diff --git a/include/linux/filter.h b/include/linux/filter.h index a7000864bb4d..4413655c0f33 100644 --- a/include/linux/filter.h +++ b/include/linux/filter.h @@ -535,13 +535,15 @@ struct sock_fprog_kern { #define BPF_BINARY_HEADER_MAGIC 0x05de0e82 +/* Some arches need doubleword alignment for their instructions and/or data */ +#define BPF_IMAGE_ALIGNMENT 8 + struct bpf_binary_header { #ifdef CONFIG_CFI_CLANG u32 magic; #endif u32 pages; - /* Some arches need word alignment for their instructions */ - u8 image[] __aligned(4); + u8 image[] __aligned(BPF_IMAGE_ALIGNMENT); }; struct bpf_prog { diff --git a/kernel/bpf/core.c b/kernel/bpf/core.c index e29da1e92d79..f59ca4404237 100644 --- a/kernel/bpf/core.c +++ b/kernel/bpf/core.c @@ -31,6 +31,7 @@ #include #include #include +#include #include #include @@ -834,6 +835,9 @@ bpf_jit_binary_alloc(unsigned int proglen, u8 **image_ptr, struct bpf_binary_header *hdr; u32 size, hole, start, pages; + WARN_ON_ONCE(!is_power_of_2(alignment) || + alignment > BPF_IMAGE_ALIGNMENT); + /* Most of BPF filters are really small, but if some of them * fill a page, allow at least 128 extra bytes to insert a * random section of illegal instructions.