mirror of
https://github.com/torvalds/linux.git
synced 2026-09-11 20:13:02 +02:00
bpf: reject BPF_PSEUDO_FUNC reference to the main program
fixups.c:jit_subprogs() rewrites BPF_PSEUDO_FUNC loads to contain real
function addresses. This function is invoked from bpf_jit_subprogs()
only when env->subprog_cnt > 1. Meaning that for any program like
below:
int main(void *ctx) {
void *ptr = main;
...
bpf_timer_set_callback(..., ptr);
...
}
The 'ptr' won't be ever converted to contain an address.
In combination with e.g. bpf_timer_set_callback() this would lead to a
function call at a bogus address.
Instead of complicating the implementation, just assume that no useful
program needs main to be a sync or async callback and reject
BPF_PSEUDO_FUNC loads for the main subprogram.
Fixes: 69c087ba62 ("bpf: Add bpf_for_each_map_elem() helper")
Reported-by: Nicholas Carlini <npc@anthropic.com>
Suggested-by: Nicholas Carlini <npc@anthropic.com>
Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
Link: https://lore.kernel.org/r/20260902233658.1186477-1-eddyz87@gmail.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
This commit is contained in:
parent
7ac9662189
commit
374b2c5561
|
|
@ -17089,6 +17089,15 @@ static int check_ld_imm(struct bpf_verifier_env *env, struct bpf_insn *insn)
|
|||
verbose(env, "callback function not static\n");
|
||||
return -EINVAL;
|
||||
}
|
||||
/*
|
||||
* When env->subprog_cnt == 1 this instruction won't be rewritten
|
||||
* to hold a real function address. Assume that no usable program
|
||||
* combines e.g. main and timer callback and just reject here.
|
||||
*/
|
||||
if (subprogno == 0) {
|
||||
verbose(env, "callback function cannot be the main program\n");
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
dst_reg->type = PTR_TO_FUNC;
|
||||
dst_reg->subprogno = subprogno;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user