* [PATCH bpf-next 0/2] Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init
@ 2023-09-12 0:55 Eduard Zingerman
2023-09-12 0:55 ` [PATCH bpf-next 1/2] bpf: " Eduard Zingerman
` (2 more replies)
0 siblings, 3 replies; 6+ messages in thread
From: Eduard Zingerman @ 2023-09-12 0:55 UTC (permalink / raw)
To: bpf, ast
Cc: andrii, daniel, martin.lau, kernel-team, yonghong.song, sdf, kuba,
Eduard Zingerman
For a device bound BPF program with flag BPF_F_XDP_DEV_BOUND_ONLY,
in case if device does not support offload, __bpf_prog_dev_bound_init()
creates a dummy bpf_offload_netdev struct with .offdev field set to NULL.
This dummy struct might be reused for programs without this flag
bound to the same device. However, bpf_prog_offload_verifier_prep()
that uses bpf_offload_netdev assumes that .offdev field cannot be NULL.
This bug was reported by syzbot in [1].
[1] https://lore.kernel.org/bpf/000000000000d97f3c060479c4f8@google.com/
Eduard Zingerman (2):
bpf: Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init
selftests/bpf: Offloaded prog after non-offloaded should not cause BUG
kernel/bpf/offload.c | 12 ++--
.../bpf/prog_tests/xdp_dev_bound_only.c | 58 +++++++++++++++++++
2 files changed, 65 insertions(+), 5 deletions(-)
create mode 100644 tools/testing/selftests/bpf/prog_tests/xdp_dev_bound_only.c
--
2.41.0
^ permalink raw reply [flat|nested] 6+ messages in thread
* [PATCH bpf-next 1/2] bpf: Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init
2023-09-12 0:55 [PATCH bpf-next 0/2] Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init Eduard Zingerman
@ 2023-09-12 0:55 ` Eduard Zingerman
2023-09-12 0:55 ` [PATCH bpf-next 2/2] selftests/bpf: Offloaded prog after non-offloaded should not cause BUG Eduard Zingerman
2023-09-12 6:30 ` [PATCH bpf-next 0/2] Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init patchwork-bot+netdevbpf
2 siblings, 0 replies; 6+ messages in thread
From: Eduard Zingerman @ 2023-09-12 0:55 UTC (permalink / raw)
To: bpf, ast
Cc: andrii, daniel, martin.lau, kernel-team, yonghong.song, sdf, kuba,
Eduard Zingerman, syzbot+291100dcb32190ec02a8
Fix for a bug observable under the following sequence of events:
1. Create a network device that does not support XDP offload.
2. Load a device bound XDP program with BPF_F_XDP_DEV_BOUND_ONLY flag
(such programs are not offloaded).
3. Load a device bound XDP program with zero flags
(such programs are offloaded).
At step (2) __bpf_prog_dev_bound_init() associates with device (1)
a dummy bpf_offload_netdev struct with .offdev field set to NULL.
At step (3) __bpf_prog_dev_bound_init() would reuse dummy struct
allocated at step (2).
However, downstream usage of the bpf_offload_netdev assumes that
.offdev field can't be NULL, e.g. in bpf_prog_offload_verifier_prep().
Adjust __bpf_prog_dev_bound_init() to require bpf_offload_netdev
with non-NULL .offdev for offloaded BPF programs.
Fixes: 2b3486bc2d23 ("bpf: Introduce device-bound XDP programs")
Reported-by: syzbot+291100dcb32190ec02a8@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/bpf/000000000000d97f3c060479c4f8@google.com/
Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
---
kernel/bpf/offload.c | 12 +++++++-----
1 file changed, 7 insertions(+), 5 deletions(-)
diff --git a/kernel/bpf/offload.c b/kernel/bpf/offload.c
index 3e4f2ec1af06..87d6693d8233 100644
--- a/kernel/bpf/offload.c
+++ b/kernel/bpf/offload.c
@@ -199,12 +199,14 @@ static int __bpf_prog_dev_bound_init(struct bpf_prog *prog, struct net_device *n
offload->netdev = netdev;
ondev = bpf_offload_find_netdev(offload->netdev);
+ /* When program is offloaded require presence of "true"
+ * bpf_offload_netdev, avoid the one created for !ondev case below.
