syzbot reported the following BUG w/o CONFIG_DEBUG_INFO_BTF
BUG: KASAN: global-out-of-bounds in task_iter_init+0x212/0x2e7 kernel/bpf/task_iter.c:661
Read of size 4 at addr ffffffff90297404 by task swapper/0/1
CPU: 1 PID: 1 Comm: swapper/0 Not tainted 5.15.0-syzkaller #0
Hardware name: ... Google Compute Engine, BIOS Google 01/01/2011
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:88 [inline]
dump_stack_lvl+0xcd/0x134 lib/dump_stack.c:106
print_address_description.constprop.0.cold+0xf/0x309 mm/kasan/report.c:256
__kasan_report mm/kasan/report.c:442 [inline]
kasan_report.cold+0x83/0xdf mm/kasan/report.c:459
task_iter_init+0x212/0x2e7 kernel/bpf/task_iter.c:661
do_one_initcall+0x103/0x650 init/main.c:1295
do_initcall_level init/main.c:1368 [inline]
do_initcalls init/main.c:1384 [inline]
do_basic_setup init/main.c:1403 [inline]
kernel_init_freeable+0x6b1/0x73a init/main.c:1606
kernel_init+0x1a/0x1d0 init/main.c:1497
ret_from_fork+0x1f/0x30 arch/x86/entry/entry_64.S:295
</TASK>
This is caused by hard-coded name[1] in BTF_ID_LIST_GLOBAL (w/o
CONFIG_DEBUG_INFO_BTF). Fix this by adding a parameter n to
BTF_ID_LIST_GLOBAL. This avoids ifdef CONFIG_DEBUG_INFO_BTF in btf.c and
filter.c.
Fixes: 7c7e3d31e7 ("bpf: Introduce helper bpf_find_vma")
Reported-by: syzbot+e0d81ec552a21d9071aa@syzkaller.appspotmail.com
Reported-by: Eric Dumazet <edumazet@google.com>
Suggested-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: Song Liu <songliubraving@fb.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Acked-by: Yonghong Song <yhs@fb.com>
Link: https://lore.kernel.org/bpf/20211112150243.1270987-2-songliubraving@fb.com
194 lines
5.3 KiB
C
194 lines
5.3 KiB
C
/* SPDX-License-Identifier: GPL-2.0 */
|
|
|
|
#ifndef _LINUX_BTF_IDS_H
|
|
#define _LINUX_BTF_IDS_H
|
|
|
|
struct btf_id_set {
|
|
u32 cnt;
|
|
u32 ids[];
|
|
};
|
|
|
|
#ifdef CONFIG_DEBUG_INFO_BTF
|
|
|
|
#include <linux/compiler.h> /* for __PASTE */
|
|
|
|
/*
|
|
* Following macros help to define lists of BTF IDs placed
|
|
* in .BTF_ids section. They are initially filled with zeros
|
|
* (during compilation) and resolved later during the
|
|
* linking phase by resolve_btfids tool.
|
|
*
|
|
* Any change in list layout must be reflected in resolve_btfids
|
|
* tool logic.
|
|
*/
|
|
|
|
#define BTF_IDS_SECTION ".BTF_ids"
|
|
|
|
#define ____BTF_ID(symbol) \
|
|
asm( \
|
|
".pushsection " BTF_IDS_SECTION ",\"a\"; \n" \
|
|
".local " #symbol " ; \n" \
|
|
".type " #symbol ", STT_OBJECT; \n" \
|
|
".size " #symbol ", 4; \n" \
|
|
#symbol ": \n" \
|
|
".zero 4 \n" \
|
|
".popsection; \n");
|
|
|
|
#define __BTF_ID(symbol) \
|
|
____BTF_ID(symbol)
|
|
|
|
#define __ID(prefix) \
|
|
__PASTE(prefix, __COUNTER__)
|
|
|
|
/*
|
|
* The BTF_ID defines unique symbol for each ID pointing
|
|
* to 4 zero bytes.
|
|
*/
|
|
#define BTF_ID(prefix, name) \
|
|
__BTF_ID(__ID(__BTF_ID__##prefix##__##name##__))
|
|
|
|
/*
|
|
* The BTF_ID_LIST macro defines pure (unsorted) list
|
|
* of BTF IDs, with following layout:
|
|
*
|
|
* BTF_ID_LIST(list1)
|
|
* BTF_ID(type1, name1)
|
|
* BTF_ID(type2, name2)
|
|
*
|
|
* list1:
|
|
* __BTF_ID__type1__name1__1:
|
|
* .zero 4
|
|
* __BTF_ID__type2__name2__2:
|
|
* .zero 4
|
|
*
|
|
*/
|
|
#define __BTF_ID_LIST(name, scope) \
|
|
asm( \
|
|
".pushsection " BTF_IDS_SECTION ",\"a\"; \n" \
|
|
"." #scope " " #name "; \n" \
|
|
#name ":; \n" \
|
|
".popsection; \n");
|
|
|
|
#define BTF_ID_LIST(name) \
|
|
__BTF_ID_LIST(name, local) \
|
|
extern u32 name[];
|
|
|
|
#define BTF_ID_LIST_GLOBAL(name, n) \
|
|
__BTF_ID_LIST(name, globl)
|
|
|
|
/* The BTF_ID_LIST_SINGLE macro defines a BTF_ID_LIST with
|
|
* a single entry.
|
|
*/
|
|
#define BTF_ID_LIST_SINGLE(name, prefix, typename) \
|
|
BTF_ID_LIST(name) \
|
|
BTF_ID(prefix, typename)
|
|
#define BTF_ID_LIST_GLOBAL_SINGLE(name, prefix, typename) \
|
|
BTF_ID_LIST_GLOBAL(name, 1) \
|
|
BTF_ID(prefix, typename)
|
|
|
|
/*
|
|
* The BTF_ID_UNUSED macro defines 4 zero bytes.
