public inbox for bpf@vger.kernel.org
 help / color / mirror / Atom feed
* [PATCH bpf-next 0/2] Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init
@ 2023-09-12  0:55 Eduard Zingerman
  2023-09-12  0:55 ` [PATCH bpf-next 1/2] bpf: " Eduard Zingerman
                   ` (2 more replies)
  0 siblings, 3 replies; 6+ messages in thread
From: Eduard Zingerman @ 2023-09-12  0:55 UTC (permalink / raw)
  To: bpf, ast
  Cc: andrii, daniel, martin.lau, kernel-team, yonghong.song, sdf, kuba,
	Eduard Zingerman

For a device bound BPF program with flag BPF_F_XDP_DEV_BOUND_ONLY,
in case if device does not support offload, __bpf_prog_dev_bound_init()
creates a dummy bpf_offload_netdev struct with .offdev field set to NULL.

This dummy struct might be reused for programs without this flag
bound to the same device. However, bpf_prog_offload_verifier_prep()
that uses bpf_offload_netdev assumes that .offdev field cannot be NULL.

This bug was reported by syzbot in [1].

[1] https://lore.kernel.org/bpf/000000000000d97f3c060479c4f8@google.com/

Eduard Zingerman (2):
  bpf: Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init
  selftests/bpf: Offloaded prog after non-offloaded should not cause BUG

 kernel/bpf/offload.c                          | 12 ++--
 .../bpf/prog_tests/xdp_dev_bound_only.c       | 58 +++++++++++++++++++
 2 files changed, 65 insertions(+), 5 deletions(-)
 create mode 100644 tools/testing/selftests/bpf/prog_tests/xdp_dev_bound_only.c

-- 
2.41.0


^ permalink raw reply	[flat|nested] 6+ messages in thread

* [PATCH bpf-next 1/2] bpf: Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init
  2023-09-12  0:55 [PATCH bpf-next 0/2] Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init Eduard Zingerman
@ 2023-09-12  0:55 ` Eduard Zingerman
  2023-09-12  0:55 ` [PATCH bpf-next 2/2] selftests/bpf: Offloaded prog after non-offloaded should not cause BUG Eduard Zingerman
  2023-09-12  6:30 ` [PATCH bpf-next 0/2] Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init patchwork-bot+netdevbpf
  2 siblings, 0 replies; 6+ messages in thread
From: Eduard Zingerman @ 2023-09-12  0:55 UTC (permalink / raw)
  To: bpf, ast
  Cc: andrii, daniel, martin.lau, kernel-team, yonghong.song, sdf, kuba,
	Eduard Zingerman, syzbot+291100dcb32190ec02a8

Fix for a bug observable under the following sequence of events:
1. Create a network device that does not support XDP offload.
2. Load a device bound XDP program with BPF_F_XDP_DEV_BOUND_ONLY flag
   (such programs are not offloaded).
3. Load a device bound XDP program with zero flags
   (such programs are offloaded).

At step (2) __bpf_prog_dev_bound_init() associates with device (1)
a dummy bpf_offload_netdev struct with .offdev field set to NULL.
At step (3) __bpf_prog_dev_bound_init() would reuse dummy struct
allocated at step (2).
However, downstream usage of the bpf_offload_netdev assumes that
.offdev field can't be NULL, e.g. in bpf_prog_offload_verifier_prep().

Adjust __bpf_prog_dev_bound_init() to require bpf_offload_netdev
with non-NULL .offdev for offloaded BPF programs.

Fixes: 2b3486bc2d23 ("bpf: Introduce device-bound XDP programs")
Reported-by: syzbot+291100dcb32190ec02a8@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/bpf/000000000000d97f3c060479c4f8@google.com/
Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
---
 kernel/bpf/offload.c | 12 +++++++-----
 1 file changed, 7 insertions(+), 5 deletions(-)

diff --git a/kernel/bpf/offload.c b/kernel/bpf/offload.c
index 3e4f2ec1af06..87d6693d8233 100644
--- a/kernel/bpf/offload.c
+++ b/kernel/bpf/offload.c
@@ -199,12 +199,14 @@ static int __bpf_prog_dev_bound_init(struct bpf_prog *prog, struct net_device *n
 	offload->netdev = netdev;
 
 	ondev = bpf_offload_find_netdev(offload->netdev);
+	/* When program is offloaded require presence of "true"
+	 * bpf_offload_netdev, avoid the one created for !ondev case below.
+	 */
+	if (bpf_prog_is_offloaded(prog->aux) && (!ondev || !ondev->offdev)) {
+		err = -EINVAL;
+		goto err_free;
+	}
 	if (!ondev) {
-		if (bpf_prog_is_offloaded(prog->aux)) {
-			err = -EINVAL;
-			goto err_free;
-		}
-
 		/* When only binding to the device, explicitly
 		 * create an entry in the hashtable.
 		 */
-- 
2.41.0


^ permalink raw reply related	[flat|nested] 6+ messages in thread

* [PATCH bpf-next 2/2] selftests/bpf: Offloaded prog after non-offloaded should not cause BUG
  2023-09-12  0:55 [PATCH bpf-next 0/2] Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init Eduard Zingerman
  2023-09-12  0:55 ` [PATCH bpf-next 1/2] bpf: " Eduard Zingerman
@ 2023-09-12  0:55 ` Eduard Zingerman
  2023-09-12  6:26   ` Martin KaFai Lau
  2023-09-12  6:30 ` [PATCH bpf-next 0/2] Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init patchwork-bot+netdevbpf
  2 siblings, 1 reply; 6+ messages in thread
From: Eduard Zingerman @ 2023-09-12  0:55 UTC (permalink / raw)
  To: bpf, ast
  Cc: andrii, daniel, martin.lau, kernel-team, yonghong.song, sdf, kuba,
	Eduard Zingerman

Check what happens if non-offloaded dev bound BPF
program is followed by offloaded dev bound program.
Test case adapated from syzbot report [1].

[1] https://lore.kernel.org/bpf/000000000000d97f3c060479c4f8@google.com/

Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
---
 .../bpf/prog_tests/xdp_dev_bound_only.c       | 58 +++++++++++++++++++
 1 file changed, 58 insertions(+)
 create mode 100644 tools/testing/selftests/bpf/prog_tests/xdp_dev_bound_only.c

diff --git a/tools/testing/selftests/bpf/prog_tests/xdp_dev_bound_only.c b/tools/testing/selftests/bpf/prog_tests/xdp_dev_bound_only.c
new file mode 100644
index 000000000000..5ee4c16d2e21
--- /dev/null
+++ b/tools/testing/selftests/bpf/prog_tests/xdp_dev_bound_only.c
@@ -0,0 +1,58 @@
+// SPDX-License-Identifier: GPL-2.0
+#include <net/if.h>
+#include <test_progs.h>
+#include <network_helpers.h>
+
+#define LOCAL_NETNS "xdp_dev_bound_only_netns"
+
+int load_dummy_prog(char *name, __u32 ifindex, __u32 flags)
+{
+	struct bpf_insn insns[] = { BPF_MOV64_IMM(BPF_REG_0, 0), BPF_EXIT_INSN() };
+	LIBBPF_OPTS(bpf_prog_load_opts, opts);
+
+	opts.prog_flags = flags;
+	opts.prog_ifindex = ifindex;
+	return bpf_prog_load(BPF_PROG_TYPE_XDP, name, "GPL", insns, ARRAY_SIZE(insns), &opts);
+}
+
+/* A test case for bpf_offload_netdev->offload handling bug:
+ * - create a veth device (does not support offload);
+ * - create a device bound XDP program with BPF_F_XDP_DEV_BOUND_ONLY flag
+ *   (such programs are not offloaded);
+ * - create a device bound XDP program without flags (such programs are offloaded).
+ * This might lead to 'BUG: kernel NULL pointer dereference'.
+ */
+void test_xdp_dev_bound_only_offdev(void)
+{
+	struct nstoken *tok = NULL;
+	__u32 ifindex;
+	int fd1 = -1;
+	int fd2 = -1;
+
+	SYS(out, "ip netns add " LOCAL_NETNS);
+	tok = open_netns(LOCAL_NETNS);
+	SYS(out, "ip link add eth42 type veth");
+	ifindex = if_nametoindex("eth42");
+	if (!ASSERT_NEQ(ifindex, 0, "if_nametoindex")) {
+		perror("if_nametoindex");
+		goto out;
+	}
+	fd1 = load_dummy_prog("dummy1", ifindex, BPF_F_XDP_DEV_BOUND_ONLY);
+	if (!ASSERT_GE(fd1, 0, "load_dummy_prog #1")) {
+		perror("load_dummy_prog #1");
+		goto out;
+	}
+	/* Program with ifindex is considered offloaded, however veth
+	 * does not support offload => error should be reported.
+	 */
+	fd2 = load_dummy_prog("dummy2", ifindex, 0);
+	ASSERT_EQ(fd2, -EINVAL, "load_dummy_prog #2 (offloaded)");
+
+out:
+	close(fd1);
+	close(fd2);
+	SYS_NOFAIL("ip link delete eth42");
+	SYS_NOFAIL("ip netns del " LOCAL_NETNS);
+	if (tok)
+		close_netns(tok);
+}
-- 
2.41.0


^ permalink raw reply related	[flat|nested] 6+ messages in thread

* Re: [PATCH bpf-next 2/2] selftests/bpf: Offloaded prog after non-offloaded should not cause BUG
  2023-09-12  0:55 ` [PATCH bpf-next 2/2] selftests/bpf: Offloaded prog after non-offloaded should not cause BUG Eduard Zingerman
@ 2023-09-12  6:26   ` Martin KaFai Lau
  2023-09-12  9:59     ` Eduard Zingerman
  0 siblings, 1 reply; 6+ messages in thread
From: Martin KaFai Lau @ 2023-09-12  6:26 UTC (permalink / raw)
  To: Eduard Zingerman
  Cc: andrii, daniel, kernel-team, yonghong.song, sdf, kuba, bpf, ast

On 9/11/23 5:55 PM, Eduard Zingerman wrote:
> Check what happens if non-offloaded dev bound BPF
> program is followed by offloaded dev bound program.
> Test case adapated from syzbot report [1].
> 
> [1] https://lore.kernel.org/bpf/000000000000d97f3c060479c4f8@google.com/
> 
> Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
> ---
>   .../bpf/prog_tests/xdp_dev_bound_only.c       | 58 +++++++++++++++++++
>   1 file changed, 58 insertions(+)
>   create mode 100644 tools/testing/selftests/bpf/prog_tests/xdp_dev_bound_only.c
> 
> diff --git a/tools/testing/selftests/bpf/prog_tests/xdp_dev_bound_only.c b/tools/testing/selftests/bpf/prog_tests/xdp_dev_bound_only.c
> new file mode 100644
> index 000000000000..5ee4c16d2e21
> --- /dev/null
> +++ b/tools/testing/selftests/bpf/prog_tests/xdp_dev_bound_only.c
> @@ -0,0 +1,58 @@
> +// SPDX-License-Identifier: GPL-2.0
> +#include <net/if.h>
> +#include <test_progs.h>
> +#include <network_helpers.h>
> +
> +#define LOCAL_NETNS "xdp_dev_bound_only_netns"
> +
> +int load_dummy_prog(char *name, __u32 ifindex, __u32 flags)

I added static.

> +{
> +	struct bpf_insn insns[] = { BPF_MOV64_IMM(BPF_REG_0, 0), BPF_EXIT_INSN() };
> +	LIBBPF_OPTS(bpf_prog_load_opts, opts);
> +
> +	opts.prog_flags = flags;
> +	opts.prog_ifindex = ifindex;
> +	return bpf_prog_load(BPF_PROG_TYPE_XDP, name, "GPL", insns, ARRAY_SIZE(insns), &opts);
> +}
> +
> +/* A test case for bpf_offload_netdev->offload handling bug:
> + * - create a veth device (does not support offload);
> + * - create a device bound XDP program with BPF_F_XDP_DEV_BOUND_ONLY flag
> + *   (such programs are not offloaded);
> + * - create a device bound XDP program without flags (such programs are offloaded).
> + * This might lead to 'BUG: kernel NULL pointer dereference'.
> + */
> +void test_xdp_dev_bound_only_offdev(void)
> +{
> +	struct nstoken *tok = NULL;
> +	__u32 ifindex;
> +	int fd1 = -1;
> +	int fd2 = -1;
> +
> +	SYS(out, "ip netns add " LOCAL_NETNS);
> +	tok = open_netns(LOCAL_NETNS);

Also added NULL check for tok.

> +	SYS(out, "ip link add eth42 type veth");
> +	ifindex = if_nametoindex("eth42");
> +	if (!ASSERT_NEQ(ifindex, 0, "if_nametoindex")) {
> +		perror("if_nametoindex");
> +		goto out;
> +	}
> +	fd1 = load_dummy_prog("dummy1", ifindex, BPF_F_XDP_DEV_BOUND_ONLY);
> +	if (!ASSERT_GE(fd1, 0, "load_dummy_prog #1")) {
> +		perror("load_dummy_prog #1");
> +		goto out;
> +	}
> +	/* Program with ifindex is considered offloaded, however veth
> +	 * does not support offload => error should be reported.
> +	 */
> +	fd2 = load_dummy_prog("dummy2", ifindex, 0);
> +	ASSERT_EQ(fd2, -EINVAL, "load_dummy_prog #2 (offloaded)");
> +
> +out:
> +	close(fd1);
> +	close(fd2);
> +	SYS_NOFAIL("ip link delete eth42");
> +	SYS_NOFAIL("ip netns del " LOCAL_NETNS);
> +	if (tok)

close_netns() can handle NULL, so removed this tok check.

Applied. Thanks for the fix and test!

> +		close_netns(tok);
> +}


^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [PATCH bpf-next 0/2] Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init
  2023-09-12  0:55 [PATCH bpf-next 0/2] Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init Eduard Zingerman
  2023-09-12  0:55 ` [PATCH bpf-next 1/2] bpf: " Eduard Zingerman
  2023-09-12  0:55 ` [PATCH bpf-next 2/2] selftests/bpf: Offloaded prog after non-offloaded should not cause BUG Eduard Zingerman
@ 2023-09-12  6:30 ` patchwork-bot+netdevbpf
  2 siblings, 0 replies; 6+ messages in thread
From: patchwork-bot+netdevbpf @ 2023-09-12  6:30 UTC (permalink / raw)
  To: Eduard Zingerman
  Cc: bpf, ast, andrii, daniel, martin.lau, kernel-team, yonghong.song,
	sdf, kuba

Hello:

This series was applied to bpf/bpf.git (master)
by Martin KaFai Lau <martin.lau@kernel.org>:

On Tue, 12 Sep 2023 03:55:36 +0300 you wrote:
> For a device bound BPF program with flag BPF_F_XDP_DEV_BOUND_ONLY,
> in case if device does not support offload, __bpf_prog_dev_bound_init()
> creates a dummy bpf_offload_netdev struct with .offdev field set to NULL.
> 
> This dummy struct might be reused for programs without this flag
> bound to the same device. However, bpf_prog_offload_verifier_prep()
> that uses bpf_offload_netdev assumes that .offdev field cannot be NULL.
> 
> [...]

Here is the summary with links:
  - [bpf-next,1/2] bpf: Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init
    https://git.kernel.org/bpf/bpf/c/1a49f4195d34
  - [bpf-next,2/2] selftests/bpf: Offloaded prog after non-offloaded should not cause BUG
    https://git.kernel.org/bpf/bpf/c/e4c31164737e

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html



^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [PATCH bpf-next 2/2] selftests/bpf: Offloaded prog after non-offloaded should not cause BUG
  2023-09-12  6:26   ` Martin KaFai Lau
@ 2023-09-12  9:59     ` Eduard Zingerman
  0 siblings, 0 replies; 6+ messages in thread
From: Eduard Zingerman @ 2023-09-12  9:59 UTC (permalink / raw)
  To: Martin KaFai Lau
  Cc: andrii, daniel, kernel-team, yonghong.song, sdf, kuba, bpf, ast

On Mon, 2023-09-11 at 23:26 -0700, Martin KaFai Lau wrote:
> On 9/11/23 5:55 PM, Eduard Zingerman wrote:
[...]
> > +int load_dummy_prog(char *name, __u32 ifindex, __u32 flags)
> 
> I added static.
 
[...]
> > +	tok = open_netns(LOCAL_NETNS);
> 
> Also added NULL check for tok.

[...]
> > +	if (tok)
> 
> close_netns() can handle NULL, so removed this tok check.
> 
> Applied. Thanks for the fix and test!

Sorry, I should have noticed these issues before sending.
Thank you for fixing it up.

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2023-09-12  9:59 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2023-09-12  0:55 [PATCH bpf-next 0/2] Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init Eduard Zingerman
2023-09-12  0:55 ` [PATCH bpf-next 1/2] bpf: " Eduard Zingerman
2023-09-12  0:55 ` [PATCH bpf-next 2/2] selftests/bpf: Offloaded prog after non-offloaded should not cause BUG Eduard Zingerman
2023-09-12  6:26   ` Martin KaFai Lau
2023-09-12  9:59     ` Eduard Zingerman
2023-09-12  6:30 ` [PATCH bpf-next 0/2] Avoid dummy bpf_offload_netdev in __bpf_prog_dev_bound_init patchwork-bot+netdevbpf

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox