From: Emil Tsalapatis <emil@etsalapatis.com>
To: bpf@vger.kernel.org
Cc: ast@kernel.org, andrii@kernel.org, eddyz87@gmail.com,
memxor@gmail.com, daniel@iogearbox.net, netdev@vger.kernel.org,
Emil Tsalapatis <emil@etsalapatis.com>,
Nicholas Carlini <nicholas@carlini.com>
Subject: [PATCH bpf 03/11] bpf: Fix bpf_sock context code generation
Date: Wed, 16 Sep 2026 05:08:21 +0000 [thread overview]
Message-ID: <20260916050830.8774-4-emil@etsalapatis.com> (raw)
In-Reply-To: <20260916050830.8774-1-emil@etsalapatis.com>
Currently, the ctx access code reads the rx_queue_mapping
field with either a 4-byte or 2-byte load. The rest of the bits
in the register are marked known zero by the verifier. However,
the emitted ctx access code places in the register on certain
the special value (-1) using BPF_MOV_IMM64, which gets sign-extended
to turn on all the bits in the register. By shifting this value right,
the program ends up with a value at runtime above what the verifier
assumes is possible.
Fix this by ensuring the read value is as wide as the assumed size.
Use MOV32 instructions instead of MOV64 instructions to keep
the upper bits zero as assumed by the verifier. Also properly report
the size of the destination variable (the bpf_sock field, 4 bytes) instead
of the source (the socket field, 2 bytes).
Fixes: c3c16f2ea6d2 ("bpf: Add rx_queue_mapping to bpf_sock")
Reported-by: Nicholas Carlini <nicholas@carlini.com>
Suggested-by: Nicholas Carlini <nicholas@carlini.com>
Signed-off-by: Emil Tsalapatis <emil@etsalapatis.com>
---
net/core/filter.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
diff --git a/net/core/filter.c b/net/core/filter.c
index 61940e753..5d1705508 100644
--- a/net/core/filter.c
+++ b/net/core/filter.c
@@ -10565,11 +10565,12 @@ u32 bpf_sock_convert_ctx_access(enum bpf_access_type type,
target_size));
*insn++ = BPF_JMP_IMM(BPF_JNE, si->dst_reg, NO_QUEUE_MAPPING,
1);
- *insn++ = BPF_MOV64_IMM(si->dst_reg, -1);
+ *insn++ = BPF_MOV32_IMM(si->dst_reg, -1);
#else
- *insn++ = BPF_MOV64_IMM(si->dst_reg, -1);
- *target_size = 2;
+ *insn++ = BPF_MOV32_IMM(si->dst_reg, -1);
#endif
+ *target_size = sizeof_field(struct bpf_sock, rx_queue_mapping);
+
break;
}
--
2.54.0
next prev parent reply other threads:[~2026-09-16 5:08 UTC|newest]
Thread overview: 23+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-16 5:08 [PATCH bpf 00/11] skb/arena bugfixes Emil Tsalapatis
2026-09-16 5:08 ` [PATCH bpf 01/11] bpf: Fix bounds check for skb-backed dynptrs Emil Tsalapatis
2026-09-16 11:52 ` Jiayuan Chen
2026-09-16 23:08 ` Jakub Kicinski
2026-09-16 5:08 ` [PATCH bpf 02/11] selftests/bpf: Test dynptr slices past end of skb Emil Tsalapatis
2026-09-16 5:18 ` sashiko-bot
2026-09-16 5:08 ` Emil Tsalapatis [this message]
2026-09-16 12:21 ` [PATCH bpf 03/11] bpf: Fix bpf_sock context code generation Jiayuan Chen
2026-09-16 5:08 ` [PATCH bpf 04/11] selftests/bpf: Add selftests for rx_queue_mapping context access Emil Tsalapatis
2026-09-16 5:08 ` [PATCH bpf 05/11] bpf: Reject pkt arguments in mutating subprogs Emil Tsalapatis
2026-09-16 5:57 ` Amery Hung
2026-09-16 5:58 ` Amery Hung
2026-09-16 18:41 ` Emil Tsalapatis
2026-09-16 19:26 ` Amery Hung
2026-09-16 5:08 ` [PATCH bpf 06/11] selftests/bpf: Test rejection of pkt args to " Emil Tsalapatis
2026-09-16 5:08 ` [PATCH bpf 07/11] bpf: Prevent variable arena/non-arena register contents Emil Tsalapatis
2026-09-16 5:08 ` [PATCH bpf 08/11] selftests/bpf: Test for mixed arena/nonarena code paths Emil Tsalapatis
2026-09-16 5:17 ` sashiko-bot
2026-09-16 5:08 ` [PATCH bpf 09/11] bpf: Track whether dynptr type is known Emil Tsalapatis
2026-09-16 5:22 ` sashiko-bot
2026-09-16 18:41 ` Emil Tsalapatis
2026-09-16 5:08 ` [PATCH bpf 10/11] bpf: Track skb memory invalidation by packet-backed dynptrs Emil Tsalapatis
2026-09-16 5:08 ` [PATCH bpf 11/11] selftests/bpf: Test dynptr slice invalidation on skb clobber Emil Tsalapatis
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260916050830.8774-4-emil@etsalapatis.com \
--to=emil@etsalapatis.com \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=eddyz87@gmail.com \
--cc=memxor@gmail.com \
--cc=netdev@vger.kernel.org \
--cc=nicholas@carlini.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox