Commit 0748b80e authored by Jakub Kicinski's avatar Jakub Kicinski Committed by Greg Kroah-Hartman

bpf: don't (ab)use instructions to store state

commit 3df126f3 upstream.

Storing state in reserved fields of instructions makes
it impossible to run verifier on programs already
marked as read-only. Allocate and use an array of
per-instruction state instead.

While touching the error path rename and move existing
jump target.
Suggested-by: default avatarAlexei Starovoitov <ast@kernel.org>
Signed-off-by: default avatarJakub Kicinski <jakub.kicinski@netronome.com>
Acked-by: default avatarAlexei Starovoitov <ast@kernel.org>
Acked-by: default avatarDaniel Borkmann <daniel@iogearbox.net>
Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
Signed-off-by: default avatarJiri Slaby <jslaby@suse.cz>
Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@linuxfoundation.org>
parent 087a9228
...@@ -186,6 +186,10 @@ struct verifier_stack_elem { ...@@ -186,6 +186,10 @@ struct verifier_stack_elem {
struct verifier_stack_elem *next; struct verifier_stack_elem *next;
}; };
struct bpf_insn_aux_data {
enum bpf_reg_type ptr_type; /* pointer type for load/store insns */
};
#define MAX_USED_MAPS 64 /* max number of maps accessed by one eBPF program */ #define MAX_USED_MAPS 64 /* max number of maps accessed by one eBPF program */
/* single container for all structs /* single container for all structs
...@@ -200,6 +204,7 @@ struct verifier_env { ...@@ -200,6 +204,7 @@ struct verifier_env {
struct bpf_map *used_maps[MAX_USED_MAPS]; /* array of map's used by eBPF program */ struct bpf_map *used_maps[MAX_USED_MAPS]; /* array of map's used by eBPF program */
u32 used_map_cnt; /* number of used maps */ u32 used_map_cnt; /* number of used maps */
bool allow_ptr_leaks; bool allow_ptr_leaks;
struct bpf_insn_aux_data *insn_aux_data; /* array of per-insn state */
}; };
/* verbose verifier prints what it's seeing /* verbose verifier prints what it's seeing
...@@ -1784,7 +1789,7 @@ static int do_check(struct verifier_env *env) ...@@ -1784,7 +1789,7 @@ static int do_check(struct verifier_env *env)
return err; return err;
} else if (class == BPF_LDX) { } else if (class == BPF_LDX) {
enum bpf_reg_type src_reg_type; enum bpf_reg_type *prev_src_type, src_reg_type;
/* check for reserved fields is already done */ /* check for reserved fields is already done */
...@@ -1813,16 +1818,18 @@ static int do_check(struct verifier_env *env) ...@@ -1813,16 +1818,18 @@ static int do_check(struct verifier_env *env)
continue; continue;
} }
if (insn->imm == 0) { prev_src_type = &env->insn_aux_data[insn_idx].ptr_type;
if (*prev_src_type == NOT_INIT) {
/* saw a valid insn /* saw a valid insn
* dst_reg = *(u32 *)(src_reg + off) * dst_reg = *(u32 *)(src_reg + off)
* use reserved 'imm' field to mark this insn * save type to validate intersecting paths
*/ */
insn->imm = src_reg_type; *prev_src_type = src_reg_type;
} else if (src_reg_type != insn->imm && } else if (src_reg_type != *prev_src_type &&
(src_reg_type == PTR_TO_CTX || (src_reg_type == PTR_TO_CTX ||
insn->imm == PTR_TO_CTX)) { *prev_src_type == PTR_TO_CTX)) {
/* ABuser program is trying to use the same insn /* ABuser program is trying to use the same insn
* dst_reg = *(u32*) (src_reg + off) * dst_reg = *(u32*) (src_reg + off)
* with different pointer types: * with different pointer types:
...@@ -1835,7 +1842,7 @@ static int do_check(struct verifier_env *env) ...@@ -1835,7 +1842,7 @@ static int do_check(struct verifier_env *env)
} }
} else if (class == BPF_STX) { } else if (class == BPF_STX) {
enum bpf_reg_type dst_reg_type; enum bpf_reg_type *prev_dst_type, dst_reg_type;
if (BPF_MODE(insn->code) == BPF_XADD) { if (BPF_MODE(insn->code) == BPF_XADD) {
err = check_xadd(env, insn); err = check_xadd(env, insn);
...@@ -1863,11 +1870,13 @@ static int do_check(struct verifier_env *env) ...@@ -1863,11 +1870,13 @@ static int do_check(struct verifier_env *env)
if (err) if (err)
return err; return err;
if (insn->imm == 0) { prev_dst_type = &env->insn_aux_data[insn_idx].ptr_type;
insn->imm = dst_reg_type;
} else if (dst_reg_type != insn->imm && if (*prev_dst_type == NOT_INIT) {
*prev_dst_type = dst_reg_type;
} else if (dst_reg_type != *prev_dst_type &&
(dst_reg_type == PTR_TO_CTX || (dst_reg_type == PTR_TO_CTX ||
insn->imm == PTR_TO_CTX)) { *prev_dst_type == PTR_TO_CTX)) {
verbose("same insn cannot be used with different pointers\n"); verbose("same insn cannot be used with different pointers\n");
return -EINVAL; return -EINVAL;
} }
...@@ -2104,17 +2113,17 @@ static void convert_pseudo_ld_imm64(struct verifier_env *env) ...@@ -2104,17 +2113,17 @@ static void convert_pseudo_ld_imm64(struct verifier_env *env)
static int convert_ctx_accesses(struct verifier_env *env) static int convert_ctx_accesses(struct verifier_env *env)
{ {
struct bpf_insn *insn = env->prog->insnsi; struct bpf_insn *insn = env->prog->insnsi;
int insn_cnt = env->prog->len; const int insn_cnt = env->prog->len;
struct bpf_insn insn_buf[16]; struct bpf_insn insn_buf[16];
struct bpf_prog *new_prog; struct bpf_prog *new_prog;
enum bpf_access_type type; enum bpf_access_type type;
int i; int i, delta = 0;
if (!env->prog->aux->ops->convert_ctx_access) if (!env->prog->aux->ops->convert_ctx_access)
return 0; return 0;
for (i = 0; i < insn_cnt; i++, insn++) { for (i = 0; i < insn_cnt; i++, insn++) {
u32 insn_delta, cnt; u32 cnt;
if (insn->code == (BPF_LDX | BPF_MEM | BPF_W)) if (insn->code == (BPF_LDX | BPF_MEM | BPF_W))
type = BPF_READ; type = BPF_READ;
...@@ -2123,11 +2132,8 @@ static int convert_ctx_accesses(struct verifier_env *env) ...@@ -2123,11 +2132,8 @@ static int convert_ctx_accesses(struct verifier_env *env)
else else
continue; continue;
if (insn->imm != PTR_TO_CTX) { if (env->insn_aux_data[i].ptr_type != PTR_TO_CTX)
/* clear internal mark */
insn->imm = 0;
continue; continue;
}
cnt = env->prog->aux->ops-> cnt = env->prog->aux->ops->
convert_ctx_access(type, insn->dst_reg, insn->src_reg, convert_ctx_access(type, insn->dst_reg, insn->src_reg,
...@@ -2137,18 +2143,16 @@ static int convert_ctx_accesses(struct verifier_env *env) ...@@ -2137,18 +2143,16 @@ static int convert_ctx_accesses(struct verifier_env *env)
return -EINVAL; return -EINVAL;
} }
new_prog = bpf_patch_insn_single(env->prog, i, insn_buf, cnt); new_prog = bpf_patch_insn_single(env->prog, i + delta, insn_buf,
cnt);
if (!new_prog) if (!new_prog)
return -ENOMEM; return -ENOMEM;
insn_delta = cnt - 1; delta += cnt - 1;
/* keep walking new program and skip insns we just inserted */ /* keep walking new program and skip insns we just inserted */
env->prog = new_prog; env->prog = new_prog;
insn = new_prog->insnsi + i + insn_delta; insn = new_prog->insnsi + i + delta;
insn_cnt += insn_delta;
i += insn_delta;
} }
return 0; return 0;
...@@ -2192,6 +2196,11 @@ int bpf_check(struct bpf_prog **prog, union bpf_attr *attr) ...@@ -2192,6 +2196,11 @@ int bpf_check(struct bpf_prog **prog, union bpf_attr *attr)
if (!env) if (!env)
return -ENOMEM; return -ENOMEM;
env->insn_aux_data = vzalloc(sizeof(struct bpf_insn_aux_data) *
(*prog)->len);
ret = -ENOMEM;
if (!env->insn_aux_data)
goto err_free_env;
env->prog = *prog; env->prog = *prog;
/* grab the mutex to protect few globals used by verifier */ /* grab the mutex to protect few globals used by verifier */
...@@ -2210,12 +2219,12 @@ int bpf_check(struct bpf_prog **prog, union bpf_attr *attr) ...@@ -2210,12 +2219,12 @@ int bpf_check(struct bpf_prog **prog, union bpf_attr *attr)
/* log_* values have to be sane */ /* log_* values have to be sane */
if (log_size < 128 || log_size > UINT_MAX >> 8 || if (log_size < 128 || log_size > UINT_MAX >> 8 ||
log_level == 0 || log_ubuf == NULL) log_level == 0 || log_ubuf == NULL)
goto free_env; goto err_unlock;
ret = -ENOMEM; ret = -ENOMEM;
log_buf = vmalloc(log_size); log_buf = vmalloc(log_size);
if (!log_buf) if (!log_buf)
goto free_env; goto err_unlock;
} else { } else {
log_level = 0; log_level = 0;
} }
...@@ -2284,14 +2293,16 @@ int bpf_check(struct bpf_prog **prog, union bpf_attr *attr) ...@@ -2284,14 +2293,16 @@ int bpf_check(struct bpf_prog **prog, union bpf_attr *attr)
free_log_buf: free_log_buf:
if (log_level) if (log_level)
vfree(log_buf); vfree(log_buf);
free_env:
if (!env->prog->aux->used_maps) if (!env->prog->aux->used_maps)
/* if we didn't copy map pointers into bpf_prog_info, release /* if we didn't copy map pointers into bpf_prog_info, release
* them now. Otherwise free_bpf_prog_info() will release them. * them now. Otherwise free_bpf_prog_info() will release them.
*/ */
release_maps(env); release_maps(env);
*prog = env->prog; *prog = env->prog;
kfree(env); err_unlock:
mutex_unlock(&bpf_verifier_lock); mutex_unlock(&bpf_verifier_lock);
vfree(env->insn_aux_data);
err_free_env:
kfree(env);
return ret; return ret;
} }
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment