mirror of
https://github.com/torvalds/linux.git
synced 2026-10-06 10:36:03 +02:00
bpf: Clear scalar delta on narrowing stack spill
check_stack_write_fixed_off() breaks the scalar link on a narrowing spill
by zeroing the id of the destination stack slot, but leaves the delta in
place. save_register_state() has just copied the source register verbatim,
so the slot keeps the BPF_ADD_CONST delta of a register it is no longer
linked to. This is the same shape as the case addressed in 1b327732c8
("bpf: Clear delta when clearing reg id for non-{add,sub} ops"). Unlike
the latter, no miscomputation seems reachable, so mainly consistency.
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: Eduard Zingerman <eddyz87@gmail.com>
Link: https://lore.kernel.org/r/20260910185604.44949-1-daniel@iogearbox.net
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
This commit is contained in:
parent
a903f145a8
commit
2936aed9b0
|
|
@ -3582,7 +3582,7 @@ static int check_stack_write_fixed_off(struct bpf_verifier_env *env,
|
|||
save_register_state(env, state, spi, reg, size);
|
||||
/* Break the relation on a narrowing spill. */
|
||||
if (!reg_value_fits)
|
||||
state->stack[spi].spilled_ptr.id = 0;
|
||||
clear_scalar_id(&state->stack[spi].spilled_ptr);
|
||||
} else if (!reg && !(off % BPF_REG_SIZE) && is_bpf_st_mem(insn) &&
|
||||
env->bpf_capable) {
|
||||
struct bpf_reg_state *tmp_reg = &env->fake_reg[0];
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user