* [PATCH bpf-next 0/2] Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init
@ 2023-09-12 0:55 Eduard Zingerman
2023-09-12 0:55 ` [PATCH bpf-next 1/2] bpf: " Eduard Zingerman
` (2 more replies)
0 siblings, 3 replies; 6+ messages in thread
From: Eduard Zingerman @ 2023-09-12 0:55 UTC (permalink / raw)
To: bpf, ast
Cc: andrii, daniel, martin.lau, kernel-team, yonghong.song, sdf, kuba,
Eduard Zingerman
For a device bound BPF program with flag BPF_F_XDP_DEV_BOUND_ONLY,
in case if device does not support offload, __bpf_prog_dev_bound_init()
creates a dummy bpf_offload_netdev struct with .offdev field set to NULL.
This dummy struct might be reused for programs without this flag
bound to the same device. However, bpf_prog_offload_verifier_prep()
that uses bpf_offload_netdev assumes that .offdev field cannot be NULL.
This bug was reported by syzbot in [1].
[1] https://lore.kernel.org/bpf/000000000000d97f3c060479c4f8@google.com/
Eduard Zingerman (2):
bpf: Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init
selftests/bpf: Offloaded prog after non-offloaded should not cause BUG
kernel/bpf/offload.c | 12 ++--
.../bpf/prog_tests/xdp_dev_bound_only.c | 58 +++++++++++++++++++
2 files changed, 65 insertions(+), 5 deletions(-)
create mode 100644 tools/testing/selftests/bpf/prog_tests/xdp_dev_bound_only.c
--
2.41.0
^ permalink raw reply [flat|nested] 6+ messages in thread* [PATCH bpf-next 1/2] bpf: Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init 2023-09-12 0:55 [PATCH bpf-next 0/2] Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init Eduard Zingerman @ 2023-09-12 0:55 ` Eduard Zingerman 2023-09-12 0:55 ` [PATCH bpf-next 2/2] selftests/bpf: Offloaded prog after non-offloaded should not cause BUG Eduard Zingerman 2023-09-12 6:30 ` [PATCH bpf-next 0/2] Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init patchwork-bot+netdevbpf 2 siblings, 0 replies; 6+ messages in thread From: Eduard Zingerman @ 2023-09-12 0:55 UTC (permalink / raw) To: bpf, ast Cc: andrii, daniel, martin.lau, kernel-team, yonghong.song, sdf, kuba, Eduard Zingerman, syzbot+291100dcb32190ec02a8 Fix for a bug observable under the following sequence of events: 1. Create a network device that does not support XDP offload. 2. Load a device bound XDP program with BPF_F_XDP_DEV_BOUND_ONLY flag (such programs are not offloaded). 3. Load a device bound XDP program with zero flags (such programs are offloaded). At step (2) __bpf_prog_dev_bound_init() associates with device (1) a dummy bpf_offload_netdev struct with .offdev field set to NULL. At step (3) __bpf_prog_dev_bound_init() would reuse dummy struct allocated at step (2). However, downstream usage of the bpf_offload_netdev assumes that .offdev field can't be NULL, e.g. in bpf_prog_offload_verifier_prep(). Adjust __bpf_prog_dev_bound_init() to require bpf_offload_netdev with non-NULL .offdev for offloaded BPF programs. Fixes: 2b3486bc2d23 ("bpf: Introduce device-bound XDP programs") Reported-by: syzbot+291100dcb32190ec02a8@syzkaller.appspotmail.com Closes: https://lore.kernel.org/bpf/000000000000d97f3c060479c4f8@google.com/ Signed-off-by: Eduard Zingerman <eddyz87@gmail.com> --- kernel/bpf/offload.c | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/kernel/bpf/offload.c b/kernel/bpf/offload.c index 3e4f2ec1af06..87d6693d8233 100644 --- a/kernel/bpf/offload.c +++ b/kernel/bpf/offload.c @@ -199,12 +199,14 @@ static int __bpf_prog_dev_bound_init(struct bpf_prog *prog, struct net_device *n offload->netdev = netdev; ondev = bpf_offload_find_netdev(offload->netdev); + /* When program is offloaded require presence of "true" + * bpf_offload_netdev, avoid the one created for !ondev case below. + */ + if (bpf_prog_is_offloaded(prog->aux) && (!ondev || !ondev->offdev)) { + err = -EINVAL; + goto err_free; + } if (!ondev) { - if (bpf_prog_is_offloaded(prog->aux)) { - err = -EINVAL; - goto err_free; - } - /* When only binding to the device, explicitly * create an entry in the hashtable. */ -- 2.41.0 ^ permalink raw reply related [flat|nested] 6+ messages in thread
* [PATCH bpf-next 2/2] selftests/bpf: Offloaded prog after non-offloaded should not cause BUG 2023-09-12 0:55 [PATCH bpf-next 0/2] Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init Eduard Zingerman 2023-09-12 0:55 ` [PATCH bpf-next 1/2] bpf: " Eduard Zingerman @ 2023-09-12 0:55 ` Eduard Zingerman 2023-09-12 6:26 ` Martin KaFai Lau 2023-09-12 6:30 ` [PATCH bpf-next 0/2] Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init patchwork-bot+netdevbpf 2 siblings, 1 reply; 6+ messages in thread From: Eduard Zingerman @ 2023-09-12 0:55 UTC (permalink / raw) To: bpf, ast Cc: andrii, daniel, martin.lau, kernel-team, yonghong.song, sdf, kuba, Eduard Zingerman Check what happens if non-offloaded dev bound BPF program is followed by offloaded dev bound program. Test case adapated from syzbot report [1]. [1] https://lore.kernel.org/bpf/000000000000d97f3c060479c4f8@google.com/ Signed-off-by: Eduard Zingerman <eddyz87@gmail.com> --- .../bpf/prog_tests/xdp_dev_bound_only.c | 58 +++++++++++++++++++ 1 file changed, 58 insertions(+) create mode 100644 tools/testing/selftests/bpf/prog_tests/xdp_dev_bound_only.c diff --git a/tools/testing/selftests/bpf/prog_tests/xdp_dev_bound_only.c b/tools/testing/selftests/bpf/prog_tests/xdp_dev_bound_only.c new file mode 100644 index 000000000000..5ee4c16d2e21 --- /dev/null +++ b/tools/testing/selftests/bpf/prog_tests/xdp_dev_bound_only.c @@ -0,0 +1,58 @@ +// SPDX-License-Identifier: GPL-2.0 +#include <net/if.h> +#include <test_progs.h> +#include <network_helpers.h> + +#define LOCAL_NETNS "xdp_dev_bound_only_netns" + +int load_dummy_prog(char *name, __u32 ifindex, __u32 flags) +{ + struct bpf_insn insns[] = { BPF_MOV64_IMM(BPF_REG_0, 0), BPF_EXIT_INSN() }; + LIBBPF_OPTS(bpf_prog_load_opts, opts); + + opts.prog_flags = flags; + opts.prog_ifindex = ifindex; + return bpf_prog_load(BPF_PROG_TYPE_XDP, name, "GPL", insns, ARRAY_SIZE(insns), &opts); +} + +/* A test case for bpf_offload_netdev->offload handling bug: + * - create a veth device (does not support offload); + * - create a device bound XDP program with BPF_F_XDP_DEV_BOUND_ONLY flag + * (such programs are not offloaded); + * - create a device bound XDP program without flags (such programs are offloaded). + * This might lead to 'BUG: kernel NULL pointer dereference'. + */ +void test_xdp_dev_bound_only_offdev(void) +{ + struct nstoken *tok = NULL; + __u32 ifindex; + int fd1 = -1; + int fd2 = -1; + + SYS(out, "ip netns add " LOCAL_NETNS); + tok = open_netns(LOCAL_NETNS); + SYS(out, "ip link add eth42 type veth"); + ifindex = if_nametoindex("eth42"); + if (!ASSERT_NEQ(ifindex, 0, "if_nametoindex")) { + perror("if_nametoindex"); + goto out; + } + fd1 = load_dummy_prog("dummy1", ifindex, BPF_F_XDP_DEV_BOUND_ONLY); + if (!ASSERT_GE(fd1, 0, "load_dummy_prog #1")) { + perror("load_dummy_prog #1"); + goto out; + } + /* Program with ifindex is considered offloaded, however veth + * does not support offload => error should be reported. + */ + fd2 = load_dummy_prog("dummy2", ifindex, 0); + ASSERT_EQ(fd2, -EINVAL, "load_dummy_prog #2 (offloaded)"); + +out: + close(fd1); + close(fd2); + SYS_NOFAIL("ip link delete eth42"); + SYS_NOFAIL("ip netns del " LOCAL_NETNS); + if (tok) + close_netns(tok); +} -- 2.41.0 ^ permalink raw reply related [flat|nested] 6+ messages in thread
* Re: [PATCH bpf-next 2/2] selftests/bpf: Offloaded prog after non-offloaded should not cause BUG 2023-09-12 0:55 ` [PATCH bpf-next 2/2] selftests/bpf: Offloaded prog after non-offloaded should not cause BUG Eduard Zingerman @ 2023-09-12 6:26 ` Martin KaFai Lau 2023-09-12 9:59 ` Eduard Zingerman 0 siblings, 1 reply; 6+ messages in thread From: Martin KaFai Lau @ 2023-09-12 6:26 UTC (permalink / raw) To: Eduard Zingerman Cc: andrii, daniel, kernel-team, yonghong.song, sdf, kuba, bpf, ast On 9/11/23 5:55 PM, Eduard Zingerman wrote: > Check what happens if non-offloaded dev bound BPF > program is followed by offloaded dev bound program. > Test case adapated from syzbot report [1]. > > [1] https://lore.kernel.org/bpf/000000000000d97f3c060479c4f8@google.com/ > > Signed-off-by: Eduard Zingerman <eddyz87@gmail.com> > --- > .../bpf/prog_tests/xdp_dev_bound_only.c | 58 +++++++++++++++++++ > 1 file changed, 58 insertions(+) > create mode 100644 tools/testing/selftests/bpf/prog_tests/xdp_dev_bound_only.c > > diff --git a/tools/testing/selftests/bpf/prog_tests/xdp_dev_bound_only.c b/tools/testing/selftests/bpf/prog_tests/xdp_dev_bound_only.c > new file mode 100644 > index 000000000000..5ee4c16d2e21 > --- /dev/null > +++ b/tools/testing/selftests/bpf/prog_tests/xdp_dev_bound_only.c > @@ -0,0 +1,58 @@ > +// SPDX-License-Identifier: GPL-2.0 > +#include <net/if.h> > +#include <test_progs.h> > +#include <network_helpers.h> > + > +#define LOCAL_NETNS "xdp_dev_bound_only_netns" > + > +int load_dummy_prog(char *name, __u32 ifindex, __u32 flags) I added static. > +{ > + struct bpf_insn insns[] = { BPF_MOV64_IMM(BPF_REG_0, 0), BPF_EXIT_INSN() }; > + LIBBPF_OPTS(bpf_prog_load_opts, opts); > + > + opts.prog_flags = flags; > + opts.prog_ifindex = ifindex; > + return bpf_prog_load(BPF_PROG_TYPE_XDP, name, "GPL", insns, ARRAY_SIZE(insns), &opts); > +} > + > +/* A test case for bpf_offload_netdev->offload handling bug: > + * - create a veth device (does not support offload); > + * - create a device bound XDP program with BPF_F_XDP_DEV_BOUND_ONLY flag > + * (such programs are not offloaded); > + * - create a device bound XDP program without flags (such programs are offloaded). > + * This might lead to 'BUG: kernel NULL pointer dereference'. > + */ > +void test_xdp_dev_bound_only_offdev(void) > +{ > + struct nstoken *tok = NULL; > + __u32 ifindex; > + int fd1 = -1; > + int fd2 = -1; > + > + SYS(out, "ip netns add " LOCAL_NETNS); > + tok = open_netns(LOCAL_NETNS); Also added NULL check for tok. > + SYS(out, "ip link add eth42 type veth"); > + ifindex = if_nametoindex("eth42"); > + if (!ASSERT_NEQ(ifindex, 0, "if_nametoindex")) { > + perror("if_nametoindex"); > + goto out; > + } > + fd1 = load_dummy_prog("dummy1", ifindex, BPF_F_XDP_DEV_BOUND_ONLY); > + if (!ASSERT_GE(fd1, 0, "load_dummy_prog #1")) { > + perror("load_dummy_prog #1"); > + goto out; > + } > + /* Program with ifindex is considered offloaded, however veth > + * does not support offload => error should be reported. > + */ > + fd2 = load_dummy_prog("dummy2", ifindex, 0); > + ASSERT_EQ(fd2, -EINVAL, "load_dummy_prog #2 (offloaded)"); > + > +out: > + close(fd1); > + close(fd2); > + SYS_NOFAIL("ip link delete eth42"); > + SYS_NOFAIL("ip netns del " LOCAL_NETNS); > + if (tok) close_netns() can handle NULL, so removed this tok check. Applied. Thanks for the fix and test! > + close_netns(tok); > +} ^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH bpf-next 2/2] selftests/bpf: Offloaded prog after non-offloaded should not cause BUG 2023-09-12 6:26 ` Martin KaFai Lau @ 2023-09-12 9:59 ` Eduard Zingerman 0 siblings, 0 replies; 6+ messages in thread From: Eduard Zingerman @ 2023-09-12 9:59 UTC (permalink / raw) To: Martin KaFai Lau Cc: andrii, daniel, kernel-team, yonghong.song, sdf, kuba, bpf, ast On Mon, 2023-09-11 at 23:26 -0700, Martin KaFai Lau wrote: > On 9/11/23 5:55 PM, Eduard Zingerman wrote: [...] > > +int load_dummy_prog(char *name, __u32 ifindex, __u32 flags) > > I added static. [...] > > + tok = open_netns(LOCAL_NETNS); > > Also added NULL check for tok. [...] > > + if (tok) > > close_netns() can handle NULL, so removed this tok check. > > Applied. Thanks for the fix and test! Sorry, I should have noticed these issues before sending. Thank you for fixing it up. ^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH bpf-next 0/2] Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init 2023-09-12 0:55 [PATCH bpf-next 0/2] Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init Eduard Zingerman 2023-09-12 0:55 ` [PATCH bpf-next 1/2] bpf: " Eduard Zingerman 2023-09-12 0:55 ` [PATCH bpf-next 2/2] selftests/bpf: Offloaded prog after non-offloaded should not cause BUG Eduard Zingerman @ 2023-09-12 6:30 ` patchwork-bot+netdevbpf 2 siblings, 0 replies; 6+ messages in thread From: patchwork-bot+netdevbpf @ 2023-09-12 6:30 UTC (permalink / raw) To: Eduard Zingerman Cc: bpf, ast, andrii, daniel, martin.lau, kernel-team, yonghong.song, sdf, kuba Hello: This series was applied to bpf/bpf.git (master) by Martin KaFai Lau <martin.lau@kernel.org>: On Tue, 12 Sep 2023 03:55:36 +0300 you wrote: > For a device bound BPF program with flag BPF_F_XDP_DEV_BOUND_ONLY, > in case if device does not support offload, __bpf_prog_dev_bound_init() > creates a dummy bpf_offload_netdev struct with .offdev field set to NULL. > > This dummy struct might be reused for programs without this flag > bound to the same device. However, bpf_prog_offload_verifier_prep() > that uses bpf_offload_netdev assumes that .offdev field cannot be NULL. > > [...] Here is the summary with links: - [bpf-next,1/2] bpf: Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init https://git.kernel.org/bpf/bpf/c/1a49f4195d34 - [bpf-next,2/2] selftests/bpf: Offloaded prog after non-offloaded should not cause BUG https://git.kernel.org/bpf/bpf/c/e4c31164737e You are awesome, thank you! -- Deet-doot-dot, I am a bot. https://korg.docs.kernel.org/patchwork/pwbot.html ^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2023-09-12 9:59 UTC | newest] Thread overview: 6+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2023-09-12 0:55 [PATCH bpf-next 0/2] Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init Eduard Zingerman 2023-09-12 0:55 ` [PATCH bpf-next 1/2] bpf: " Eduard Zingerman 2023-09-12 0:55 ` [PATCH bpf-next 2/2] selftests/bpf: Offloaded prog after non-offloaded should not cause BUG Eduard Zingerman 2023-09-12 6:26 ` Martin KaFai Lau 2023-09-12 9:59 ` Eduard Zingerman 2023-09-12 6:30 ` [PATCH bpf-next 0/2] Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init patchwork-bot+netdevbpf
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox