mirror of
https://github.com/torvalds/linux.git
synced 2026-09-12 20:53:03 +02:00
bpf: Mark sched_process_wait argument as nullable
do_wait() passes wo->wo_pid to the sched_process_wait tracepoint.
kernel_wait4() leaves wo_pid NULL for wait4(-1), and
kernel_waitid_prepare() does likewise for waitid(P_ALL).
btf_ctx_access() currently types argument 0 as PTR_TO_BTF_ID |
PTR_TRUSTED. Without PTR_MAYBE_NULL, the verifier accepts an unchecked
dereference. Trusted pointer loads have no fault protection, so a wait for
any child can then cause a NULL pointer dereference in JITed BPF code.
Add sched_process_wait to raw_tp_null_args[] with argument 0 marked
nullable. The verifier rejects an unchecked dereference while preserving
access after the program checks the pointer for NULL.
Fixes: 838a10bd2e ("bpf: Augment raw_tp arguments with PTR_MAYBE_NULL")
Reported-by: Nicholas Carlini <npc@anthropic.com>
Suggested-by: Nicholas Carlini <npc@anthropic.com>
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Link: https://lore.kernel.org/r/20260903144433.1716731-8-memxor@gmail.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
This commit is contained in:
parent
08b4dc83d9
commit
a453d6e3b8
|
|
@ -6672,6 +6672,10 @@ struct bpf_raw_tp_null_args {
|
|||
static const struct bpf_raw_tp_null_args raw_tp_null_args[] = {
|
||||
/* sched */
|
||||
{ "sched_pi_setprio", 0x10 },
|
||||
/*
|
||||
* do_wait() passes NULL for wait4(-1) and waitid(P_ALL).
|
||||
*/
|
||||
{ "sched_process_wait", 0x1 },
|
||||
/* ... from sched_numa_pair_template event class */
|
||||
{ "sched_stick_numa", 0x100 },
|
||||
{ "sched_swap_numa", 0x100 },
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user