From: Kumar Kartikeya Dwivedi <memxor@gmail.com>
To: bpf@vger.kernel.org
Cc: Alexei Starovoitov <ast@kernel.org>,
Andrii Nakryiko <andrii@kernel.org>,
Daniel Borkmann <daniel@iogearbox.net>,
Eduard Zingerman <eddyz87@gmail.com>,
Emil Tsalapatis <emil@etsalapatis.com>,
kkd@meta.com, kernel-team@meta.com
Subject: [PATCH bpf-next v1 2/3] bpf: Check fastcall contract of the frame a stack read targets
Date: Wed, 23 Sep 2026 10:41:57 +0200 [thread overview]
Message-ID: <20260923084201.2437625-3-memxor@gmail.com> (raw)
In-Reply-To: <20260923084201.2437625-1-memxor@gmail.com>
check_stack_read_fixed_off() applies the fastcall contract check to the
current frame, even when the pointer targets a caller's stack. A callee
can therefore read a caller's fastcall spill slot without disabling the
caller's rewrite:
caller:
r1 = 1;
*(u64 *)(r10 - 8) = r1;
call bpf_get_smp_processor_id;
r1 = *(u64 *)(r10 - 8);
r1 = r10;
r1 += -8;
call callee;
callee:
r0 = *(u64 *)(r1 + 0);
The caller's spill and fill are removed and its stack depth drops to 0,
but the verifier still tracks the slot as holding the spilled constant.
The callee's load then reads kernel stack outside the caller's frame,
while the verifier assumes r0 is 1.
Check the contract of reg_state, the frame that owns the slot, as the
stack write paths already do.
Fixes: 5b5f51bff1b6 ("bpf: no_caller_saved_registers attribute for helper calls")
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
---
kernel/bpf/verifier.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
index 1d9defa231d1..b38c4c7562db 100644
--- a/kernel/bpf/verifier.c
+++ b/kernel/bpf/verifier.c
@@ -3951,7 +3951,7 @@ static int check_stack_read_fixed_off(struct bpf_verifier_env *env,
reg = ®_state->stack[spi].spilled_ptr;
mark_stack_slot_scratched(env, spi);
- check_fastcall_stack_contract(env, state, env->insn_idx, off);
+ check_fastcall_stack_contract(env, reg_state, env->insn_idx, off);
/*
* Refine the in-progress load record's origin to the source stack slot.
--
2.53.0
next prev parent reply other threads:[~2026-09-23 8:42 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-23 8:41 [PATCH bpf-next v1 0/3] Fix fastcall rewrite with indirect stack accesses Kumar Kartikeya Dwivedi
2026-09-23 8:41 ` [PATCH bpf-next v1 1/3] bpf: Check fastcall contract for helper and kfunc stack buffers Kumar Kartikeya Dwivedi
2026-09-24 5:55 ` Alexei Starovoitov
2026-09-23 8:41 ` Kumar Kartikeya Dwivedi [this message]
2026-09-23 8:41 ` [PATCH bpf-next v1 3/3] selftests/bpf: Test fastcall rewrite with indirect stack accesses Kumar Kartikeya Dwivedi
2026-09-23 9:33 ` bot+bpf-ci
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260923084201.2437625-3-memxor@gmail.com \
--to=memxor@gmail.com \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=eddyz87@gmail.com \
--cc=emil@etsalapatis.com \
--cc=kernel-team@meta.com \
--cc=kkd@meta.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox