The Linux Kernel Mailing List
 help / color / mirror / Atom feed
From: yebin <yebin@huaweicloud.com>
To: Steven Rostedt <rostedt@goodmis.org>
Cc: mhiramat@kernel.org, mathieu.desnoyers@efficios.com,
	mark.rutland@arm.com, linux-trace-kernel@vger.kernel.org,
	linux-kernel@vger.kernel.org, yebin10@huawei.com
Subject: Re: [PATCH 1/2] ftrace: fix UAF when lookup kallsym after ftrace disabled
Date: Mon, 26 May 2025 09:33:37 +0800	[thread overview]
Message-ID: <6833C4F1.3030300@huaweicloud.com> (raw)
In-Reply-To: <20250523135452.626d8dcd@gandalf.local.home>



On 2025/5/24 1:54, Steven Rostedt wrote:
> On Fri, 23 May 2025 16:39:44 +0800
> Ye Bin <yebin@huaweicloud.com> wrote:
>
>> Above issue may happens as follow:
>> (1) Add kprobe trace point;
>> (2) insmod test.ko;
>> (3) Trigger ftrace disabled;
>
> This is the bug. How was ftrace_disabled triggered? That should never
> happen. Was test.ko buggy?
>
Yes. The following warning is reported during concurrent registration 
between register_kprobe() and live patch, causing ftrace_disabled.

WARNING: CPU: 56 PID: 2769 at kernel/trace/ftrace.c:2612 
ftrace_modify_all_code+0x116/0x140
>> (4) rmmod test.ko;
>> (5) cat /proc/kallsyms; --> Will trigger UAF as test.ko already removed;
>> ftrace_mod_get_kallsym()
>> ...
>> strscpy(module_name, mod_map->mod->name, MODULE_NAME_LEN);
>> ...
>>
>> As ftrace_release_mod() judge 'ftrace_disabled' is true will return, and
>> 'mod_map' will remaining in ftrace_mod_maps. 'mod_map' has no chance to
>> release. Therefore, this also causes residual resources to accumulate.
>> To solve above issue, unconditionally clean up'mod_map'.
>>
>> Fixes: aba4b5c22cba ("ftrace: Save module init functions kallsyms symbols for tracing")
>
> This is *not* a fix. ftrace_disabled gets set when a bug is triggered. If
> this prevents ftrace_disabled from getting set, then it would be a fix. But
> if something else happens when ftrace_disabled is set, it just fixes a
> symptom and not the bug itself.
>
There are multiple causes for triggering ftrace_disabled. I agree that 
aba4b5c22cba is not faulty. However, the incorporation of this patch 
will cause problems due to triggering ftrace_disabled. The generation of 
ftrace_disabled is beyond our control. This is related to the user. What 
we can do is even if there are no additional derivative problems.
>
>> Signed-off-by: Ye Bin <yebin10@huawei.com>
>> ---
>>   kernel/trace/ftrace.c | 3 ---
>>   1 file changed, 3 deletions(-)
>>
>> diff --git a/kernel/trace/ftrace.c b/kernel/trace/ftrace.c
>> index a3d4dfad0cbc..ff5d9d73a4a7 100644
>> --- a/kernel/trace/ftrace.c
>> +++ b/kernel/trace/ftrace.c
>> @@ -7438,9 +7438,6 @@ void ftrace_release_mod(struct module *mod)
>>
>>   	mutex_lock(&ftrace_lock);
>>
>> -	if (ftrace_disabled)
>> -		goto out_unlock;
>> -
>
> Here you delete the check, and the next patch you have:
>
> +	if (ftrace_disabled || (mod && !mod->num_ftrace_callsites)) {
> +		mutex_unlock(&ftrace_lock);
> +		return;
> +	}
> +
>
The second patch I added judgment when initializing 'mod_map' in 
ftrace_free_mem(). The first patch removes the judgment when 
ftrace_release_mod() releases'mod_map'. The logic modified by the two 
patches is isolated.
> Why the two patches where the second patch just adds back the check and
> then adds some more stuff around it. This should be a single patch.
>
> Also, why not just keep the goto unlock, that has:
>
The ftrace_free_mem() function itself looks a little strange. It is easy 
to misunderstand that it is a release function, but it is actually an 
initialization function. My two patches did not modify the same function.
>   out_unlock:
> 	mutex_unlock(&ftrace_lock);
>
> 	/* Need to synchronize with ftrace_location_range() */
> 	if (tmp_page)
> 		synchronize_rcu();
> 	for (pg = tmp_page; pg; pg = tmp_page) {
>
> 		/* Needs to be called outside of ftrace_lock */
> 		clear_mod_from_hashes(pg);
>
> 		if (pg->records) {
> 			free_pages((unsigned long)pg->records, pg->order);
> 			ftrace_number_of_pages -= 1 << pg->order;
> 		}
> 		tmp_page = pg->next;
> 		kfree(pg);
> 		ftrace_number_of_groups--;
> 	}
> }
>
> And tmp_page is set to NULL before that jump, so the if and for loop will
> both be nops.
>
> Why all this extra churn?
>
> -- Steve
>
>
>>   	list_for_each_entry_safe(mod_map, n, &ftrace_mod_maps, list) {
>>   		if (mod_map->mod == mod) {
>>   			list_del_rcu(&mod_map->list);
>


  reply	other threads:[~2025-05-26  1:33 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-05-23  8:39 [PATCH 0/2] fix UAF when lookup kallsym after ftrace disabled Ye Bin
2025-05-23  8:39 ` [PATCH 1/2] ftrace: " Ye Bin
2025-05-23 17:54   ` Steven Rostedt
2025-05-26  1:33     ` yebin [this message]
2025-05-27 13:41       ` Steven Rostedt
2025-05-28 13:22         ` yebin
2025-05-28 14:13           ` Steven Rostedt
2025-05-23  8:39 ` [PATCH 2/2] ftrace: don't allocate ftrace module map Ye Bin
2025-05-24  1:13   ` kernel test robot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=6833C4F1.3030300@huaweicloud.com \
    --to=yebin@huaweicloud.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-trace-kernel@vger.kernel.org \
    --cc=mark.rutland@arm.com \
    --cc=mathieu.desnoyers@efficios.com \
    --cc=mhiramat@kernel.org \
    --cc=rostedt@goodmis.org \
    --cc=yebin10@huawei.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox