fixes: 5b92a28a ("bpf: Support attaching tracing BPF program to other BPF programs")
    Reported-by: default avatarEelco Chaudron <echaudro@redhat.com>
    Signed-off-by: default avatarYonghong Song <yhs@fb.com>
    Signed-off-by: default avatarAlexei Starovoitov <ast@kernel.org>
    Link: https://lore.kernel.org/bpf/20191205010606.177774-1-yhs@fb.com
    e9eeec58
verifier.c 280 KB