+ */
+ if (bpf_prog_is_offloaded(prog->aux) && (!ondev || !ondev->offdev)) {
+ err = -EINVAL;
+ goto err_free;
+ }
if (!ondev) {
- if (bpf_prog_is_offloaded(prog->aux)) {
- err = -EINVAL;
- goto err_free;
- }
-
/* When only binding to the device, explicitly
* create an entry in the hashtable.
*/
--
2.41.0
^ permalink raw reply related [flat|nested] 6+ messages in thread
* [PATCH bpf-next 2/2] selftests/bpf: Offloaded prog after non-offloaded should not cause BUG
2023-09-12 0:55 [PATCH bpf-next 0/2] Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init Eduard Zingerman
2023-09-12 0:55 ` [PATCH bpf-next 1/2] bpf: " Eduard Zingerman
@ 2023-09-12 0:55 ` Eduard Zingerman
2023-09-12 6:26 ` Martin KaFai Lau
2023-09-12 6:30 ` [PATCH bpf-next 0/2] Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init patchwork-bot+netdevbpf
2 siblings, 1 reply; 6+ messages in thread
From: Eduard Zingerman @ 2023-09-12 0:55 UTC (permalink / raw)
To: bpf, ast
Cc: andrii, daniel, martin.lau, kernel-team, yonghong.song, sdf, kuba,
Eduard Zingerman
Check what happens if non-offloaded dev bound BPF
program is followed by offloaded dev bound program.
Test case adapated from syzbot report [1].
[1] https://lore.kernel.org/bpf/000000000000d97f3c060479c4f8@google.com/
Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
---
.../bpf/prog_tests/xdp_dev_bound_only.c | 58 +++++++++++++++++++
1 file changed, 58 insertions(+)
create mode 100644 tools/testing/selftests/bpf/prog_tests/xdp_dev_bound_only.c
diff --git a/tools/testing/selftests/bpf/prog_tests/xdp_dev_bound_only.c b/tools/testing/selftests/bpf/prog_tests/xdp_dev_bound_only.c
new file mode 100644
index 000000000000..5ee4c16d2e21
--- /dev/null
+++ b/tools/testing/selftests/bpf/prog_tests/xdp_dev_bound_only.c
@@ -0,0 +1,58 @@
+// SPDX-License-Identifier: GPL-2.0
+#include <net/if.h>
+#include <test_progs.h>
+#include <network_helpers.h>
+
+#define LOCAL_NETNS "xdp_dev_bound_only_netns"
+
+int load_dummy_prog(char *name, __u32 ifindex, __u32 flags)
+{
+ struct bpf_insn insns[] = { BPF_MOV64_IMM(BPF_REG_0, 0), BPF_EXIT_INSN() };
+ LIBBPF_OPTS(bpf_prog_load_opts, opts);
+
+ opts.prog_flags = flags;
+ opts.prog_ifindex = ifindex;
+ return bpf_prog_load(BPF_PROG_TYPE_XDP, name, "GPL", insns, ARRAY_SIZE(insns), &opts);
+}
+
+/* A test case for bpf_offload_netdev->offload handling bug:
+ * - create a veth device (does not support offload);
+ * - create a device bound XDP program with BPF_F_XDP_DEV_BOUND_ONLY flag
+ * (such programs are not offloaded);
+ * - create a device bound XDP program without flags (such programs are offloaded).
+ * This might lead to 'BUG: kernel NULL pointer dereference'.
+ */
+void test_xdp_dev_bound_only_offdev(void)
+{
+ struct nstoken *tok = NULL;
+ __u32 ifindex;
+ int fd1 = -1;
+ int fd2 = -1;
+
+ SYS(out, "ip netns add " LOCAL_NETNS);
+ tok = open_netns(LOCAL_NETNS);
+ SYS(out, "ip link add eth42 type veth");
+ ifindex = if_nametoindex("eth42");
+ if (!ASSERT_NEQ(ifindex, 0, "if_nametoindex")) {
+ perror("if_nametoindex");
+ goto out;
+ }
+ fd1 = load_dummy_prog("dummy1", ifindex, BPF_F_XDP_DEV_BOUND_ONLY);
+ if (!ASSERT_GE(fd1, 0, "load_dummy_prog #1")) {
+ perror("load_dummy_prog #1");
+ goto out;
+ }
+ /* Program with ifindex is considered offloaded, however veth
+ * does not support offload => error should be reported.
+ */
+ fd2 = load_dummy_prog("dummy2", ifindex, 0);
+ ASSERT_EQ(fd2, -EINVAL, "load_dummy_prog #2 (offloaded)");
+
+out:
+ close(fd1);
+ close(fd2);
+ SYS_NOFAIL("ip link delete eth42");
+ SYS_NOFAIL("ip netns del " LOCAL_NETNS);
+ if (tok)
+ close_netns(tok);
+}
--
2.41.0
^ permalink raw reply related [flat|nested] 6+ messages in thread
* Re: [PATCH bpf-next 2/2] selftests/bpf: Offloaded prog after non-offloaded should not cause BUG
2023-09-12 0:55 ` [PATCH bpf-next 2/2] selftests/bpf: Offloaded prog after non-offloaded should not cause BUG Eduard Zingerman
@ 2023-09-12 6:26 ` Martin KaFai Lau
2023-09-12 9:59 ` Eduard Zingerman
0 siblings, 1 reply; 6+ messages in thread
From: Martin KaFai Lau @ 2023-09-12 6:26 UTC (permalink / raw)
To: Eduard Zingerman
Cc: andrii, daniel, kernel-team, yonghong.song, sdf, kuba, bpf, ast
On 9/11/23 5:55 PM, Eduard Zingerman wrote:
> Check what happens if non-offloaded dev bound BPF
> program is followed by offloaded dev bound program.
> Test case adapated from syzbot report [1].
>
> [1] https://lore.kernel.org/bpf/000000000000d97f3c060479c4f8@google.com/
>
> Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
> ---
> .../bpf/prog_tests/xdp_dev_bound_only.c | 58 +++++++++++++++++++
> 1 file changed, 58 insertions(+)
> create mode 100644 tools/testing/selftests/bpf/prog_tests/xdp_dev_bound_only.c
>
> diff --git a/tools/testing/selftests/bpf/prog_tests/xdp_dev_bound_only.c b/tools/testing/selftests/bpf/prog_tests/xdp_dev_bound_only.c
> new file mode 100644
> index 000000000000..5ee4c16d2e21
> --- /dev/null
> +++ b/tools/testing/selftests/bpf/prog_tests/xdp_dev_bound_only.c
> @@ -0,0 +1,58 @@
> +// SPDX-License-Identifier: GPL-2.0
> +#include <net/if.h>
> +#include <test_progs.h>
> +#include <network_helpers.h>
> +
> +#define LOCAL_NETNS "xdp_dev_bound_only_netns"
> +
> +int load_dummy_prog(char *name, __u32 ifindex, __u32 flags)
I added static.
> +{
> + struct bpf_insn insns[] = { BPF_MOV64_IMM(BPF_REG_0, 0), BPF_EXIT_INSN() };
> + LIBBPF_OPTS(bpf_prog_load_opts, opts);
> +
> + opts.prog_flags = flags;
> + opts.prog_ifindex = ifindex;
> + return bpf_prog_load(BPF_PROG_TYPE_XDP, name, "GPL", insns, ARRAY_SIZE(insns), &opts);
> +}
> +
> +/* A test case for bpf_offload_netdev->offload handling bug:
> + * - create a veth device (does not support offload);
> + * - create a device bound XDP program with BPF_F_XDP_DEV_BOUND_ONLY flag
> + * (such programs are not offloaded);
> + * - create a device bound XDP program without flags (such programs are offloaded).
> + * This might lead to 'BUG: kernel NULL pointer dereference'.
> + */
> +void test_xdp_dev_bound_only_offdev(void)
> +{
> + struct nstoken *tok = NULL;
> + __u32 ifindex;
> + int fd1 = -1;
> + int fd2 = -1;
> +
> + SYS(out, "ip netns add " LOCAL_NETNS);
> + tok = open_netns(LOCAL_NETNS);
Also added NULL check for tok.
> + SYS(out, "ip link add eth42 type veth");
> + ifindex = if_nametoindex("eth42");
> + if (!ASSERT_NEQ(ifindex, 0, "if_nametoindex")) {
> + perror("if_nametoindex");
> + goto out;
> + }
> + fd1 = load_dummy_prog("dummy1", ifindex, BPF_F_XDP_DEV_BOUND_ONLY);
> + if (!ASSERT_GE(fd1, 0, "load_dummy_prog #1")) {
> + perror("load_dummy_prog #1");
> + goto out;
> + }
> + /* Program with ifindex is considered offloaded, however veth
> + * does not support offload => error should be reported.
> + */
> + fd2 = load_dummy_prog("dummy2", ifindex, 0);
> + ASSERT_EQ(fd2, -EINVAL, "load_dummy_prog #2 (offloaded)");
> +
> +out:
> + close(fd1);
> + close(fd2);
> + SYS_NOFAIL("ip link delete eth42");
> + SYS_NOFAIL("ip netns del " LOCAL_NETNS);
> + if (tok)
close_netns() can handle NULL, so removed this tok check.
Applied. Thanks for the fix and test!
> + close_netns(tok);
> +}
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH bpf-next 0/2] Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init
2023-09-12 0:55 [PATCH bpf-next 0/2] Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init Eduard Zingerman
2023-09-12 0:55 ` [PATCH bpf-next 1/2] bpf: " Eduard Zingerman
2023-09-12 0:55 ` [PATCH bpf-next 2/2] selftests/bpf: Offloaded prog after non-offloaded should not cause BUG Eduard Zingerman
@ 2023-09-12 6:30 ` patchwork-bot+netdevbpf
2 siblings, 0 replies; 6+ messages in thread
From: patchwork-bot+netdevbpf @ 2023-09-12 6:30 UTC (permalink / raw)
To: Eduard Zingerman
Cc: bpf, ast, andrii, daniel, martin.lau, kernel-team, yonghong.song,
sdf, kuba
Hello:
This series was applied to bpf/bpf.git (master)
by Martin KaFai Lau <martin.lau@kernel.org>:
On Tue, 12 Sep 2023 03:55:36 +0300 you wrote:
> For a device bound BPF program with flag BPF_F_XDP_DEV_BOUND_ONLY,
> in case if device does not support offload, __bpf_prog_dev_bound_init()
> creates a dummy bpf_offload_netdev struct with .offdev field set to NULL.
>
> This dummy struct might be reused for programs without this flag
> bound to the same device. However, bpf_prog_offload_verifier_prep()
> that uses bpf_offload_netdev assumes that .offdev field cannot be NULL.
>
> [...]
Here is the summary with links:
- [bpf-next,1/2] bpf: Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init
https://git.kernel.org/bpf/bpf/c/1a49f4195d34
- [bpf-next,2/2] selftests/bpf: Offloaded prog after non-offloaded should not cause BUG
https://git.kernel.org/bpf/bpf/c/e4c31164737e
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH bpf-next 2/2] selftests/bpf: Offloaded prog after non-offloaded should not cause BUG
2023-09-12 6:26 ` Martin KaFai Lau
@ 2023-09-12 9:59 ` Eduard Zingerman
0 siblings, 0 replies; 6+ messages in thread
From: Eduard Zingerman @ 2023-09-12 9:59 UTC (permalink / raw)
To: Martin KaFai Lau
Cc: andrii, daniel, kernel-team, yonghong.song, sdf, kuba, bpf, ast
On Mon, 2023-09-11 at 23:26 -0700, Martin KaFai Lau wrote:
> On 9/11/23 5:55 PM, Eduard Zingerman wrote:
[...]
> > +int load_dummy_prog(char *name, __u32 ifindex, __u32 flags)
>
> I added static.
[...]
> > + tok = open_netns(LOCAL_NETNS);
>
> Also added NULL check for tok.
[...]
> > + if (tok)
>
> close_netns() can handle NULL, so removed this tok check.
>
> Applied. Thanks for the fix and test!
Sorry, I should have noticed these issues before sending.
Thank you for fixing it up.
^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2023-09-12 9:59 UTC | newest]
Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2023-09-12 0:55 [PATCH bpf-next 0/2] Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init Eduard Zingerman
2023-09-12 0:55 ` [PATCH bpf-next 1/2] bpf: " Eduard Zingerman
2023-09-12 0:55 ` [PATCH bpf-next 2/2] selftests/bpf: Offloaded prog after non-offloaded should not cause BUG Eduard Zingerman
2023-09-12 6:26 ` Martin KaFai Lau
2023-09-12 9:59 ` Eduard Zingerman
2023-09-12 6:30 ` [PATCH bpf-next 0/2] Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init patchwork-bot+netdevbpf
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox