mirror of
https://github.com/torvalds/linux.git
synced 2026-07-28 18:21:24 +02:00
Merge branch 'more-gen_loader-fixes'
Daniel Borkmann says:
====================
More gen_loader fixes
Follow-up fixes for the signed loader, includes also the recent
sashiko findings.
v1->v2:
- Fixed up verifier_map_ptr selftest
- Added patch 1/2/6/7 with a new map-in-map fix and a
redundant hash_buf memcpy cleanup as well as selftests
====================
Link: https://patch.msgid.link/20260601150248.394863-1-daniel@iogearbox.net
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
This commit is contained in:
commit
b6aa0abf9f
|
|
@ -111,7 +111,7 @@ struct bpf_map_ops {
|
|||
long (*map_pop_elem)(struct bpf_map *map, void *value);
|
||||
long (*map_peek_elem)(struct bpf_map *map, void *value);
|
||||
void *(*map_lookup_percpu_elem)(struct bpf_map *map, void *key, u32 cpu);
|
||||
int (*map_get_hash)(struct bpf_map *map, u32 hash_buf_size, void *hash_buf);
|
||||
int (*map_get_hash)(struct bpf_map *map);
|
||||
|
||||
/* funcs called by prog_array and perf_event_array map */
|
||||
void *(*map_fd_get_ptr)(struct bpf_map *map, struct file *map_file,
|
||||
|
|
@ -296,6 +296,7 @@ struct bpf_map_owner {
|
|||
|
||||
struct bpf_map {
|
||||
u8 sha[SHA256_DIGEST_SIZE];
|
||||
u32 excl;
|
||||
const struct bpf_map_ops *ops;
|
||||
struct bpf_map *inner_map_meta;
|
||||
#ifdef CONFIG_SECURITY
|
||||
|
|
|
|||
|
|
@ -175,14 +175,12 @@ static void *array_map_lookup_elem(struct bpf_map *map, void *key)
|
|||
return array->value + (u64)array->elem_size * (index & array->index_mask);
|
||||
}
|
||||
|
||||
static int array_map_get_hash(struct bpf_map *map, u32 hash_buf_size,
|
||||
void *hash_buf)
|
||||
static int array_map_get_hash(struct bpf_map *map)
|
||||
{
|
||||
struct bpf_array *array = container_of(map, struct bpf_array, map);
|
||||
|
||||
sha256(array->value, (u64)array->elem_size * array->map.max_entries,
|
||||
hash_buf);
|
||||
memcpy(array->map.sha, hash_buf, sizeof(array->map.sha));
|
||||
array->map.sha);
|
||||
return 0;
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -20,7 +20,8 @@ struct bpf_map *bpf_map_meta_alloc(int inner_map_ufd)
|
|||
/* Does not support >1 level map-in-map */
|
||||
if (inner_map->inner_map_meta)
|
||||
return ERR_PTR(-EINVAL);
|
||||
|
||||
if (inner_map->excl_prog_sha)
|
||||
return ERR_PTR(-ENOTSUPP);
|
||||
if (!inner_map->ops->map_meta_equal)
|
||||
return ERR_PTR(-ENOTSUPP);
|
||||
|
||||
|
|
@ -101,6 +102,8 @@ void *bpf_map_fd_get_ptr(struct bpf_map *map,
|
|||
inner_map = __bpf_map_get(f);
|
||||
if (IS_ERR(inner_map))
|
||||
return inner_map;
|
||||
if (inner_map->excl_prog_sha)
|
||||
return ERR_PTR(-ENOTSUPP);
|
||||
|
||||
inner_map_meta = map->inner_map_meta;
|
||||
if (inner_map_meta->ops->map_meta_equal(inner_map_meta, inner_map))
|
||||
|
|
|
|||
|
|
@ -1588,6 +1588,13 @@ static int map_create_alloc(union bpf_attr *attr, bpfptr_t uattr, struct bpf_ver
|
|||
err = -EFAULT;
|
||||
goto free_map;
|
||||
}
|
||||
|
||||
/* See libbpf: emit_signature_match() */
|
||||
BUILD_BUG_ON(offsetof(struct bpf_map, excl) != SHA256_DIGEST_SIZE);
|
||||
BUILD_BUG_ON(!__same_type(map->excl, u32));
|
||||
BUILD_BUG_ON(offsetof(struct bpf_map, sha) != 0);
|
||||
BUILD_BUG_ON(!__same_type(map->sha, u8[SHA256_DIGEST_SIZE]));
|
||||
map->excl = 1;
|
||||
} else if (attr->excl_prog_hash_size) {
|
||||
bpf_log(log, "Invalid excl_prog_hash_size.\n");
|
||||
err = -EINVAL;
|
||||
|
|
@ -5434,18 +5441,16 @@ static int bpf_map_get_info_by_fd(struct file *file,
|
|||
|
||||
if (!map->ops->map_get_hash)
|
||||
return -EINVAL;
|
||||
|
||||
if (info.hash_size != SHA256_DIGEST_SIZE)
|
||||
if (info.hash_size != sizeof(map->sha))
|
||||
return -EINVAL;
|
||||
|
||||
if (!READ_ONCE(map->frozen))
|
||||
return -EPERM;
|
||||
|
||||
err = map->ops->map_get_hash(map, SHA256_DIGEST_SIZE, map->sha);
|
||||
err = map->ops->map_get_hash(map);
|
||||
if (err != 0)
|
||||
return err;
|
||||
|
||||
if (copy_to_user(uhash, map->sha, SHA256_DIGEST_SIZE) != 0)
|
||||
if (copy_to_user(uhash, map->sha, sizeof(map->sha)) != 0)
|
||||
return -EFAULT;
|
||||
} else if (info.hash_size) {
|
||||
return -EINVAL;
|
||||
|
|
|
|||
|
|
@ -546,13 +546,22 @@ void bpf_gen__map_create(struct bpf_gen *gen,
|
|||
default:
|
||||
break;
|
||||
}
|
||||
/* conditionally update max_entries */
|
||||
if (map_idx >= 0)
|
||||
|
||||
/*
|
||||
* Conditionally update max_entries from the host-supplied loader
|
||||
* ctx. This sizes the map at runtime, but for a signed loader
|
||||
* (gen_hash) it would let an untrusted host re-dimension the
|
||||
* program's maps after emit_signature_match(), outside what the
|
||||
* signature attests to. Keep the signer-provided max_entries
|
||||
* baked into the blob in that case.
|
||||
*/
|
||||
if (map_idx >= 0 && !OPTS_GET(gen->opts, gen_hash, false))
|
||||
move_ctx2blob(gen, attr_field(map_create_attr, max_entries), 4,
|
||||
sizeof(struct bpf_loader_ctx) +
|
||||
sizeof(struct bpf_map_desc) * map_idx +
|
||||
offsetof(struct bpf_map_desc, max_entries),
|
||||
true /* check that max_entries != 0 */);
|
||||
|
||||
/* emit MAP_CREATE command */
|
||||
emit_sys_bpf(gen, BPF_MAP_CREATE, map_create_attr, attr_size);
|
||||
debug_ret(gen, "map_create %s idx %d type %d value_size %d value_btf_id %d",
|
||||
|
|
@ -586,6 +595,23 @@ static void emit_signature_match(struct bpf_gen *gen)
|
|||
__s64 off;
|
||||
int i;
|
||||
|
||||
/*
|
||||
* Reject if the metadata map is not exclusive. Without exclusivity
|
||||
* the cached map->sha[] verified above can be stale: another BPF
|
||||
* program with map access could have mutated the contents between
|
||||
* BPF_OBJ_GET_INFO_BY_FD and loader execution.
