netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH bpf v3 0/2] Fix BPF verifier bypass on scalar spill
@ 2023-06-06 21:42 Maxim Mikityanskiy
  2023-06-06 21:42 ` [PATCH bpf v3 1/2] bpf: Fix verifier tracking scalars on spill Maxim Mikityanskiy
  2023-06-06 21:42 ` [PATCH bpf v3 2/2] selftests/bpf: Add test cases to assert proper ID tracking " Maxim Mikityanskiy
  0 siblings, 2 replies; 7+ messages in thread
From: Maxim Mikityanskiy @ 2023-06-06 21:42 UTC (permalink / raw)
  To: bpf
  Cc: netdev, linux-kselftest, Daniel Borkmann, John Fastabend,
	Alexei Starovoitov, Andrii Nakryiko, Martin KaFai Lau,
	Eduard Zingerman, Maxim Mikityanskiy, Song Liu, Yonghong Song,
	KP Singh, Stanislav Fomichev, Hao Luo, Jiri Olsa, Mykola Lysenko,
	Shuah Khan, David S. Miller, Jakub Kicinski,
	Jesper Dangaard Brouer

From: Maxim Mikityanskiy <maxim@isovalent.com>

See the details in the commit message (TL/DR: under CAP_BPF, the
verifier can be fooled to think that a scalar is zero while in fact it's
your predefined number.)

v1 and v2 were sent off-list.

v2 changes:

Added more tests, migrated them to inline asm, started using
bpf_get_prandom_u32, switched to a more bulletproof dead branch check
and modified the failing spill test scenarios so that an unauthorized
access attempt is performed in both branches.

v3 changes:

Dropped an improvement not necessary for the fix, changed the Fixes tag.

Maxim Mikityanskiy (2):
  bpf: Fix verifier tracking scalars on spill
  selftests/bpf: Add test cases to assert proper ID tracking on spill

 kernel/bpf/verifier.c                         |   7 +
 .../selftests/bpf/progs/verifier_spill_fill.c | 198 ++++++++++++++++++
 2 files changed, 205 insertions(+)

-- 
2.40.1


^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2023-06-07  7:36 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2023-06-06 21:42 [PATCH bpf v3 0/2] Fix BPF verifier bypass on scalar spill Maxim Mikityanskiy
2023-06-06 21:42 ` [PATCH bpf v3 1/2] bpf: Fix verifier tracking scalars on spill Maxim Mikityanskiy
2023-06-07  1:32   ` Yonghong Song
2023-06-07  7:36     ` Maxim Mikityanskiy
2023-06-06 21:42 ` [PATCH bpf v3 2/2] selftests/bpf: Add test cases to assert proper ID tracking " Maxim Mikityanskiy
2023-06-07  1:40   ` Yonghong Song
2023-06-07  1:43   ` Alexei Starovoitov

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).