Commit graph

981,800 commits

Author SHA1 Message Date
Pankaj Gupta
374cf47171
kgsl: Avoid use after free in kgsl_destroy_ion()
When deallocating dma-buf metadata in kgsl_destroy_ion, the priv_data
pointer in the associated kgsl_mem_entry structure is not reset after
kfree(). To avoid use after free, set entry->priv_data to NULL
immediately after freeing metadata.

Change-Id: Ia222d3a88666b7ee406f1508eb37a4eef766c83e
Signed-off-by: Shiv Kumar <shikum@qti.qualcomm.com>
Signed-off-by: Pankaj Gupta <gpankaj@qti.qualcomm.com>
2026-05-05 20:02:21 +03:00
Michael Bestas
1df27edaaf
Revert "wifi: cfg80211: Increase akm_suites array size in"
This reverts commit 525fb1b48f.

Reason for revert: Breaks WiFi, likely needs additional changes to be
backported for it to work properly.

Change-Id: Ifc537c0dc80d759a9ab12671c7ff053ad6c31759
2026-05-05 20:02:19 +03:00
Michael Bestas
77d305881e
Merge tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/video-driver into android13-5.4-lahaina
LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0

* tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/video-driver:
  msm: vidc: Fix use after free in driver
  msm: vidc: Enable hybrid mode only for HFR usecase

Change-Id: Ic2a5c64a04bcd2bed2c853f541255b7563d9b65c
2026-04-30 21:20:07 +03:00
Michael Bestas
3700e67df3
Merge tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/display-drivers into android13-5.4-lahaina
LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0

* tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/display-drivers:
  disp: msm: dsi: Fix potential data race in ctrl isr
  disp: msm: dsi: Fix potential data race in ctrl isr
  disp: msm: dsi: Fix potential data race in ctrl isr
  msm: smmu: Unregister SMMU fault handler before cleanup
  disp: msm: sde: Add change to fix slab out of bounds
  disp: msm: sde: fix splash resource cleanup for edp
  disp: msm: sde: get_modes from connector if not present
  disp: msm: dp: handle panel_init when host is ready
  disp: msm: sde: fix kms NULL pointer access in encoder IRQ control
  disp: msm: dsi: add support for hibernation
  disp: config: fix copyright marking for lahaina config
  disp: config: fix copyright marking for lahaina config
  disp: msm: dsi: fix error path for dsi_display init
  disp: msm: dsi: add null pointer check in dsi_display_dev_remove
  disp: config :disable CONFIG_DSI_PARSER for kodiak
  disp: msm: dp: parse display_type before connector initialization

 Conflicts:
	techpack/display/msm/dsi/dsi_display.c

Change-Id: I5263698636da978ff39d868e2305e3f4699e3ac8
2026-04-30 21:18:34 +03:00
Michael Bestas
be47524e56
Merge tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/dataipa into android13-5.4-lahaina
LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0

* tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/dataipa:
  ipa: Added changes to move the hdr entry to free list
  msm: ipa: Avoid use-after-free scenario

Change-Id: I53d9b6e5cd83948d5a7cd67b8b7ffa58af13efef
2026-04-30 21:15:00 +03:00
Michael Bestas
311bbabf94
Merge tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/camera-kernel into android13-5.4-lahaina
LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0

* tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/camera-kernel:
  msm: camera: sensor: TOCTOU error handling

Change-Id: I831403abf0e0b345a80fbc033bfe1c46ef768bab
2026-04-30 21:14:11 +03:00
Michael Bestas
d2ba8e663f
Merge tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/audio-kernel into android13-5.4-lahaina
LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0

* tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/opensource/audio-kernel:
  asoc: lsm: thread safety issue in hw params management
  asoc: lsm: Race condition protection in confidence levels handling
  asoc: lsm: thread safety issue while accessing substream data
  asoc: compress: race condition handling in stream cmd put function
  asoc: handle heap overflow in effect driver
  asoc: Update dai link for ACM8625S AMP.
  asoc: Modification for 8ch capture
  audio-kernel: Fix wcd938x DMIC unable to record
  audio-kernel: Enable hdmi in audio function for AIO bar
  dsp: q6adm: Checking array sizeof channel_type
  asoc: codec: avoid out of bound write to map array
  dsp: q6lsm: Check size of payload before access

Change-Id: I9eebb44e5b838891dc094853e28535930dee6b83
2026-04-30 21:13:31 +03:00
Michael Bestas
18efc279f6
Merge tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/qcacld-3.0 into android13-5.4-lahaina
LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0

* tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/qcacld-3.0:
  qcacld-3.0: Populate MBSSID cap in Ext CAP IE
  Release 2.0.8.35G
  qcacld-3.0: Fix underflow issue of beacon length
  Release 2.0.8.35F
  qcacld-3.0: don't overwrite psd_power flag if psd_set is true
  qcacld-3.0: Add TPE IE EIRP power support for 6 GHz band
  Release 2.0.8.35E
  qcacld-3.0: Validate bw in lim calculate tpc
  qcacld-3.0: Add Validation for WMA Handle and PSOC in Wake Event
  Release 2.0.8.35D
  qcacld-3.0: Add ini to apply RSSI delta for 6 GHz roam
  Release 2.0.8.35C
  qcacld-3.0: Update PMK from firmware for FT-SAE AKM also
  Release 2.0.8.35B
  qcacld-3.0: Rename variables name chan to chan_freq of wlan_hdd_mgmt_tx
  qcacld-3.0: Fix mgmt tx from supplicant failed on 6 GHz chan
  Release 2.0.8.35A
  qcacld-3.0: Fix potential OOB memory access
  Release 2.0.8.35
  qcacld-3.0: Recalculate TX power post CSA
  qcacld-3.0: Correcting the TSInfo structure size according to the Spec
  qcacld-3.0: Fix the possible OOB write in country IE unpack
  qcacld-3.0: Enhance the RSNXE inter-op logic
  qcacld-3.0: Fix the AKM precedence order for RSN IE
  qcacld-3.0: Update connect request crypto parameters
  qcacld-3.0: Enable CFG80211_MULTI_AKM_CONNECT_SUPPORT from kernelv6.0
  qcacld-3.0: Update wiphy max_num_akms_connect variable

Change-Id: I87412b74b79c527b7c867dd61b062ad38da8aab3
2026-04-30 21:12:43 +03:00
Michael Bestas
a2d66d3891
Merge tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/qca-wifi-host-cmn into android13-5.4-lahaina
LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0

* tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/qca-wifi-host-cmn:
  qcacmn: Validate vdev count before pdev CSA switch count update
  qcacmn: Fix out of bounds read in extract_roam_scan_ap_stats_tlv
  qcacmn: Update is_psd_power logic in reg get client pwr API
  qcacmn: Keep counter atomicity while logging
  qcacmn: Avoid OOB read in reg fill master channel API
  qcacmn: Add macro to determine WPA3 AKM
  qcacmn: Correct RSNXE capability indexes

Change-Id: I99ee7720aa22bc6dcfe52505d883498d767c7f09
2026-04-30 21:11:29 +03:00
Michael Bestas
031cd7d112
Merge tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/fw-api into android13-5.4-lahaina
LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0

* tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/platform/vendor/qcom-opensource/wlan/fw-api:
  fw-api: CL 29789367 - update fw common interface files
  fw-api: CL 29778978 - update fw common interface files
  fw-api: CL 29754585 - update fw common interface files
  fw-api: CL 29754552 - update fw common interface files
  fw-api: CL 29734524 - update fw common interface files
  fw-api: CL 29712800 - update fw common interface files
  fw-api: CL 29678196 - update fw common interface files
  fw-api: CL 29659315 - update fw common interface files
  fw-api: CL 29622365 - update fw common interface files
  fw-api: CL 29596437 - update fw common interface files
  fw-api: CL 29574189 - update fw common interface files
  fw-api: CL 29563157 - update fw common interface files
  fw-api: CL 29563125 - update fw common interface files
  fw-api: CL 29527156 - update fw common interface files
  fw-api: CL 29499792 - update fw common interface files
  fw-api: CL 29498712 - update fw common interface files
  fw-api: CL 29497269 - update fw common interface files
  fw-api: CL 29496038 - update fw common interface files
  fw-api: CL 29495802 - update fw common interface files
  fw-api: CL 29472287 - update fw common interface files
  fw-api: CL 29472280 - update fw common interface files
  fw-api: CL 29472274 - update fw common interface files
  fw-api: CL 29449928 - update fw common interface files
  fw-api: CL 29449355 - update fw common interface files
  fw-api: CL 29412107 - update fw common interface files
  fw-api: CL 29384929 - update fw common interface files
  fw-api: CL 29372661 - update fw common interface files
  fw-api: CL 29372366 - update fw common interface files
  fw-api: CL 29370374 - update fw common interface files
  fw-api: CL 29370368 - update fw common interface files
  fw-api: CL 29347560 - update fw common interface files
  fw-api: CL 29346866 - update fw common interface files
  fw-api: CL 29346863 - update fw common interface files
  qca-cmn-fw : Add extra parameter in existing rate_upper_cap command
  fw-api: CL 29312190 - update fw common interface files
  fw-api: CL 29310832 - update fw common interface files
  fw-api: CL 29310378 - update fw common interface files
  fw-api: CL 29309854 - update fw common interface files
  fw-api: CL 29309837 - update fw common interface files
  fw-api: CL 29289452 - update fw common interface files
  fw-api: CL 29289444 - update fw common interface files
  fw-api: CL 29280684 - update fw common interface files
  fw-api: CL 29279982 - update fw common interface files
  fw-api: CL 29254060 - update fw common interface files
  fw-api: CL 29230158 - update fw common interface files
  fw-api: CL 29217789 - update fw common interface files
  fw-api: CL 29208203 - update fw common interface files
  fw-api: CL 29193068 - update fw common interface files
  fw-api: CL 29182219 - update fw common interface files
  fw-api: CL 29158320 - update fw common interface files
  fw-api: CL 29137988 - update fw common interface files
  fw-api: CL 29126604 - update fw common interface files
  fw-api: CL 29115376 - update fw common interface files
  fw-api: CL 29072944 - update fw common interface files
  fw-api: CL 29042940 - update fw common interface files
  fw-api: CL 29035093 - update fw common interface files
  fw-api: CL 29026260 - update fw common interface files
  fw-api: CL 29018064 - update fw common interface files
  fw-api: CL 29017022 - update fw common interface files
  fw-api: CL 29007944 - update fw common interface files
  fw-api: CL 28998846 - update fw common interface files
  fw-api: CL 28998301 - update fw common interface files
  fw-api: CL 28990820 - update fw common interface files
  fw-api: CL 28971130 - update fw common interface files
  fw-api: CL 28972929 - update fw common interface files
  fw-api: CL 28970374 - update fw common interface files
  fw-api: CL 28944690 - update fw common interface files
  fw-api: CL 28942439 - update fw common interface files
  fw-api: CL 28935775 - update fw common interface files
  fw-api: CL 28933869 - update fw common interface files
  fw-api: CL 28911997 - update fw common interface files
  fw-api: CL 28903851 - update fw common interface files
  fw-api: CL 28887056 - update fw common interface files
  fw-api: CL 28862777 - update fw common interface files
  fw-api: CL 28855140 - update fw common interface files
  fw-api: CL 28843692 - update fw common interface files
  fw-api: CL 28837244 - update fw common interface files
  fw-api: CL 28829747 - update fw common interface files
  fw-api: CL 28811455 - update fw common interface files
  fw-api: CL 28805911 - update fw common interface files
  fw-api: CL 28757294 - update fw common interface files
  fw-api: CL 28748436 - update fw common interface files
  fw-api: CL 28739491 - update fw common interface files
  fw-api: CL 28727084 - update fw common interface files
  fw-api: CL 28705885 - update fw common interface files
  fw-api: CL 28686055 - update fw common interface files
  fw-api: CL 28676060 - update fw common interface files
  fw-api: CL 28639946 - update fw common interface files
  fw-api: CL 28638758 - update fw common interface files
  fw-api: CL 28611293 - update fw common interface files
  fw-api: CL 28602565 - update fw common interface files
  fw-api: CL 28584645 - update fw common interface files
  fw-api: CL 28583592 - update fw common interface files

Change-Id: If92c430fd46f708ab3642087b2c8f6ac655c4743
2026-04-30 21:10:43 +03:00
Michael Bestas
af92965dcb
usb: Undo qcom damage
Revert "reverting all USB patches"

This reverts commit 365834436c.

 Conflicts:
	drivers/usb/core/quirks.c
	drivers/usb/dwc3/dwc3-qcom.c
	drivers/usb/host/xhci-plat.c
	drivers/usb/serial/option.c

Partially revert "reverting enum-conversion, Handle CPU state and all USB patches"

This partially reverts commit 2c3bda25f8.

 Conflicts:
	drivers/usb/core/quirks.c
	drivers/usb/dwc3/gadget.c
	drivers/usb/gadget/function/f_fs.c
	drivers/usb/serial/option.c

Change-Id: I89f5ca04b3306fddb8b9ebd5382ec495ff9e1030
2026-04-30 21:08:27 +03:00
Michael Bestas
9f0d3e60bc
Merge tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/kernel/msm-5.4 into android13-5.4-lahaina
LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0

* tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/kernel/msm-5.4:
  msm:kgsl: Prevent sign extension on alignments
  reverting all USB patches
  msm: eva: OOB write issue in fence processing
  kgsl: gmu: Use num_vma for safe GMU VMAs array access
  net: Add netdevice notification for bridge activity
  bridge: port structure members from 5.4 kernel
  net: bridge: Fix for co-located mode
  UPSTREAM: usb: gadget: configfs: Add frame-based frame format support
  kgsl: Add buffer overflow check for perfcounter dynamic list
  usb: gadget: uvc: Add grey and I420 YUV UVC format support
  mtd: msm_qpic_nand: Use flash device ECC capability for erase page
  mtd: msm_qpic_nand: check for page_erased bit along with op_err
  UPSTREAM: usb: dwc3: Wait for EndXfer command completion
  netfilter: fix NATTYPE refresh timeout issue
  usb: gadget: uvc: Modify UVC_NUM_REQUESTS
  reverting enum-conversion, Handle CPU state and all USB patches
  msm: cvp: Fix for kernel address exposure vulnerability to user
  cnss: Init reserved memory device
  cnss: Dump stack by stack_trace_print
  cnss: Add support for building CNSS as a loadable module
  FROMLIST: media: venus: Add a check for packet size
  Add configures to enable CNSS platform driver
  FROMLIST: media: venus: Fix OOB read due to missing payload bound check
  dma-mapping-fast: Fix PMD offset calculation for non-2M aligned start aperture
  crypto: qcedev - fix UAF in crypto-qti driver
  msm: adsprpc: Prevent refcount increment for duplicate dmahandles
  dmaengine: msm_gpi: fix to avoid null pointer access
  mdm: ipa3: support IPoGRE new IOCTL and proc params
  msm: mhi_dev: Workqueue to handle host wakeup in M3+D0
  iommu: Fix invalid access in av8l_fast_unmap_public
  msm: mhi_dev: Handle host wakeup in M3/D0
  msm: ep_pcie: Wake host in D3cold handling if wake is pending
  FROMGIT: media: venus: hfi: add a check to handle OOB in sfr region
  FROMGIT: media: venus: hfi: add check to handle incorrect queue size
  FROMGIT: media: venus: hfi_parser: add check to avoid out of bound access
  Revert "msm_ipa: Install exception rule for PPPoE-MPLS"
  firmware: qcom_scm: do not clear dump mode from shutdown
  msm: adsprpc: Avoid taking reference for group_info
  adsprpc: Handle UAF scenario in put_args
  msm: eva: Adding kref count for cvp_get_inst_from_id
  wifi: cfg80211: Increase akm_suites array size in cfg80211_crypto_settings
  thermal: qcom: Add support to update tsens trip based on nvmem data

 Conflicts:
	Makefile
	arch/arm64/include/asm/cputype.h
	drivers/char/adsprpc.c
	drivers/hid/hid-ids.h
	drivers/net/usb/rtl8150.c
	drivers/platform/Kconfig
	drivers/platform/Makefile
	drivers/soc/qcom/mdt_loader.c
	drivers/soc/qcom/rpmh-rsc.c
	drivers/usb/core/quirks.c
	drivers/usb/dwc3/dwc3-qcom.c
	drivers/usb/dwc3/gadget.c
	drivers/usb/gadget/function/f_fs.c
	drivers/usb/gadget/function/f_ncm.c
	mm/slub.c
	mm/zsmalloc.c
	net/ipv4/tcp_output.c
	scripts/Makefile.extrawarn

Change-Id: Ia4f3356ed4a105a2f3b0feda3e78725a01a970b2
2026-04-30 20:46:30 +03:00
angelomds42
af20c21925 Makefile: Fix LLVM_IAS condition after IAS default flip
The commit 01ecebdbac6e ("BACKPORT: scripts/Makefile.clang: default to
LLVM_IAS=1") flipped LLVM_IAS to opt-out but did not update the
ifneq ($(LLVM_IAS),1) condition introduced by 2f5d594440ac ("FROMLIST:
Kbuild: do not emit debug info for assembly with LLVM_IAS=1"), causing
warnings when LLVM_IAS is unset:

warning: DWARF2 only supports one section per compilation unit

Fixes: 01ecebdbac6e ("BACKPORT: scripts/Makefile.clang: default to LLVM_IAS=1")
Change-Id: If373071466d851ee8d814751f9bc4672e68aaf34
2026-04-20 22:49:04 -04:00
Anandu Krishnan E
26a278473b
dsp-kernel: Avoid overflow in ALIGN macro usage
Check for potential overflow before using the ALIGN macro,
as it is not overflow-safe.

Change-Id: Iffa1b7a01a9e072fb748c93f6625d0f1a163d0f8
Signed-off-by: Anandu Krishnan E <quic_anane@quicinc.com>
(cherry picked from commit 96a6c4a8768f73ba9041c15511f0d5888507c8f4)
2026-04-18 03:46:04 +03:00
Linux Build Service Account
0910d94404 Merge df582cc15a on remote branch
Change-Id: I7a0833a456eec4b5cc5921c88cb7808a8e799844
2026-02-26 07:58:02 -08:00
Linux Build Service Account
2aeceac738 Merge f1b974d142 on remote branch
Change-Id: If973c515e7540989893d8e8f17039174b47453f0
2026-02-26 07:47:51 -08:00
Thomas Turner
7d4c64f722 fixup! BACKPORT: treewide: Use fallthrough pseudo-keyword
Somehow net/core/filter.c was skipped.

Change-Id: Icc40edde93e6d9563faa66d21153c4fecc623c80
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-11 18:43:09 +00:00
QCTECMDR Service
f1b974d142 Merge "msm:kgsl: Prevent sign extension on alignments" 2026-02-02 01:24:39 -08:00
Thomas Turner
33cf9d14d1
Revert "net, sctp, filter: remap copy_from_user failure error"
Reason for revert: This commit was not needed on 5.10 and above.

This reverts commit 55bac51762.

Change-Id: I552769bda33fb27fcd32de5191ab0f45fb7f2efa
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:59 -08:00
Paul Chaignon
2f7e583d02
UPSTREAM: bpf: Fix L4 csum update on IPv6 in CHECKSUM_COMPLETE
commit ead7f9b8de65632ef8060b84b0c55049a33cfea1 upstream.

In Cilium, we use bpf_csum_diff + bpf_l4_csum_replace to, among other
things, update the L4 checksum after reverse SNATing IPv6 packets. That
use case is however not currently supported and leads to invalid
skb->csum values in some cases. This patch adds support for IPv6 address
changes in bpf_l4_csum_update via a new flag.

When calling bpf_l4_csum_replace in Cilium, it ends up calling
inet_proto_csum_replace_by_diff:

    1:  void inet_proto_csum_replace_by_diff(__sum16 *sum, struct sk_buff *skb,
    2:                                       __wsum diff, bool pseudohdr)
    3:  {
    4:      if (skb->ip_summed != CHECKSUM_PARTIAL) {
    5:          csum_replace_by_diff(sum, diff);
    6:          if (skb->ip_summed == CHECKSUM_COMPLETE && pseudohdr)
    7:              skb->csum = ~csum_sub(diff, skb->csum);
    8:      } else if (pseudohdr) {
    9:          *sum = ~csum_fold(csum_add(diff, csum_unfold(*sum)));
    10:     }
    11: }

The bug happens when we're in the CHECKSUM_COMPLETE state. We've just
updated one of the IPv6 addresses. The helper now updates the L4 header
checksum on line 5. Next, it updates skb->csum on line 7. It shouldn't.

For an IPv6 packet, the updates of the IPv6 address and of the L4
checksum will cancel each other. The checksums are set such that
computing a checksum over the packet including its checksum will result
in a sum of 0. So the same is true here when we update the L4 checksum
on line 5. We'll update it as to cancel the previous IPv6 address
update. Hence skb->csum should remain untouched in this case.

The same bug doesn't affect IPv4 packets because, in that case, three
fields are updated: the IPv4 address, the IP checksum, and the L4
checksum. The change to the IPv4 address and one of the checksums still
cancel each other in skb->csum, but we're left with one checksum update
and should therefore update skb->csum accordingly. That's exactly what
inet_proto_csum_replace_by_diff does.

This special case for IPv6 L4 checksums is also described atop
inet_proto_csum_replace16, the function we should be using in this case.

This patch introduces a new bpf_l4_csum_replace flag, BPF_F_IPV6,
to indicate that we're updating the L4 checksum of an IPv6 packet. When
the flag is set, inet_proto_csum_replace_by_diff will skip the
skb->csum update.

Fixes: 7d672345ed ("bpf: add generic bpf_csum_diff helper")
Change-Id: Ief7e9d62380eb344a218a149cda3dfeeaf568ae6
Signed-off-by: Paul Chaignon <paul.chaignon@gmail.com>
Acked-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://patch.msgid.link/96a6bc3a443e6f0b21ff7b7834000e17fb549e05.1748509484.git.paul.chaignon@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
[ Note: Fixed conflict due to unrelated comment change. ]
Signed-off-by: Paul Chaignon <paul.chaignon@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:58 -08:00
Paul Chaignon
2ec8753738
UPSTREAM: net: Fix checksum update for ILA adj-transport
commit 6043b794c7668c19dabc4a93c75b924a19474d59 upstream.

During ILA address translations, the L4 checksums can be handled in
different ways. One of them, adj-transport, consist in parsing the
transport layer and updating any found checksum. This logic relies on
inet_proto_csum_replace_by_diff and produces an incorrect skb->csum when
in state CHECKSUM_COMPLETE.

This bug can be reproduced with a simple ILA to SIR mapping, assuming
packets are received with CHECKSUM_COMPLETE:

  $ ip a show dev eth0
  14: eth0@if15: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
      link/ether 62:ae:35:9e:0f:8d brd ff:ff:ff:ff:ff:ff link-netnsid 0
      inet6 3333:0:0:1::c078/64 scope global
         valid_lft forever preferred_lft forever
      inet6 fd00:10:244:1::c078/128 scope global nodad
         valid_lft forever preferred_lft forever
      inet6 fe80::60ae:35ff:fe9e:f8d/64 scope link proto kernel_ll
         valid_lft forever preferred_lft forever
  $ ip ila add loc_match fd00:10:244:1 loc 3333:0:0:1 \
      csum-mode adj-transport ident-type luid dev eth0

Then I hit [fd00:10:244:1::c078]:8000 with a server listening only on
[3333:0:0:1::c078]:8000. With the bug, the SYN packet is dropped with
SKB_DROP_REASON_TCP_CSUM after inet_proto_csum_replace_by_diff changed
skb->csum. The translation and drop are visible on pwru [1] traces:

  IFACE   TUPLE                                                        FUNC
  eth0:9  [fd00:10:244:3::3d8]:51420->[fd00:10:244:1::c078]:8000(tcp)  ipv6_rcv
  eth0:9  [fd00:10:244:3::3d8]:51420->[fd00:10:244:1::c078]:8000(tcp)  ip6_rcv_core
  eth0:9  [fd00:10:244:3::3d8]:51420->[fd00:10:244:1::c078]:8000(tcp)  nf_hook_slow
  eth0:9  [fd00:10:244:3::3d8]:51420->[fd00:10:244:1::c078]:8000(tcp)  inet_proto_csum_replace_by_diff
  eth0:9  [fd00:10:244:3::3d8]:51420->[3333:0:0:1::c078]:8000(tcp)     tcp_v6_early_demux
  eth0:9  [fd00:10:244:3::3d8]:51420->[3333:0:0:1::c078]:8000(tcp)     ip6_route_input
  eth0:9  [fd00:10:244:3::3d8]:51420->[3333:0:0:1::c078]:8000(tcp)     ip6_input
  eth0:9  [fd00:10:244:3::3d8]:51420->[3333:0:0:1::c078]:8000(tcp)     ip6_input_finish
  eth0:9  [fd00:10:244:3::3d8]:51420->[3333:0:0:1::c078]:8000(tcp)     ip6_protocol_deliver_rcu
  eth0:9  [fd00:10:244:3::3d8]:51420->[3333:0:0:1::c078]:8000(tcp)     raw6_local_deliver
  eth0:9  [fd00:10:244:3::3d8]:51420->[3333:0:0:1::c078]:8000(tcp)     ipv6_raw_deliver
  eth0:9  [fd00:10:244:3::3d8]:51420->[3333:0:0:1::c078]:8000(tcp)     tcp_v6_rcv
  eth0:9  [fd00:10:244:3::3d8]:51420->[3333:0:0:1::c078]:8000(tcp)     __skb_checksum_complete
  eth0:9  [fd00:10:244:3::3d8]:51420->[3333:0:0:1::c078]:8000(tcp)     kfree_skb_reason(SKB_DROP_REASON_TCP_CSUM)
  eth0:9  [fd00:10:244:3::3d8]:51420->[3333:0:0:1::c078]:8000(tcp)     skb_release_head_state
  eth0:9  [fd00:10:244:3::3d8]:51420->[3333:0:0:1::c078]:8000(tcp)     skb_release_data
  eth0:9  [fd00:10:244:3::3d8]:51420->[3333:0:0:1::c078]:8000(tcp)     skb_free_head
  eth0:9  [fd00:10:244:3::3d8]:51420->[3333:0:0:1::c078]:8000(tcp)     kfree_skbmem

This is happening because inet_proto_csum_replace_by_diff is updating
skb->csum when it shouldn't. The L4 checksum is updated such that it
"cancels" the IPv6 address change in terms of checksum computation, so
the impact on skb->csum is null.

Note this would be different for an IPv4 packet since three fields
would be updated: the IPv4 address, the IP checksum, and the L4
checksum. Two would cancel each other and skb->csum would still need
to be updated to take the L4 checksum change into account.

This patch fixes it by passing an ipv6 flag to
inet_proto_csum_replace_by_diff, to skip the skb->csum update if we're
in the IPv6 case. Note the behavior of the only other user of
inet_proto_csum_replace_by_diff, the BPF subsystem, is left as is in
this patch and fixed in the subsequent patch.

With the fix, using the reproduction from above, I can confirm
skb->csum is not touched by inet_proto_csum_replace_by_diff and the TCP
SYN proceeds to the application after the ILA translation.

Link: https://github.com/cilium/pwru [1]
Fixes: 65d7ab8de5 ("net: Identifier Locator Addressing module")
Change-Id: Iff2bd64e26b7e318f3d580070ffc20d44bf630b2
Signed-off-by: Paul Chaignon <paul.chaignon@gmail.com>
Acked-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://patch.msgid.link/b5539869e3550d46068504feb02d37653d939c0b.1748509484.git.paul.chaignon@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
[ Fixed conflict due to unrelated change in inet_proto_csum_replace_by_diff. ]
Signed-off-by: Paul Chaignon <paul.chaignon@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:57 -08:00
Cong Wang
3402025538
UPSTREAM: lwt_bpf: Replace preempt_disable() with migrate_disable()
migrate_disable() is just a wrapper for preempt_disable() in
non-RT kernel. It is safe to replace it, and RT kernel will
benefit.

