mirror of
https://github.com/torvalds/linux.git
synced 2026-09-11 02:48:03 +02:00
bpf: mark a NULL BTF_ID argument of a global subprogram precise
btf_check_func_arg_match() accepts a NULL register for an
ARG_PTR_TO_BTF_ID argument tagged __arg_nullable and skips
check_reg_type() and check_func_arg_reg_off() without marking the
register precise. Hence a checkpoint created on such a path would
prune against arbitrary scalar value.
Fixes: e2b3c4ff5d ("bpf: add __arg_trusted global func arg tag")
Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
Link: https://lore.kernel.org/r/20260904-register-is-null-precise-fixes-v1-7-0f5a360ff15d@gmail.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
This commit is contained in:
parent
562d266d3f
commit
e726fc6b9a
|
|
@ -9774,8 +9774,12 @@ static int btf_check_func_arg_match(struct bpf_verifier_env *env, int subprog,
|
|||
struct bpf_call_arg_meta meta;
|
||||
int err;
|
||||
|
||||
if (bpf_register_is_null(reg) && type_may_be_null(arg->arg_type))
|
||||
if (bpf_register_is_null(reg) && type_may_be_null(arg->arg_type)) {
|
||||
err = mark_arg_precision(env, argno);
|
||||
if (err)
|
||||
return err;
|
||||
continue;
|
||||
}
|
||||
|
||||
memset(&meta, 0, sizeof(meta)); /* leave func_id as zero */
|
||||
err = check_reg_type(env, reg, argno, arg->arg_type, &arg->btf_id, &meta,
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user