From: Luis Gerhorst <luis.gerhorst@fau.de>
To: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Cc: Alexei Starovoitov <ast@kernel.org>,
Daniel Borkmann <daniel@iogearbox.net>,
Andrii Nakryiko <andrii@kernel.org>,
Martin KaFai Lau <martin.lau@linux.dev>,
Eduard Zingerman <eddyz87@gmail.com>, Song Liu <song@kernel.org>,
Yonghong Song <yonghong.song@linux.dev>,
John Fastabend <john.fastabend@gmail.com>,
KP Singh <kpsingh@kernel.org>,
Stanislav Fomichev <sdf@fomichev.me>,
Hao Luo <haoluo@google.com>, Jiri Olsa <jolsa@kernel.org>,
Puranjay Mohan <puranjay@kernel.org>,
Xu Kuohai <xukuohai@huaweicloud.com>,
Catalin Marinas <catalin.marinas@arm.com>,
Will Deacon <will@kernel.org>,
Hari Bathini <hbathini@linux.ibm.com>,
Christophe Leroy <christophe.leroy@csgroup.eu>,
Naveen N Rao <naveen@kernel.org>,
Madhavan Srinivasan <maddy@linux.ibm.com>,
Michael Ellerman <mpe@ellerman.id.au>,
Nicholas Piggin <npiggin@gmail.com>,
Mykola Lysenko <mykolal@fb.com>, Shuah Khan <shuah@kernel.org>,
Henriette Herzog <henriette.herzog@rub.de>,
Saket Kumar Bhaskar <skb99@linux.ibm.com>,
Cupertino Miranda <cupertino.miranda@oracle.com>,
Jiayuan Chen <mrpre@163.com>,
Matan Shachnai <m.shachnai@gmail.com>,
Dimitar Kanaliev <dimitar.kanaliev@siteground.com>,
Shung-Hsi Yu <shung-hsi.yu@suse.com>, Daniel Xu <dxu@dxuuu.xyz>,
bpf@vger.kernel.org, linux-arm-kernel@lists.infradead.org,
linux-kernel@vger.kernel.org, linuxppc-dev@lists.ozlabs.org,
linux-kselftest@vger.kernel.org, Maximilian Ott <ott@cs.fau.de>,
Milan Stephan <milan.stephan@fau.de>
Subject: Re: [PATCH bpf-next v3 10/11] bpf: Allow nospec-protected var-offset stack access
Date: Tue, 03 Jun 2025 23:07:30 +0200 [thread overview]
Message-ID: <874iwwlejx.fsf@fau.de> (raw)
In-Reply-To: <CAP01T76HZ+s5h+_REqRFkRjjoKwnZZn9YswpSVinGicah1pGJw@mail.gmail.com> (Kumar Kartikeya Dwivedi's message of "Fri, 2 May 2025 02:03:12 +0200")
Kumar Kartikeya Dwivedi <memxor@gmail.com> writes:
> Hmm, while reading related code, I noticed that sanitize_check_bounds
> returns 0 in case the type is not map_value or stack.
> It seems like it should be returning an error, cannot check right now
> but I'm pretty sure these are not the two pointer types unprivileged
> programs can access?
> So smells like a bug?