Note that it is introduced since Feb 2020.

Suggested-by: Alexei Starovoitov <alexei.starovoitov@gmail.com>
Change-Id: I1365390ddebc37532188ebaadfe3289836b746ff
Signed-off-by: Cong Wang <cong.wang@bytedance.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://lore.kernel.org/bpf/20201205075946.497763-2-xiyou.wangcong@gmail.com
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:57 -08:00
Greg Kroah-Hartman
ff781de48d
ANDROID: add kabi padding for bpf_verifier structure
Also add a few missing things. (no functional change)

Change-Id: I5d29028ffdacb08afcde396543145e9cf21cb6fe
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:56 -08:00
Christoph Hellwig
b37692ea84
UPSTREAM: net/bpfilter: Initialize pos in __bpfilter_process_sockopt
__bpfilter_process_sockopt never initialized the pos variable passed
to the pipe write. This has been mostly harmless in the past as pipes
ignore the offset, but the switch to kernel_write now verified the
position, which can lead to a failure depending on the exact stack
initialization pattern. Initialize the variable to zero to make
rw_verify_area happy.

Fixes: 6955a76fbcd5 ("bpfilter: switch to kernel_write")
Reported-by: Christian Brauner <christian.brauner@ubuntu.com>
Reported-by: Rodrigo Madera <rodrigo.madera@gmail.com>
Change-Id: I8881e10460784cece6b2a2338c1b418adf99965e
Signed-off-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Tested-by: Rodrigo Madera <rodrigo.madera@gmail.com>
Tested-by: Christian Brauner <christian.brauner@ubuntu.com>
Reviewed-by: Christian Brauner <christian.brauner@ubuntu.com>
Link: https://lore.kernel.org/bpf/20200730160900.187157-1-hch@lst.de
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:55 -08:00
Christoph Hellwig
b644b034eb
UPSTREAM: bpfilter: switch bpfilter_ip_set_sockopt to sockptr_t
This is mostly to prepare for cleaning up the callers, as bpfilter by
design can't handle kernel pointers.

Change-Id: I2696c789576b662bcf3849b718a2b06b0a5a37a5
Signed-off-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:55 -08:00
Christoph Hellwig
7feeb09195
UPSTREAM: bpfilter: reject kernel addresses
The bpfilter user mode helper processes the optval address using
process_vm_readv.  Don't send it kernel addresses fed under
set_fs(KERNEL_DS) as that won't work.

Change-Id: Ifa43c1bea055758b57c5b0a7e46d36036dd09daf
Signed-off-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:54 -08:00
Christoph Hellwig
fda92fa32c
UPSTREAM: net/bpfilter: split __bpfilter_process_sockopt
Split __bpfilter_process_sockopt into a low-level send request routine and
the actual setsockopt hook to split the init time ping from the actual
setsockopt processing.

Change-Id: Ic1f2d56c8a714739a88672bd4e4d75d2b17ba415
Signed-off-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:54 -08:00
Christoph Hellwig
f7a13b6f6d
UPSTREAM: bpfilter: fix up a sparse annotation
The __user doesn't make sense when casting to an integer type, just
switch to a uintptr_t cast which also removes the need for the __force.

Change-Id: I12ac2ad1687b213037bd77db602350df40e144ce
Signed-off-by: Christoph Hellwig <hch@lst.de>
Reviewed-by: Luc Van Oostenryck <luc.vanoostenryck@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:53 -08:00
Masahiro Yamada
bc0a23431a
UPSTREAM: bpfilter: Allow to build bpfilter_umh as a module without static library
Originally, bpfilter_umh was linked with -static only when
CONFIG_BPFILTER_UMH=y.

Commit 8a2cc0505cc4 ("bpfilter: use 'userprogs' syntax to build
bpfilter_umh") silently, accidentally dropped the CONFIG_BPFILTER_UMH=y
test in the Makefile. Revive it in order to link it dynamically when
CONFIG_BPFILTER_UMH=m.

Since commit b1183b6dca3e ("bpfilter: check if $(CC) can link static
libc in Kconfig"), the compiler must be capable of static linking to
enable CONFIG_BPFILTER_UMH, but it requires more than needed.

To loosen the compiler requirement, I changed the dependency as follows:

    depends on CC_CAN_LINK
    depends on m || CC_CAN_LINK_STATIC

If CONFIG_CC_CAN_LINK_STATIC in unset, CONFIG_BPFILTER_UMH is restricted
to 'm' or 'n'.

In theory, CONFIG_CC_CAN_LINK is not required for CONFIG_BPFILTER_UMH=y,
but I did not come up with a good way to describe it.

Fixes: 8a2cc0505cc4 ("bpfilter: use 'userprogs' syntax to build bpfilter_umh")
Reported-by: Michal Kubecek <mkubecek@suse.cz>
Change-Id: I2341985feef30c977f7562be1aab28457c88964f
Signed-off-by: Masahiro Yamada <masahiroy@kernel.org>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Tested-by: Michal Kubecek <mkubecek@suse.cz>
Link: https://lore.kernel.org/bpf/20200701092644.762234-1-masahiroy@kernel.org
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:52 -08:00
Alexei Starovoitov
0fc6df7760
UPSTREAM: bpfilter: Initialize pos variable
Make sure 'pos' is initialized to zero before calling kernel_write().

Fixes: d2ba09c17a ("net: add skeleton of bpfilter kernel module")
Change-Id: I7d7e53e5e18f9ee05fb5a30b9629a3e09af1c913
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:52 -08:00
Christoph Hellwig
30e262549b
UPSTREAM: bpfilter: switch to kernel_write
While pipes don't really need sb_writers projection, __kernel_write is an
interface better kept private, and the additional rw_verify_area does not
hurt here.

Change-Id: Ia2fb6109d3c1a6d65aa2e22dc7737e57bfac578e
Signed-off-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:51 -08:00
Eric W. Biederman
99eec559b4
UPSTREAM: bpfilter: Take advantage of the facilities of struct pid
Instead of relying on the exit_umh cleanup callback use the fact a
struct pid can be tested to see if a process still exists, and that
struct pid has a wait queue that notifies when the process dies.

v1: https://lkml.kernel.org/r/87h7uydlu9.fsf_-_@x220.int.ebiederm.org
v2: https://lkml.kernel.org/r/874kqt4owu.fsf_-_@x220.int.ebiederm.org
Link: https://lkml.kernel.org/r/20200702164140.4468-14-ebiederm@xmission.com
Reviewed-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Acked-by: Alexei Starovoitov <ast@kernel.org>
Tested-by: Alexei Starovoitov <ast@kernel.org>
Change-Id: Id9db45a4e902e36922c4f9bd83b80de71012545a
Signed-off-by: "Eric W. Biederman" <ebiederm@xmission.com>
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:50 -08:00
Eric W. Biederman
c65fbcec66
UPSTREAM: bpfilter: Move bpfilter_umh back into init data
To allow for restarts 61fbf5933d ("net: bpfilter: restart
bpfilter_umh when error occurred") moved the blob holding the
userspace binary out of the init sections.

