bpf: Zero queue and stack outputs on lock failure

Queue and stack pop/peek helpers accept an uninitialized output buffer
because the verifier expects the helper to initialize it. The empty-map
error path clears the buffer, but a failed lock acquisition returns
-EBUSY without writing it.

Clear the output before returning -EBUSY so BPF programs cannot observe
uninitialized stack contents after a failed helper call.

Fixes: a34a9f1a19 ("bpf: Avoid deadlock when using queue and stack maps from NMI")
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
Link: https://lore.kernel.org/bpf/20260719125419.1782196-1-memxor@gmail.com
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
This commit is contained in:
Kumar Kartikeya Dwivedi
2026-07-21 18:55:48 +02:00
parent 5f30ac9472
commit 7ac6e1ae41
+6 -2
View File
@@ -99,8 +99,10 @@ static long __queue_map_get(struct bpf_map *map, void *value, bool delete)
int err = 0;
void *ptr;
if (raw_res_spin_lock_irqsave(&qs->lock, flags))
if (raw_res_spin_lock_irqsave(&qs->lock, flags)) {
memset(value, 0, qs->map.value_size);
return -EBUSY;
}
if (queue_stack_map_is_empty(qs)) {
memset(value, 0, qs->map.value_size);
@@ -130,8 +132,10 @@ static long __stack_map_get(struct bpf_map *map, void *value, bool delete)
void *ptr;
u32 index;
if (raw_res_spin_lock_irqsave(&qs->lock, flags))
if (raw_res_spin_lock_irqsave(&qs->lock, flags)) {
memset(value, 0, qs->map.value_size);
return -EBUSY;
}
if (queue_stack_map_is_empty(qs)) {
memset(value, 0, qs->map.value_size);