|
||||
*/
|
||||
emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX,
|
||||
0, 0, 0, 0));
|
||||
emit(gen, BPF_LDX_MEM(BPF_W, BPF_REG_2, BPF_REG_1, SHA256_DIGEST_LENGTH));
|
||||
off = -(gen->insn_cur - gen->insn_start - gen->cleanup_label) / 8 - 2;
|
||||
if (is_simm16(off)) {
|
||||
emit(gen, BPF_MOV64_IMM(BPF_REG_7, -EINVAL));
|
||||
emit(gen, BPF_JMP_IMM(BPF_JNE, BPF_REG_2, 1, off));
|
||||
} else {
|
||||
gen->error = -ERANGE;
|
||||
}
|
||||
|
||||
for (i = 0; i < SHA256_DWORD_SIZE; i++) {
|
||||
emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX,
|
||||
0, 0, 0, 0));
|
||||
|
|
@ -1170,27 +1196,36 @@ void bpf_gen__map_update_elem(struct bpf_gen *gen, int map_idx, void *pvalue,
|
|||
value = add_data(gen, pvalue, value_size);
|
||||
key = add_data(gen, &zero, sizeof(zero));
|
||||
|
||||
/* if (map_desc[map_idx].initial_value) {
|
||||
/*
|
||||
* if (map_desc[map_idx].initial_value) {
|
||||
* if (ctx->flags & BPF_SKEL_KERNEL)
|
||||
* bpf_probe_read_kernel(value, value_size, initial_value);
|
||||
* else
|
||||
* bpf_copy_from_user(value, value_size, initial_value);
|
||||
* }
|
||||
*
|
||||
* The runtime initial_value comes from the host-supplied loader
|
||||
* ctx and would overwrite the blob value after emit_signature_match()
|
||||
* has already validated map->sha[]. For a signed loader (gen_hash)
|
||||
* the attested blob value must be authoritative, so skip the override
|
||||
* and leave the hashed value in place.
|
||||
*/
|
||||
emit(gen, BPF_LDX_MEM(BPF_DW, BPF_REG_3, BPF_REG_6,
|
||||
sizeof(struct bpf_loader_ctx) +
|
||||
sizeof(struct bpf_map_desc) * map_idx +
|
||||
offsetof(struct bpf_map_desc, initial_value)));
|
||||
emit(gen, BPF_JMP_IMM(BPF_JEQ, BPF_REG_3, 0, 8));
|
||||
emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX_VALUE,
|
||||
0, 0, 0, value));
|
||||
emit(gen, BPF_MOV64_IMM(BPF_REG_2, value_size));
|
||||
emit(gen, BPF_LDX_MEM(BPF_W, BPF_REG_0, BPF_REG_6,
|
||||
offsetof(struct bpf_loader_ctx, flags)));
|
||||
emit(gen, BPF_JMP_IMM(BPF_JSET, BPF_REG_0, BPF_SKEL_KERNEL, 2));
|
||||
emit(gen, BPF_EMIT_CALL(BPF_FUNC_copy_from_user));
|
||||
emit(gen, BPF_JMP_IMM(BPF_JA, 0, 0, 1));
|
||||
emit(gen, BPF_EMIT_CALL(BPF_FUNC_probe_read_kernel));
|
||||
if (!OPTS_GET(gen->opts, gen_hash, false)) {
|
||||
emit(gen, BPF_LDX_MEM(BPF_DW, BPF_REG_3, BPF_REG_6,
|
||||
sizeof(struct bpf_loader_ctx) +
|
||||
sizeof(struct bpf_map_desc) * map_idx +
|
||||
offsetof(struct bpf_map_desc, initial_value)));
|
||||
emit(gen, BPF_JMP_IMM(BPF_JEQ, BPF_REG_3, 0, 8));
|
||||
emit2(gen, BPF_LD_IMM64_RAW_FULL(BPF_REG_1, BPF_PSEUDO_MAP_IDX_VALUE,
|
||||
0, 0, 0, value));
|
||||
emit(gen, BPF_MOV64_IMM(BPF_REG_2, value_size));
|
||||
emit(gen, BPF_LDX_MEM(BPF_W, BPF_REG_0, BPF_REG_6,
|
||||
offsetof(struct bpf_loader_ctx, flags)));
|
||||
emit(gen, BPF_JMP_IMM(BPF_JSET, BPF_REG_0, BPF_SKEL_KERNEL, 2));
|
||||
emit(gen, BPF_EMIT_CALL(BPF_FUNC_copy_from_user));
|
||||
emit(gen, BPF_JMP_IMM(BPF_JA, 0, 0, 1));
|
||||
emit(gen, BPF_EMIT_CALL(BPF_FUNC_probe_read_kernel));
|
||||
}
|
||||
|
||||
map_update_attr = add_data(gen, &attr, attr_size);
|
||||
pr_debug("gen: map_update_elem: idx %d, value: off %d size %d, attr: off %d size %d\n",
