All of lore.kernel.org
 help / color / mirror / Atom feed
From: Jiri Olsa <olsajiri@gmail.com>
To: Andrii Nakryiko <andrii.nakryiko@gmail.com>
Cc: Alexei Starovoitov <ast@kernel.org>,
	Daniel Borkmann <daniel@iogearbox.net>,
	Andrii Nakryiko <andrii@kernel.org>,
	Sashiko <sashiko-bot@kernel.org>,
	bpf@vger.kernel.org, Martin KaFai Lau <martin.lau@linux.dev>,
	Eduard Zingerman <eddyz87@gmail.com>,
	Song Liu <songliubraving@fb.com>, Yonghong Song <yhs@fb.com>,
	Quentin Monnet <qmo@kernel.org>, Tao Chen <chen.dylane@linux.dev>,
	STAR Labs SG <info@starlabs.sg>,
	Arnaud Lecomte <contact@arnaud-lcm.com>
Subject: Re: [PATCHv2 bpf-next 11/11] bpf: Clear buf on error in __bpf_get_task_stack
Date: Fri, 31 Jul 2026 15:33:33 +0200	[thread overview]
Message-ID: <amykLSjSzayP4WHa@krava> (raw)
In-Reply-To: <CAEf4BzYvmVJ7bFZ_dmW-HbwwM1yUxzs40yHNdF_JTn+Hr+0w4A@mail.gmail.com>

On Thu, Jul 30, 2026 at 04:11:02PM -0700, Andrii Nakryiko wrote:
> On Wed, Jul 29, 2026 at 1:40 AM Jiri Olsa <jolsa@kernel.org> wrote:
> >
> > Both bpf_get_task_stack and bpf_get_task_stack helpers that use
> > __bpf_get_task_stack have buf defined as ARG_PTR_TO_UNINIT_MEM
> > argument, and we should initialize the buf on every return path.
> >
> 
> why "should"? what's the point to initialize it to all zeroes if we
> failed to get stack trace? we shouldn't allow grabbing stack trace
> without CAP_PERFMON, and with CAP_PERFMON we shouldn't be worried
> about "leaking kernel memory" because CAP_PERFMON is plenty privileged
> and allows to access any kernel memory.

hum __bpf_get_stack already clears buf on error, so I did not question it ;-)

there's this comment:

        /* Pointer to memory does not need to be initialized, since helper function
         * fills all bytes or clears them in error case.
         */
        ARG_PTR_TO_UNINIT_MEM           = MEM_UNINIT | MEM_WRITE | ARG_PTR_TO_MEM,

IIUC from verifier POV bpf_get_task_stack switches un-initialized buffer to
initialized regardless of the returned error and such buffer could be then
passed to another helper that allows only initialized buffer

jirka

> 
> or am I missing more reasoning behind this change?
> 
> > Adding missing buf memset for __bpf_get_task_stack fail paths.
> > The __bpf_get_stack call does clear the buf properly.
> >
> > Fixes: 06ab134ce8ec ("bpf: Refcount task stack in bpf_get_task_stack")
> > Fixes: b992f01e6615 ("bpf: Guard against accessing NULL pt_regs in bpf_get_task_stack()")
> > Reported-by: Sashiko <sashiko-bot@kernel.org>
> > Signed-off-by: Jiri Olsa <jolsa@kernel.org>
> > ---
> >  kernel/bpf/stackmap.c | 7 +++++--
> >  1 file changed, 5 insertions(+), 2 deletions(-)
> >
> > diff --git a/kernel/bpf/stackmap.c b/kernel/bpf/stackmap.c
> > index f4827afbfed9..9ab0c2523a41 100644
> > --- a/kernel/bpf/stackmap.c
> > +++ b/kernel/bpf/stackmap.c
> > @@ -890,14 +890,17 @@ static long __bpf_get_task_stack(struct task_struct *task, void *buf, u32 size,
> >         struct pt_regs *regs;
> >         long res = -EINVAL;
> >
> > -       if (!try_get_task_stack(task))
> > +       if (!try_get_task_stack(task)) {
> > +               memset(buf, 0, size);
> >                 return -EFAULT;
> > +       }
> >
> >         regs = task_pt_regs(task);
> >         if (regs)
> >                 res = __bpf_get_stack(regs, task, buf, size, flags, may_fault);
> > +       else
> > +               memset(buf, 0, size);
> >         put_task_stack(task);
> > -
> >         return res;
> >  }
> >
> > --
> > 2.54.0
> >

  reply	other threads:[~2026-07-31 13:33 UTC|newest]

Thread overview: 34+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-29  8:37 [PATCHv2 bpf-next 00/11] bpf: Disable preemption in stack map code Jiri Olsa
2026-07-29  8:37 ` [PATCHv2 bpf-next 01/11] bpf: Factor stackid_init function from __bpf_get_stackid Jiri Olsa
2026-07-29  8:51   ` sashiko-bot
2026-07-30 12:04     ` Jiri Olsa
2026-07-29  8:37 ` [PATCHv2 bpf-next 02/11] bpf: Factor stackid_fastpath " Jiri Olsa
2026-07-29  8:37 ` [PATCHv2 bpf-next 03/11] bpf: Factor stackid_new_bucket " Jiri Olsa
2026-07-29  8:38 ` [PATCHv2 bpf-next 04/11] bpf: Use stack id functions instead of __bpf_get_stackid Jiri Olsa
2026-07-29  9:42   ` bot+bpf-ci
2026-07-29  8:38 ` [PATCHv2 bpf-next 05/11] bpf: Disable preemption in bpf_get_stackid Jiri Olsa
2026-07-29 10:30   ` Leon Hwang
2026-07-30 11:38     ` Jiri Olsa
2026-07-30 13:43       ` Leon Hwang
2026-07-30 22:52         ` Andrii Nakryiko
2026-07-31 13:33           ` Jiri Olsa
2026-07-29  8:38 ` [PATCHv2 bpf-next 06/11] bpf: Factor callchain_store function from __bpf_get_stack Jiri Olsa
2026-07-29  8:57   ` sashiko-bot
2026-07-30 12:04     ` Jiri Olsa
2026-07-29  8:38 ` [PATCHv2 bpf-next 07/11] bpf: Factor callchain_finalize " Jiri Olsa
2026-07-29  9:41   ` bot+bpf-ci
2026-07-29  8:38 ` [PATCHv2 bpf-next 08/11] bpf: Restore trace->nr value properly in bpf_get_stack_pe Jiri Olsa
2026-07-30 23:01   ` Andrii Nakryiko
2026-07-31 13:33     ` Jiri Olsa
2026-07-29  8:38 ` [PATCHv2 bpf-next 09/11] bpf: Remove trace_in argument from __bpf_get_stack Jiri Olsa
2026-07-29  9:58   ` bot+bpf-ci
2026-07-30 23:06   ` Andrii Nakryiko
2026-07-31 13:33     ` Jiri Olsa
2026-07-31 15:14       ` Andrii Nakryiko
2026-07-29  8:38 ` [PATCHv2 bpf-next 10/11] bpf: Disable preemption in __bpf_get_stack Jiri Olsa
2026-07-29  8:38 ` [PATCHv2 bpf-next 11/11] bpf: Clear buf on error in __bpf_get_task_stack Jiri Olsa
2026-07-29  9:57   ` bot+bpf-ci
2026-07-30 12:04     ` Jiri Olsa
2026-07-30 23:11   ` Andrii Nakryiko
2026-07-31 13:33     ` Jiri Olsa [this message]
2026-07-31 15:18       ` Andrii Nakryiko

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=amykLSjSzayP4WHa@krava \
    --to=olsajiri@gmail.com \
    --cc=andrii.nakryiko@gmail.com \
    --cc=andrii@kernel.org \
    --cc=ast@kernel.org \
    --cc=bpf@vger.kernel.org \
    --cc=chen.dylane@linux.dev \
    --cc=contact@arnaud-lcm.com \
    --cc=daniel@iogearbox.net \
    --cc=eddyz87@gmail.com \
    --cc=info@starlabs.sg \
    --cc=martin.lau@linux.dev \
    --cc=qmo@kernel.org \
    --cc=sashiko-bot@kernel.org \
    --cc=songliubraving@fb.com \
    --cc=yhs@fb.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.