mirror of
https://github.com/linux-msm/laptops-kernel.git
synced 2026-08-13 14:19:53 -07:00
bpf: Fix WARNING in bpf_tracing_link_release
The trampoline could be corrupted by the blindly
'tr->flags = BPF_TRAMP_F_TAIL_CALL_CTX' in verifier.
1. A fexit attached to a tail_call_reachable prog. 'tr->flags' became
'BPF_TRAMP_F_CALL_ORIG | BPF_TRAMP_F_TAIL_CALL_CTX'. And, the
trampoline would poke the target prog's nop insn using jmp insn instead
of call insn.
2. Another fexit loaded with the same tail_call_reachable prog target.
'tr->flags' became 'BPF_TRAMP_F_TAIL_CALL_CTX'.
3. Close the first fexit link. Due to no BPF_TRAMP_F_CALL_ORIG in
'tr->flags', the trampoline will fail to restore the prog's nop insn
using call insn.
[ 3.410719] WARNING: kernel/bpf/syscall.c:3551 at bpf_tracing_link_release+0x53/0x60, CPU#1: test_progs/98
...
[ 3.428793] bpf_link_free+0x58/0x130
[ 3.429293] bpf_link_release+0x23/0x30
Fix the warning by updating 'tr->flags' with '|=' and lock.
Fixes: 2b5dcb31a1 ("bpf, x64: Fix tailcall infinite loop")
Signed-off-by: Leon Hwang <leon.hwang@linux.dev>
Reviewed-by: Pu Lehui <pulehui@huawei.com>
Acked-by: Jiri Olsa <jolsa@kernel.org>
Link: https://lore.kernel.org/bpf/20260722151909.69142-2-leon.hwang@linux.dev
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
This commit is contained in:
@@ -1523,6 +1523,7 @@ int bpf_trampoline_multi_attach(struct bpf_prog *prog, u32 *ids,
|
||||
struct bpf_tracing_multi_link *link);
|
||||
int bpf_trampoline_multi_detach(struct bpf_prog *prog,
|
||||
struct bpf_tracing_multi_link *link);
|
||||
void bpf_trampoline_set_flags(struct bpf_trampoline *tr, u32 flags);
|
||||
|
||||
/*
|
||||
* When the architecture supports STATIC_CALL replace the bpf_dispatcher_fn
|
||||
@@ -1646,6 +1647,7 @@ static inline int bpf_trampoline_multi_detach(struct bpf_prog *prog,
|
||||
{
|
||||
return -ENOTSUPP;
|
||||
}
|
||||
static inline void bpf_trampoline_set_flags(struct bpf_trampoline *tr, u32 flags) {}
|
||||
#endif
|
||||
|
||||
struct bpf_func_info_aux {
|
||||
|
||||
@@ -670,6 +670,13 @@ out:
|
||||
return ERR_PTR(err);
|
||||
}
|
||||
|
||||
void bpf_trampoline_set_flags(struct bpf_trampoline *tr, u32 flags)
|
||||
{
|
||||
trampoline_lock(tr);
|
||||
tr->flags |= flags;
|
||||
trampoline_unlock(tr);
|
||||
}
|
||||
|
||||
static int bpf_trampoline_update(struct bpf_trampoline *tr, bool lock_direct_mutex,
|
||||
const struct bpf_trampoline_ops *ops, void *data)
|
||||
{
|
||||
|
||||
@@ -19523,7 +19523,7 @@ static int check_attach_btf_id(struct bpf_verifier_env *env)
|
||||
return -ENOMEM;
|
||||
|
||||
if (tgt_prog && tgt_prog->aux->tail_call_reachable)
|
||||
tr->flags = BPF_TRAMP_F_TAIL_CALL_CTX;
|
||||
bpf_trampoline_set_flags(tr, BPF_TRAMP_F_TAIL_CALL_CTX);
|
||||
|
||||
prog->aux->dst_trampoline = tr;
|
||||
return 0;
|
||||
|
||||
Reference in New Issue
Block a user