|
||||
|
|
|
|||
|
|
@ -8,6 +8,10 @@
|
|||
|
||||
#include "map_excl.skel.h"
|
||||
|
||||
#ifndef SHA256_DIGEST_SIZE
|
||||
#define SHA256_DIGEST_SIZE 32
|
||||
#endif
|
||||
|
||||
static void test_map_excl_allowed(void)
|
||||
{
|
||||
struct map_excl *skel = map_excl__open();
|
||||
|
|
@ -45,10 +49,52 @@ static void test_map_excl_denied(void)
|
|||
|
||||
}
|
||||
|
||||
static void test_map_excl_no_map_in_map(void)
|
||||
{
|
||||
__u8 hash[SHA256_DIGEST_SIZE] = {};
|
||||
LIBBPF_OPTS(bpf_map_create_opts, excl_opts,
|
||||
.excl_prog_hash = hash,
|
||||
.excl_prog_hash_size = sizeof(hash));
|
||||
LIBBPF_OPTS(bpf_map_create_opts, outer_opts);
|
||||
int excl_fd, tmpl_fd = -1, outer_fd = -1, err;
|
||||
__u32 key = 0;
|
||||
|
||||
excl_fd = bpf_map_create(BPF_MAP_TYPE_ARRAY, "excl_inner", 4, 4, 1, &excl_opts);
|
||||
if (!ASSERT_OK_FD(excl_fd, "create exclusive map"))
|
||||
return;
|
||||
|
||||
outer_opts.inner_map_fd = excl_fd;
|
||||
err = bpf_map_create(BPF_MAP_TYPE_ARRAY_OF_MAPS, "outer_from_excl",
|
||||
4, 4, 1, &outer_opts);
|
||||
if (err >= 0)
|
||||
close(err);
|
||||
ASSERT_EQ(err, -ENOTSUPP, "reject exclusive map as map-in-map template");
|
||||
|
||||
tmpl_fd = bpf_map_create(BPF_MAP_TYPE_ARRAY, "tmpl", 4, 4, 1, NULL);
|
||||
if (!ASSERT_OK_FD(tmpl_fd, "create inner template"))
|
||||
goto out;
|
||||
|
||||
outer_opts.inner_map_fd = tmpl_fd;
|
||||
outer_fd = bpf_map_create(BPF_MAP_TYPE_ARRAY_OF_MAPS, "outer", 4, 4, 1, &outer_opts);
|
||||
if (!ASSERT_OK_FD(outer_fd, "create map-of-maps"))
|
||||
goto out;
|
||||
|
||||
err = bpf_map_update_elem(outer_fd, &key, &excl_fd, 0);
|
||||
ASSERT_EQ(err, -ENOTSUPP, "reject exclusive map as map-in-map element");
|
||||
out:
|
||||
if (outer_fd >= 0)
|
||||
close(outer_fd);
|
||||
if (tmpl_fd >= 0)
|
||||
close(tmpl_fd);
|
||||
close(excl_fd);
|
||||
}
|
||||
|
||||
void test_map_excl(void)
|
||||
{
|
||||
if (test__start_subtest("map_excl_allowed"))
|
||||
test_map_excl_allowed();
|
||||
if (test__start_subtest("map_excl_denied"))
|
||||
test_map_excl_denied();
|
||||
if (test__start_subtest("map_excl_no_map_in_map"))
|
||||
test_map_excl_no_map_in_map();
|
||||
}
|
||||
|
|
|
|||
|
|
@ -70,13 +70,15 @@ __naked void bpf_map_ptr_write_rejected(void)
|
|||
: __clobber_all);
|
||||
}
|
||||
|
||||
/* The first element of struct bpf_map is a SHA256 hash of 32 bytes, accessing
|
||||
* into this array is valid. The opts field is now at offset 33.
|
||||
/*
|
||||
* struct bpf_map starts with the SHA256 hash sha[32] at offset 0 (a readable
|
||||
* byte array), followed by the u32 excl field at offset 32. Reading a u32 at
|
||||
* offset 33 runs past the end of excl and is rejected.
|
||||
*/
|
||||
SEC("socket")
|
||||
__description("bpf_map_ptr: read non-existent field rejected")
|
||||
__failure
|
||||
__msg("cannot access ptr member ops with moff 32 in struct bpf_map with off 33 size 4")
|
||||
__msg("access beyond the end of member excl (mend:36) in struct bpf_map with off 33 size 4")
|
||||
__failure_unpriv
|
||||
__msg_unpriv("access is allowed only to CAP_PERFMON and CAP_SYS_ADMIN")
|
||||
__flag(BPF_F_ANY_ALIGNMENT)
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user