Now that loading the blob into a filesystem is separate from executing
the blob the blob no longer needs to live .rodata to allow for restarting.
So move the blob back to .init.rodata.

v1: https://lkml.kernel.org/r/87sgeidlvq.fsf_-_@x220.int.ebiederm.org
v2: https://lkml.kernel.org/r/87ftad4ozc.fsf_-_@x220.int.ebiederm.org
Link: https://lkml.kernel.org/r/20200702164140.4468-11-ebiederm@xmission.com
Reviewed-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Acked-by: Alexei Starovoitov <ast@kernel.org>
Tested-by: Alexei Starovoitov <ast@kernel.org>
Change-Id: Ia9bcca3837fd544724e7e6f8f7410d11581c94d5
Signed-off-by: "Eric W. Biederman" <ebiederm@xmission.com>
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:50 -08:00
Valdis Kl ē tnieks
3ed5cc82f2
UPSTREAM: bpfilter: document build requirements for bpfilter_umh
It's not intuitively obvious that bpfilter_umh is a statically linked binary.
Mention the toolchain requirement in the Kconfig help, so people
have an easier time figuring out what's needed.

Change-Id: I06d348723791d67a56271cb39f2445de562f763d
Signed-off-by: Valdis Kletnieks <valdis.kletnieks@vt.edu>
Signed-off-by: Masahiro Yamada <masahiroy@kernel.org>
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:49 -08:00
Masahiro Yamada
7ee4cba542
UPSTREAM: bpfilter: use 'userprogs' syntax to build bpfilter_umh
The user mode helper should be compiled for the same architecture as
the kernel.

This Makefile reused the 'hostprogs' syntax by overriding HOSTCC with CC.
Use the new syntax 'userprogs' to fix the Makefile mess.

Change-Id: I457180fe9e4e3da6e25b5665c47033780e48b40c
Signed-off-by: Masahiro Yamada <masahiroy@kernel.org>
Acked-by: Sam Ravnborg <sam@ravnborg.org>
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:49 -08:00
Eric W. Biederman
6782cb9b3f
UPSTREAM: exit: Factor thread_group_exited out of pidfd_poll
Create an independent helper thread_group_exited which returns true
when all threads have passed exit_notify in do_exit.  AKA all of the
threads are at least zombies and might be dead or completely gone.

Create this helper by taking the logic out of pidfd_poll where it is
already tested, and adding a READ_ONCE on the read of
task->exit_state.

I will be changing the user mode driver code to use this same logic
to know when a user mode driver needs to be restarted.

Place the new helper thread_group_exited in kernel/exit.c and
EXPORT it so it can be used by modules.

Link: https://lkml.kernel.org/r/20200702164140.4468-13-ebiederm@xmission.com
Acked-by: Christian Brauner <christian.brauner@ubuntu.com>
Acked-by: Alexei Starovoitov <ast@kernel.org>
Tested-by: Alexei Starovoitov <ast@kernel.org>
Change-Id: I26813e9dad6a0bb78528cf1cff3fbc6c2369231f
Signed-off-by: "Eric W. Biederman" <ebiederm@xmission.com>
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:48 -08:00
Greg Kroah-Hartman
6e202efd9d
ANDROID: add kabi padding for bpf structures
Change-Id: I42535ee7955d094c6491845ec5ff721128db5a36
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:47 -08:00
Wang Qing
81d35fca80
UPSTREAM: bpf: Fix passing zero to PTR_ERR() in bpf_btf_printf_prepare
There is a bug when passing zero to PTR_ERR() and return.
Fix the smatch error.

Fixes: c4d0bfb45068 ("bpf: Add bpf_snprintf_btf helper")
Change-Id: Ibddaa08258ecc2f9887f84445abac7db55a90537
Signed-off-by: Wang Qing <wangqing@vivo.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: Yonghong Song <yhs@fb.com>
Acked-by: John Fastabend <john.fastabend@gmail.com>
Link: https://lore.kernel.org/bpf/1604735144-686-1-git-send-email-wangqing@vivo.com
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:47 -08:00
Yonghong Song
d34a994203
UPSTREAM: bpf: Fix a possible task gone issue with bpf_send_signal[_thread]() helpers
[ Upstream commit bdb7fdb0aca8b96cef9995d3a57e251c2289322f ]

In current bpf_send_signal() and bpf_send_signal_thread() helper
implementation, irq_work is used to handle nmi context. Hao Sun
reported in [1] that the current task at the entry of the helper
might be gone during irq_work callback processing. To fix the issue,
a reference is acquired for the current task before enqueuing into
the irq_work so that the queued task is still available during
irq_work callback processing.

  [1] https://lore.kernel.org/bpf/20230109074425.12556-1-sunhao.th@gmail.com/

Fixes: 8b401f9ed2 ("bpf: implement bpf_send_signal() helper")
Tested-by: Hao Sun <sunhao.th@gmail.com>
Reported-by: Hao Sun <sunhao.th@gmail.com>
Change-Id: I9caf795beeffc0041ced83cf2d7c960ce2e3a206
Signed-off-by: Yonghong Song <yhs@fb.com>
Link: https://lore.kernel.org/r/20230118204815.3331855-1-yhs@fb.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:46 -08:00
Jiri Olsa
75696eea7d
UPSTREAM: bpf: Disable preemption in bpf_event_output
commit d62cc390c2e99ae267ffe4b8d7e2e08b6c758c32 upstream.

We received report [1] of kernel crash, which is caused by
using nesting protection without disabled preemption.

The bpf_event_output can be called by programs executed by
bpf_prog_run_array_cg function that disabled migration but
keeps preemption enabled.

This can cause task to be preempted by another one inside the
nesting protection and lead eventually to two tasks using same
perf_sample_data buffer and cause crashes like:

  BUG: kernel NULL pointer dereference, address: 0000000000000001
  #PF: supervisor instruction fetch in kernel mode
  #PF: error_code(0x0010) - not-present page
  ...
  ? perf_output_sample+0x12a/0x9a0
  ? finish_task_switch.isra.0+0x81/0x280
  ? perf_event_output+0x66/0xa0
  ? bpf_event_output+0x13a/0x190
  ? bpf_event_output_data+0x22/0x40
  ? bpf_prog_dfc84bbde731b257_cil_sock4_connect+0x40a/0xacb
  ? xa_load+0x87/0xe0
  ? __cgroup_bpf_run_filter_sock_addr+0xc1/0x1a0
  ? release_sock+0x3e/0x90
  ? sk_setsockopt+0x1a1/0x12f0
  ? udp_pre_connect+0x36/0x50
  ? inet_dgram_connect+0x93/0xa0
  ? __sys_connect+0xb4/0xe0
  ? udp_setsockopt+0x27/0x40
  ? __pfx_udp_push_pending_frames+0x10/0x10
  ? __sys_setsockopt+0xdf/0x1a0
  ? __x64_sys_connect+0xf/0x20
  ? do_syscall_64+0x3a/0x90
  ? entry_SYSCALL_64_after_hwframe+0x72/0xdc

Fixing this by disabling preemption in bpf_event_output.

[1] https://github.com/cilium/cilium/issues/26756
Cc: stable@vger.kernel.org
Reported-by: Oleg "livelace" Popov <o.popov@livelace.ru>
Closes: https://github.com/cilium/cilium/issues/26756
Fixes: 2a916f2f546c ("bpf: Use migrate_disable/enable in array macros and cgroup/lirc code.")
Acked-by: Hou Tao <houtao1@huawei.com>
Change-Id: Icaf207af7dfb071f0adb10fe9bb7f367e25c1860
Signed-off-by: Jiri Olsa <jolsa@kernel.org>
Link: https://lore.kernel.org/r/20230725084206.580930-3-jolsa@kernel.org
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:46 -08:00
Yonghong Song
3150a87b86
UPSTREAM: bpf: Support 'X' in bpf_seq_printf() helper
'X' tells kernel to print hex with upper case letters.
/proc/net/tcp{4,6} seq_file show() used this, and
supports it in bpf_seq_printf() helper too.

Change-Id: I7c88f9f2c9088a6acb3b2085988de50535b970e6
Signed-off-by: Yonghong Song <yhs@fb.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Acked-by: Martin KaFai Lau <kafai@fb.com>
Link: https://lore.kernel.org/bpf/20200623230807.3988014-1-yhs@fb.com
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:45 -08:00
Song Liu
b23f48db3c
UPSTREAM: bpf: Allow %pB in bpf_seq_printf() and bpf_trace_printk()
This makes it easy to dump stack trace in text.

Change-Id: Ia29115428a1dadf823881bfbbc793628b2fc9715
Signed-off-by: Song Liu <songliubraving@fb.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Acked-by: Yonghong Song <yhs@fb.com>
Acked-by: Andrii Nakryiko <andriin@fb.com>
Link: https://lore.kernel.org/bpf/20200630062846.664389-4-songliubraving@fb.com
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:45 -08:00
Stanislav Fomichev
f2a2b97107
UPSTREAM: bpf: Remove inline from bpf_do_trace_printk
I get the following error during compilation on my side:
kernel/trace/bpf_trace.c: In function 'bpf_do_trace_printk':
kernel/trace/bpf_trace.c:386:34: error: function 'bpf_do_trace_printk' can never be inlined because it uses variable argument lists
 static inline __printf(1, 0) int bpf_do_trace_printk(const char *fmt, ...)
                                  ^

Fixes: ac5a72ea5c89 ("bpf: Use dedicated bpf_trace_printk event instead of trace_printk()")
Change-Id: I105192533535b3f3cbc78c7a54f1fbbc2eb6450b
Signed-off-by: Stanislav Fomichev <sdf@google.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://lore.kernel.org/bpf/20200806182612.1390883-1-sdf@google.com
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:44 -08:00
Alan Maguire
b338e77ab0
UPSTREAM: bpf: Use dedicated bpf_trace_printk event instead of trace_printk()
The bpf helper bpf_trace_printk() uses trace_printk() under the hood.
This leads to an alarming warning message originating from trace
buffer allocation which occurs the first time a program using
bpf_trace_printk() is loaded.

We can instead create a trace event for bpf_trace_printk() and enable
it in-kernel when/if we encounter a program using the
bpf_trace_printk() helper.  With this approach, trace_printk()
is not used directly and no warning message appears.

This work was started by Steven (see Link) and finished by Alan; added
Steven's Signed-off-by with his permission.

Change-Id: I3644e434a2f1e99d1fa523d247ac0b19911d041b
Signed-off-by: Steven Rostedt (VMware) <rostedt@goodmis.org>
Signed-off-by: Alan Maguire <alan.maguire@oracle.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Acked-by: Andrii Nakryiko <andriin@fb.com>
Link: https://lore.kernel.org/r/20200628194334.6238b933@oasis.local.home
Link: https://lore.kernel.org/bpf/1594641154-18897-2-git-send-email-alan.maguire@oracle.com
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:43 -08:00
Daniel Xu
5e5bb29653
UPSTREAM: lib/strncpy_from_user.c: Mask out bytes after NUL terminator.
do_strncpy_from_user() may copy some extra bytes after the NUL
terminator into the destination buffer. This usually does not matter for
normal string operations. However, when BPF programs key BPF maps with
strings, this matters a lot.

A BPF program may read strings from user memory by calling the
bpf_probe_read_user_str() helper which eventually calls
do_strncpy_from_user(). The program can then key a map with the
destination buffer. BPF map keys are fixed-width and string-agnostic,
meaning that map keys are treated as a set of bytes.

The issue is when do_strncpy_from_user() overcopies bytes after the NUL
terminator, it can result in seemingly identical strings occupying
multiple slots in a BPF map. This behavior is subtle and totally
unexpected by the user.

This commit masks out the bytes following the NUL while preserving
long-sized stride in the fast path.

Fixes: 6ae08ae3dea2 ("bpf: Add probe_read_{user, kernel} and probe_read_{user, kernel}_str helpers")
Change-Id: I10d009c0e2db1ca242fbc0076fa2933f17c4a9a9
Signed-off-by: Daniel Xu <dxu@dxuuu.xyz>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://lore.kernel.org/bpf/21efc982b3e9f2f7b0379eed642294caaa0c27a7.1605642949.git.dxu@dxuuu.xyz
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:43 -08:00
Daniel Borkmann
be5cfab9c4
BACKPORT: bpf: Add lockdown check for probe_write_user helper
commit 51e1bb9eeaf7868db56e58f47848e364ab4c4129 upstream.

Back then, commit 96ae522795 ("bpf: Add bpf_probe_write_user BPF helper
to be called in tracers") added the bpf_probe_write_user() helper in order
to allow to override user space memory. Its original goal was to have a
facility to "debug, divert, and manipulate execution of semi-cooperative
processes" under CAP_SYS_ADMIN. Write to kernel was explicitly disallowed
since it would otherwise tamper with its integrity.

One use case was shown in cf9b1199de ("samples/bpf: Add test/example of
using bpf_probe_write_user bpf helper") where the program DNATs traffic
at the time of connect(2) syscall, meaning, it rewrites the arguments to
a syscall while they're still in userspace, and before the syscall has a
chance to copy the argument into kernel space. These days we have better
mechanisms in BPF for achieving the same (e.g. for load-balancers), but
without having to write to userspace memory.

Of course the bpf_probe_write_user() helper can also be used to abuse
many other things for both good or bad purpose. Outside of BPF, there is
a similar mechanism for ptrace(2) such as PTRACE_PEEK{TEXT,DATA} and
PTRACE_POKE{TEXT,DATA}, but would likely require some more effort.
Commit 96ae522795 explicitly dedicated the helper for experimentation
purpose only. Thus, move the helper's availability behind a newly added
LOCKDOWN_BPF_WRITE_USER lockdown knob so that the helper is disabled under
the "integrity" mode. More fine-grained control can be implemented also
from LSM side with this change.

Fixes: 96ae522795 ("bpf: Add bpf_probe_write_user BPF helper to be called in tracers")
Change-Id: I824213c9e94b9c0c3ce0fe6188ed82ddebab018c
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: Andrii Nakryiko <andrii@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:42 -08:00
Alexei Starovoitov
c285b52590
UPSTREAM: bpf: Unbreak BPF_PROG_TYPE_KPROBE when kprobe is called via do_int3
[ Upstream commit 548f1191d86ccb9bde2a5305988877b7584c01eb ]

The commit 0d00449c7a28 ("x86: Replace ist_enter() with nmi_enter()")
converted do_int3 handler to be "NMI-like".
That made old if (in_nmi()) check abort execution of bpf programs
attached to kprobe when kprobe is firing via int3
(For example when kprobe is placed in the middle of the function).
Remove the check to restore user visible behavior.

Fixes: 0d00449c7a28 ("x86: Replace ist_enter() with nmi_enter()")
Reported-by: Nikolay Borisov <nborisov@suse.com>
Change-Id: I29ee95686ea9a51b2b59f8b06462510253036360
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Tested-by: Nikolay Borisov <nborisov@suse.com>
Reviewed-by: Masami Hiramatsu <mhiramat@kernel.org>
Link: https://lore.kernel.org/bpf/20210203070636.70926-1-alexei.starovoitov@gmail.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:42 -08:00
Thomas Gleixner
7ad9996931
UPSTREAM: bpf/trace: Remove redundant preempt_disable from trace_call_bpf()
Similar to __bpf_trace_run this is redundant because __bpf_trace_run() is
invoked from a trace point via __DO_TRACE() which already disables
preemption _before_ invoking any of the functions which are attached to a
trace point.

Remove it and add a cant_sleep() check.

Change-Id: I6106e5ed79cf84ae2b6e6032c7b081209a68da6c
Signed-off-by: Thomas Gleixner <tglx@linutronix.de>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://lore.kernel.org/bpf/20200224145643.059995527@linutronix.de
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:41 -08:00
Jiri Olsa
19b8833055
UPSTREAM: bpf: Add extra path pointer check to d_path helper
[ Upstream commit f46fab0e36e611a2389d3843f34658c849b6bd60 ]

Anastasios reported crash on stable 5.15 kernel with following
BPF attached to lsm hook:

  SEC("lsm.s/bprm_creds_for_exec")
  int BPF_PROG(bprm_creds_for_exec, struct linux_binprm *bprm)
  {
          struct path *path = &bprm->executable->f_path;
          char p[128] = { 0 };

          bpf_d_path(path, p, 128);
          return 0;
  }

But bprm->executable can be NULL, so bpf_d_path call will crash:

  BUG: kernel NULL pointer dereference, address: 0000000000000018
  #PF: supervisor read access in kernel mode
  #PF: error_code(0x0000) - not-present page
  PGD 0 P4D 0
  Oops: 0000 [#1] PREEMPT SMP DEBUG_PAGEALLOC NOPTI
  ...
  RIP: 0010:d_path+0x22/0x280
  ...
  Call Trace:
   <TASK>
   bpf_d_path+0x21/0x60
   bpf_prog_db9cf176e84498d9_bprm_creds_for_exec+0x94/0x99
   bpf_trampoline_6442506293_0+0x55/0x1000
   bpf_lsm_bprm_creds_for_exec+0x5/0x10
   security_bprm_creds_for_exec+0x29/0x40
   bprm_execve+0x1c1/0x900
   do_execveat_common.isra.0+0x1af/0x260
   __x64_sys_execve+0x32/0x40

It's problem for all stable trees with bpf_d_path helper, which was
added in 5.9.

This issue is fixed in current bpf code, where we identify and mark
trusted pointers, so the above code would fail even to load.

For the sake of the stable trees and to workaround potentially broken
verifier in the future, adding the code that reads the path object from
the passed pointer and verifies it's valid in kernel space.

Fixes: 6e22ab9da793 ("bpf: Add d_path helper")
Reported-by: Anastasios Papagiannis <tasos.papagiannnis@gmail.com>
Suggested-by: Alexei Starovoitov <ast@kernel.org>
Change-Id: I865e5c3a9c4d0268e9cbb35a74a162898c1c0a7e
Signed-off-by: Jiri Olsa <jolsa@kernel.org>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: Stanislav Fomichev <sdf@google.com>
Acked-by: Yonghong Song <yhs@fb.com>
Link: https://lore.kernel.org/bpf/20230606181714.532998-1-jolsa@kernel.org
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:41 -08:00
Kajol Jain
506d2a3bbf
UPSTREAM: bpf: Remove config check to enable bpf support for branch records
[ Upstream commit db52f57211b4e45f0ebb274e2c877b211dc18591 ]

Branch data available to BPF programs can be very useful to get stack traces
out of userspace application.

Commit fff7b64355ea ("bpf: Add bpf_read_branch_records() helper") added BPF
support to capture branch records in x86. Enable this feature also for other
architectures as well by removing checks specific to x86.

If an architecture doesn't support branch records, bpf_read_branch_records()
still has appropriate checks and it will return an -EINVAL in that scenario.
Based on UAPI helper doc in include/uapi/linux/bpf.h, unsupported architectures
should return -ENOENT in such case. Hence, update the appropriate check to
return -ENOENT instead.

Selftest 'perf_branches' result on power9 machine which has the branch stacks
support:

 - Before this patch:

  [command]# ./test_progs -t perf_branches
   #88/1 perf_branches/perf_branches_hw:FAIL
   #88/2 perf_branches/perf_branches_no_hw:OK
   #88 perf_branches:FAIL
  Summary: 0/1 PASSED, 0 SKIPPED, 1 FAILED

 - After this patch:

  [command]# ./test_progs -t perf_branches
   #88/1 perf_branches/perf_branches_hw:OK
   #88/2 perf_branches/perf_branches_no_hw:OK
   #88 perf_branches:OK
  Summary: 1/2 PASSED, 0 SKIPPED, 0 FAILED

Selftest 'perf_branches' result on power9 machine which doesn't have branch
stack report:

 - After this patch:

  [command]# ./test_progs -t perf_branches
   #88/1 perf_branches/perf_branches_hw:SKIP
   #88/2 perf_branches/perf_branches_no_hw:OK
   #88 perf_branches:OK
  Summary: 1/1 PASSED, 1 SKIPPED, 0 FAILED

Fixes: fff7b64355eac ("bpf: Add bpf_read_branch_records() helper")
Suggested-by: Peter Zijlstra <peterz@infradead.org>
Change-Id: Ide9c32fdd0c825e46d7a9c6872d78122e4bb9b79
Signed-off-by: Kajol Jain <kjain@linux.ibm.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/bpf/20211206073315.77432-1-kjain@linux.ibm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-02-01 20:44:40 -08:00