I now looked into this and as suspected it does not appear to be a bug
but only misleading code, I have sent a patch with a detailed
explanation and an assert:
https://lore.kernel.org/bpf/20250603204557.332447-1-luis.gerhorst@fau.de/T/#u
next prev parent reply other threads:[~2025-06-03 21:07 UTC|newest]
Thread overview: 35+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-05-01 7:35 [PATCH bpf-next v3 00/11] bpf: Mitigate Spectre v1 using barriers Luis Gerhorst
2025-05-01 7:35 ` [PATCH bpf-next v3 01/11] selftests/bpf: Fix caps for __xlated/jited_unpriv Luis Gerhorst
2025-05-01 16:56 ` Kumar Kartikeya Dwivedi
2025-05-01 17:45 ` Eduard Zingerman
2025-05-01 7:35 ` [PATCH bpf-next v3 02/11] bpf: Move insn if/else into do_check_insn() Luis Gerhorst
2025-05-01 18:22 ` Eduard Zingerman
2025-05-05 18:31 ` Luis Gerhorst
2025-05-01 22:06 ` Kumar Kartikeya Dwivedi
2025-05-01 7:35 ` [PATCH bpf-next v3 03/11] bpf: Return -EFAULT on misconfigurations Luis Gerhorst
2025-05-01 22:06 ` Kumar Kartikeya Dwivedi
2025-05-01 7:35 ` [PATCH bpf-next v3 04/11] bpf: Return -EFAULT on internal errors Luis Gerhorst
2025-05-01 22:07 ` Kumar Kartikeya Dwivedi
2025-05-01 7:35 ` [PATCH bpf-next v3 05/11] bpf, arm64, powerpc: Add bpf_jit_bypass_spec_v1/v4() Luis Gerhorst
2025-05-01 22:14 ` Kumar Kartikeya Dwivedi
2025-05-18 10:38 ` Hari Bathini
2025-05-01 7:35 ` [PATCH bpf-next v3 06/11] bpf, arm64, powerpc: Change nospec to include v1 barrier Luis Gerhorst
2025-05-19 7:01 ` Hari Bathini
2025-05-01 7:35 ` [PATCH bpf-next v3 07/11] bpf: Rename sanitize_stack_spill to nospec_result Luis Gerhorst
2025-05-01 22:30 ` Kumar Kartikeya Dwivedi
2025-05-01 7:35 ` [PATCH bpf-next v3 08/11] bpf: Fall back to nospec for Spectre v1 Luis Gerhorst
2025-05-01 23:55 ` Kumar Kartikeya Dwivedi
2025-05-02 18:57 ` Luis Gerhorst
2025-05-14 5:38 ` Kumar Kartikeya Dwivedi
2025-05-01 7:36 ` [PATCH bpf-next v3 09/11] selftests/bpf: Add test for Spectre v1 mitigation Luis Gerhorst
2025-05-14 6:24 ` Kumar Kartikeya Dwivedi
2025-05-01 7:36 ` [PATCH bpf-next v3 10/11] bpf: Allow nospec-protected var-offset stack access Luis Gerhorst
2025-05-02 0:03 ` Kumar Kartikeya Dwivedi
2025-06-03 21:07 ` Luis Gerhorst [this message]
2025-05-14 6:28 ` Kumar Kartikeya Dwivedi
2025-05-01 7:36 ` [PATCH bpf-next v3 11/11] bpf: Fall back to nospec for sanitization-failures Luis Gerhorst
2025-05-14 6:47 ` Kumar Kartikeya Dwivedi
2025-05-14 17:30 ` Luis Gerhorst
2025-05-14 17:34 ` Kumar Kartikeya Dwivedi
2025-05-09 18:40 ` [PATCH bpf-next v3 00/11] bpf: Mitigate Spectre v1 using barriers patchwork-bot+netdevbpf
2025-05-09 18:43 ` Alexei Starovoitov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=874iwwlejx.fsf@fau.de \
--to=luis.gerhorst@fau.de \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=catalin.marinas@arm.com \
--cc=christophe.leroy@csgroup.eu \
--cc=cupertino.miranda@oracle.com \
--cc=daniel@iogearbox.net \
--cc=dimitar.kanaliev@siteground.com \
--cc=dxu@dxuuu.xyz \
--cc=eddyz87@gmail.com \
--cc=haoluo@google.com \
--cc=hbathini@linux.ibm.com \
--cc=henriette.herzog@rub.de \
--cc=john.fastabend@gmail.com \
--cc=jolsa@kernel.org \
--cc=kpsingh@kernel.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-kselftest@vger.kernel.org \
--cc=linuxppc-dev@lists.ozlabs.org \
--cc=m.shachnai@gmail.com \
--cc=maddy@linux.ibm.com \
--cc=martin.lau@linux.dev \
--cc=memxor@gmail.com \
--cc=milan.stephan@fau.de \
--cc=mpe@ellerman.id.au \
--cc=mrpre@163.com \
--cc=mykolal@fb.com \
--cc=naveen@kernel.org \
--cc=npiggin@gmail.com \
--cc=ott@cs.fau.de \
--cc=puranjay@kernel.org \
--cc=sdf@fomichev.me \
--cc=shuah@kernel.org \
--cc=shung-hsi.yu@suse.com \
--cc=skb99@linux.ibm.com \
--cc=song@kernel.org \
--cc=will@kernel.org \
--cc=xukuohai@huaweicloud.com \
--cc=yonghong.song@linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.