|
|
* It's used when we want to define 'unused' entry
|
|
* in BTF_ID_LIST, like:
|
|
*
|
|
* BTF_ID_LIST(bpf_skb_output_btf_ids)
|
|
* BTF_ID(struct, sk_buff)
|
|
* BTF_ID_UNUSED
|
|
* BTF_ID(struct, task_struct)
|
|
*/
|
|
|
|
#define BTF_ID_UNUSED \
|
|
asm( \
|
|
".pushsection " BTF_IDS_SECTION ",\"a\"; \n" \
|
|
".zero 4 \n" \
|
|
".popsection; \n");
|
|
|
|
/*
|
|
* The BTF_SET_START/END macros pair defines sorted list of
|
|
* BTF IDs plus its members count, with following layout:
|
|
*
|
|
* BTF_SET_START(list)
|
|
* BTF_ID(type1, name1)
|
|
* BTF_ID(type2, name2)
|
|
* BTF_SET_END(list)
|
|
*
|
|
* __BTF_ID__set__list:
|
|
* .zero 4
|
|
* list:
|
|
* __BTF_ID__type1__name1__3:
|
|
* .zero 4
|
|
* __BTF_ID__type2__name2__4:
|
|
* .zero 4
|
|
*
|
|
*/
|
|
#define __BTF_SET_START(name, scope) \
|
|
asm( \
|
|
".pushsection " BTF_IDS_SECTION ",\"a\"; \n" \
|
|
"." #scope " __BTF_ID__set__" #name "; \n" \
|
|
"__BTF_ID__set__" #name ":; \n" \
|
|
".zero 4 \n" \
|
|
".popsection; \n");
|
|
|
|
#define BTF_SET_START(name) \
|
|
__BTF_ID_LIST(name, local) \
|
|
__BTF_SET_START(name, local)
|
|
|
|
#define BTF_SET_START_GLOBAL(name) \
|
|
__BTF_ID_LIST(name, globl) \
|
|
__BTF_SET_START(name, globl)
|
|
|
|
#define BTF_SET_END(name) \
|
|
asm( \
|
|
".pushsection " BTF_IDS_SECTION ",\"a\"; \n" \
|
|
".size __BTF_ID__set__" #name ", .-" #name " \n" \
|
|
".popsection; \n"); \
|
|
extern struct btf_id_set name;
|
|
|
|
#else
|
|
|
|
#define BTF_ID_LIST(name) static u32 name[5];
|
|
#define BTF_ID(prefix, name)
|
|
#define BTF_ID_UNUSED
|
|
#define BTF_ID_LIST_GLOBAL(name, n) u32 name[n];
|
|
#define BTF_ID_LIST_SINGLE(name, prefix, typename) static u32 name[1];
|
|
#define BTF_ID_LIST_GLOBAL_SINGLE(name, prefix, typename) u32 name[1];
|
|
#define BTF_SET_START(name) static struct btf_id_set name = { 0 };
|
|
#define BTF_SET_START_GLOBAL(name) static struct btf_id_set name = { 0 };
|
|
#define BTF_SET_END(name)
|
|
|
|
#endif /* CONFIG_DEBUG_INFO_BTF */
|
|
|
|
#ifdef CONFIG_NET
|
|
/* Define a list of socket types which can be the argument for
|
|
* skc_to_*_sock() helpers. All these sockets should have
|
|
* sock_common as the first argument in its memory layout.
|
|
*/
|
|
#define BTF_SOCK_TYPE_xxx \
|
|
BTF_SOCK_TYPE(BTF_SOCK_TYPE_INET, inet_sock) \
|
|
BTF_SOCK_TYPE(BTF_SOCK_TYPE_INET_CONN, inet_connection_sock) \
|
|
BTF_SOCK_TYPE(BTF_SOCK_TYPE_INET_REQ, inet_request_sock) \
|
|
BTF_SOCK_TYPE(BTF_SOCK_TYPE_INET_TW, inet_timewait_sock) \
|
|
BTF_SOCK_TYPE(BTF_SOCK_TYPE_REQ, request_sock) \
|
|
BTF_SOCK_TYPE(BTF_SOCK_TYPE_SOCK, sock) \
|
|
BTF_SOCK_TYPE(BTF_SOCK_TYPE_SOCK_COMMON, sock_common) \
|
|
BTF_SOCK_TYPE(BTF_SOCK_TYPE_TCP, tcp_sock) \
|
|
BTF_SOCK_TYPE(BTF_SOCK_TYPE_TCP_REQ, tcp_request_sock) \
|
|
BTF_SOCK_TYPE(BTF_SOCK_TYPE_TCP_TW, tcp_timewait_sock) \
|
|
BTF_SOCK_TYPE(BTF_SOCK_TYPE_TCP6, tcp6_sock) \
|
|
BTF_SOCK_TYPE(BTF_SOCK_TYPE_UDP, udp_sock) \
|
|
BTF_SOCK_TYPE(BTF_SOCK_TYPE_UDP6, udp6_sock) \
|
|
BTF_SOCK_TYPE(BTF_SOCK_TYPE_UNIX, unix_sock)
|
|
|
|
enum {
|
|
#define BTF_SOCK_TYPE(name, str) name,
|
|
BTF_SOCK_TYPE_xxx
|
|
#undef BTF_SOCK_TYPE
|
|
MAX_BTF_SOCK_TYPE,
|
|
};
|
|
|
|
extern u32 btf_sock_ids[];
|
|
#endif
|
|
|
|
extern u32 btf_task_struct_ids[];
|
|
|
|
#endif
|