BPF List
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Alexei Starovoitov" <alexei.starovoitov@gmail.com>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf-next 09/14] bpf: Allow a variable in DATASEC that is smaller than its type
Date: Wed, 30 Sep 2026 19:47:35 +0000	[thread overview]
Message-ID: <20260930194736.3830F1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260930193127.2181684-10-alexei.starovoitov@gmail.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] bpftool/perf: out-of-bounds heap read when dumping DATASEC variables
--

commit 1b453d08464afcede36a667c89c48e99ef1d651d
Author: Alexei Starovoitov <ast@kernel.org>

bpf: Allow a variable in DATASEC that is smaller than its type
    
LLVM splits a static of a Rust program into pieces. Every piece is a VAR
with the type of the whole static:
    
  [223] STRUCT 'BpfCell<core::option::Option<...>>' size=32 vlen=1
  [236] VAR '..scx_cosmos9TASK_CTXS.0' type_id=223, linkage=static
  [248] DATASEC '.bss' size=0 vlen=9
          type_id=236 offset=24648 size=1 (VAR '..TASK_CTXS.0')
    
and the kernel rejects such BTF with "Invalid size". Allow it.

> diff --git a/kernel/bpf/btf.c b/kernel/bpf/btf.c
> index c9d4b709380c9..0630675377aaa 100644
> --- a/kernel/bpf/btf.c
> +++ b/kernel/bpf/btf.c
[ ... ]
> @@ -5412,16 +5412,16 @@ static int btf_datasec_resolve(struct btf_verifier_env *env,
>  			return env_stack_push(env, var_type, var_type_id);
>  		}
>  
> +		/*
> +		 * The variable can be smaller than its type. It's a piece of
> +		 * a variable that the compiler split then, with the type of
> +		 * the whole variable.
> +		 */
>  		type_id = var_type->type;
> -		if (!btf_type_id_size(btf, &type_id, &type_size)) {
> +		if (!btf_type_id_size(btf, &type_id, NULL)) {
>  			btf_verifier_log_vsi(env, v->t, vsi, "Invalid type");
>  			return -EINVAL;
>  		}
> -
> -		if (vsi->size < type_size) {
> -			btf_verifier_log_vsi(env, v->t, vsi, "Invalid size");
> -			return -EINVAL;
> -		}

[Severity: Medium]
Does removing this validation expose userspace tools to out-of-bounds heap
reads?

By allowing vsi->size < type_size, a DATASEC variable piece's offset plus its
full type size can now exceed the DATASEC's total size.

When bpftool dumps a DATASEC:

tools/bpf/bpftool/btf_dumper.c:btf_dumper_datasec() {
    ...
    ret = btf_dumper_do_type(d, vsi[i].type, 0, data + vsi[i].offset);
    ...
}

It unconditionally reads bytes based on the variable's full type size. Since
the piece is smaller than its type, this reads past the end of the allocated
map value buffer.

Similarly, perf passes the full type size as the bounding data_sz to libbpf:

tools/perf/util/bpf-event.c:format_btf_variable() {
    ...
    btf_size = btf__resolve_size(btf, t->type);
    btf_dump__dump_type_data(d, t->type, btf_data, btf_size, &opts);
    ...
}

This incorrectly bypasses libbpf's internal bounds checks, causing libbpf
to read out-of-bounds from map->rodata.

>  	}
>  
>  	env_stack_pop_resolved(env, 0, 0);

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260930193127.2181684-1-alexei.starovoitov@gmail.com?part=9

  reply	other threads:[~2026-09-30 19:47 UTC|newest]

Thread overview: 31+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-30 19:31 [PATCH bpf-next 00/14] bpf: Support programs compiled by rust-bpf Alexei Starovoitov
2026-09-30 19:31 ` [PATCH bpf-next 01/14] bpf: Allow bitwise ops, shifts and mul/div on pointers with CAP_PERFMON Alexei Starovoitov
2026-09-30 19:31 ` [PATCH bpf-next 02/14] selftests/bpf: Add tests for ALU " Alexei Starovoitov
2026-09-30 19:31 ` [PATCH bpf-next 03/14] bpf: Treat load and store through a number as arena access Alexei Starovoitov
2026-09-30 19:31 ` [PATCH bpf-next 04/14] selftests/bpf: Add tests for arena access through numbers Alexei Starovoitov
2026-09-30 19:48   ` sashiko-bot
2026-09-30 20:22   ` bot+bpf-ci
2026-09-30 19:31 ` [PATCH bpf-next 05/14] bpf: Allow names of Rust types and functions in BTF Alexei Starovoitov
2026-09-30 20:22   ` bot+bpf-ci
2026-10-01 17:42   ` Alan Maguire
2026-10-02 12:24     ` Alexei Starovoitov
2026-10-02 13:38       ` Alan Maguire
2026-09-30 19:31 ` [PATCH bpf-next 06/14] selftests/bpf: Add tests for " Alexei Starovoitov
2026-09-30 20:22   ` bot+bpf-ci
2026-09-30 19:31 ` [PATCH bpf-next 07/14] bpf: Allow arguments without names in static " Alexei Starovoitov
2026-10-01 21:14   ` Alan Maguire
2026-09-30 19:31 ` [PATCH bpf-next 08/14] selftests/bpf: Add test for arguments without names in static functions Alexei Starovoitov
2026-10-01 21:22   ` Alan Maguire
2026-09-30 19:31 ` [PATCH bpf-next 09/14] bpf: Allow a variable in DATASEC that is smaller than its type Alexei Starovoitov
2026-09-30 19:47   ` sashiko-bot [this message]
2026-09-30 19:31 ` [PATCH bpf-next 10/14] selftests/bpf: Add tests for a variable " Alexei Starovoitov
2026-09-30 19:31 ` [PATCH bpf-next 11/14] libbpf: Keep global data in arena when the object has .arena.data Alexei Starovoitov
2026-09-30 19:46   ` sashiko-bot
2026-09-30 20:22   ` bot+bpf-ci
2026-09-30 19:31 ` [PATCH bpf-next 12/14] libbpf: Keep format strings of bpf_printk() in .rodata.str Alexei Starovoitov
2026-09-30 20:22   ` bot+bpf-ci
2026-09-30 19:31 ` [PATCH bpf-next 13/14] selftests/bpf: Add test for global data in arena Alexei Starovoitov
2026-09-30 20:22   ` bot+bpf-ci
2026-09-30 19:31 ` [PATCH bpf-next 14/14] selftests/bpf: Add test for global data of a program in Rust Alexei Starovoitov
2026-09-30 19:53   ` sashiko-bot
2026-09-30 20:22   ` bot+bpf-ci

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260930194736.3830F1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=alexei.starovoitov@gmail.com \
    --cc=bpf@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox