BPF List
 help / color / mirror / Atom feed
* [PATCH bpf-next v3 0/3] Check cfi_stubs before registering a struct_ops type.
@ 2024-02-16 19:34 thinker.li
  2024-02-16 19:34 ` [PATCH bpf-next v3 1/3] x86/cfi,bpf: Add a stub function for get_info of struct tcp_congestion_ops thinker.li
                   ` (2 more replies)
  0 siblings, 3 replies; 6+ messages in thread
From: thinker.li @ 2024-02-16 19:34 UTC (permalink / raw)
  To: bpf, ast, martin.lau, song, kernel-team, andrii
  Cc: sinquersw, kuifeng, Kui-Feng Lee

From: Kui-Feng Lee <thinker.li@gmail.com>

Recently, cfi_stubs were introduced. However, existing struct_ops
types that are not in the upstream may not be aware of this, resulting
in kernel crashes. By rejecting struct_ops types that do not provide
cfi_stubs properly during registration, these crashes can be avoided.

---
Changes from v2:

 - Add a stub function for get_info of struct tcp_congestion_ops.

Changes from v1:

 - Check *(void **)(cfi_stubs + moff) to make sure stub functions are
   provided for every operator.

 - Add a test case to ensure that struct_ops rejects incomplete
   cfi_stub.

v2: https://lore.kernel.org/all/20240216020350.2061373-1-thinker.li@gmail.com/
v1: https://lore.kernel.org/all/20240215022401.1882010-1-thinker.li@gmail.com/

Kui-Feng Lee (3):
  x86/cfi,bpf: Add a stub function for get_info of struct
    tcp_congestion_ops.
  bpf: Check cfi_stubs before registering a struct_ops type.
  selftests/bpf: Test case for lacking CFI stub functions.

 kernel/bpf/bpf_struct_ops.c                   | 14 +++
 net/ipv4/bpf_tcp_ca.c                         |  7 ++
 tools/testing/selftests/bpf/Makefile          | 10 +-
 .../selftests/bpf/bpf_test_no_cfi/Makefile    | 19 ++++
 .../bpf/bpf_test_no_cfi/bpf_test_no_cfi.c     | 93 +++++++++++++++++++
 .../bpf/prog_tests/test_struct_ops_no_cfi.c   | 31 +++++++
 tools/testing/selftests/bpf/testing_helpers.c |  4 +-
 tools/testing/selftests/bpf/testing_helpers.h |  2 +
 8 files changed, 177 insertions(+), 3 deletions(-)
 create mode 100644 tools/testing/selftests/bpf/bpf_test_no_cfi/Makefile
 create mode 100644 tools/testing/selftests/bpf/bpf_test_no_cfi/bpf_test_no_cfi.c
 create mode 100644 tools/testing/selftests/bpf/prog_tests/test_struct_ops_no_cfi.c

-- 
2.34.1


^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2024-02-20 22:26 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2024-02-16 19:34 [PATCH bpf-next v3 0/3] Check cfi_stubs before registering a struct_ops type thinker.li
2024-02-16 19:34 ` [PATCH bpf-next v3 1/3] x86/cfi,bpf: Add a stub function for get_info of struct tcp_congestion_ops thinker.li
2024-02-20 17:38   ` Alexei Starovoitov
2024-02-20 22:26     ` Kui-Feng Lee
2024-02-16 19:34 ` [PATCH bpf-next v3 2/3] bpf: Check cfi_stubs before registering a struct_ops type thinker.li
2024-02-16 19:34 ` [PATCH bpf-next v3 3/3] selftests/bpf: Test case for lacking CFI stub functions thinker.li

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox