From: chenyuan_fl@163.com
To: bpf@vger.kernel.org
Cc: ast@kernel.org, daniel@iogearbox.net, andrii@kernel.org,
andrii.nakryiko@gmail.com, Yuan Chen <chenyuan@kylinos.cn>
Subject: [PATCH bpf v4 0/2] bpf: Fix queue/stack map u32 index overflow
Date: Mon, 24 Aug 2026 16:33:25 +0800 [thread overview]
Message-ID: <20260824083327.1708560-1-chenyuan_fl@163.com> (raw)
In-Reply-To: <CAEf4BzbGe74OuUKiDz7oBrWzQCD54JVhYuCTQEWNHOHmnBEtbQ@mail.gmail.com>
From: Yuan Chen <chenyuan@kylinos.cn>
This series fixes an integer overflow in BPF queue/stack maps. The u32
head/tail index is multiplied by value_size to address elements[], but
the storage itself is allocated with 64-bit arithmetic. When
max_entries * value_size reaches or exceeds U32_MAX, the index
multiplication wraps and push/peek/pop operate on the wrong element,
corrupting map data and leaking stale values to user space.
max_entries == U32_MAX would also wrap the u32 capacity counter
qs->size (max_entries + 1) to 0 and permanently break the map.
Patch 1 restores the size bound in queue_stack_map_alloc_check() that
was lost when the check inside bpf_map_charge_init() was removed. A
single division-based comparison covers both the index multiplication
overflow and the capacity counter wrap.
Patch 2 adds a regression test for both rejection cases.
Many thanks to Andrii Nakryiko for the careful review and the helpful
suggestions: the bound has been simplified to a single
`max_entries >= U32_MAX / value_size` check, and the selftest now
asserts the bpf_map_create() return value directly instead of reading
errno.
v2 -> v3:
- also reject max_entries == U32_MAX, which would wrap the u32
capacity counter qs->size (max_entries + 1) to 0
- fix the Fixes tag: the guard was actually dropped by a37fb7ef24a4,
which removed the bpf_map_charge_init() call the check had been
moved into by c85d69135a91
v3 -> v4:
- simplify the bound to a single `max_entries >= U32_MAX /
value_size` comparison, which also rejects max_entries == U32_MAX
- check the bpf_map_create() return value directly instead of errno
in the selftest
Yuan Chen (2):
bpf: Fix queue/stack map u32 index overflow
selftests/bpf: Add regression test for queue/stack map size limit
kernel/bpf/queue_stack_maps.c | 9 ++++++
.../selftests/bpf/prog_tests/queue_stack_map.c | 37 ++++++++++++++++++++++
2 files changed, 46 insertions(+)
next prev parent reply other threads:[~2026-08-24 8:34 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-10 13:59 [PATCH bpf v3 0/2] bpf: Fix queue/stack map u32 index overflow chenyuan_fl
2026-08-10 13:59 ` [PATCH bpf v3 1/2] " chenyuan_fl
2026-08-10 13:59 ` [PATCH bpf v3 2/2] selftests/bpf: Add regression test for queue/stack map size limit chenyuan_fl
2026-08-10 14:49 ` bot+bpf-ci
2026-08-13 22:19 ` Andrii Nakryiko
2026-08-24 8:33 ` chenyuan_fl [this message]
2026-08-24 8:33 ` [PATCH bpf v4 1/2] bpf: Fix queue/stack map u32 index overflow chenyuan_fl
2026-08-24 8:47 ` sashiko-bot
2026-08-28 0:04 ` Andrii Nakryiko
2026-08-31 6:32 ` [PATCH bpf v5 0/2] " chenyuan_fl
2026-08-31 6:32 ` [PATCH bpf v5 1/2] " chenyuan_fl
2026-08-31 7:13 ` bot+bpf-ci
2026-08-31 6:32 ` [PATCH bpf v5 2/2] selftests/bpf: Add regression test for queue/stack map size limit chenyuan_fl
2026-08-31 7:13 ` bot+bpf-ci
2026-09-02 23:30 ` [PATCH bpf v5 0/2] bpf: Fix queue/stack map u32 index overflow patchwork-bot+netdevbpf
2026-08-24 8:33 ` [PATCH bpf v4 2/2] selftests/bpf: Add regression test for queue/stack map size limit chenyuan_fl
2026-08-24 8:43 ` sashiko-bot
2026-08-24 9:25 ` bot+bpf-ci
2026-08-28 0:04 ` Andrii Nakryiko
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260824083327.1708560-1-chenyuan_fl@163.com \
--to=chenyuan_fl@163.com \
--cc=andrii.nakryiko@gmail.com \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=chenyuan@kylinos.cn \
--cc=daniel@iogearbox.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.