Ilya Leoshkevich
1fe038030c
bpf: Clear zext_dst of dead insns
...
[ Upstream commit 45c709f8c71b525b51988e782febe84ce933e7e0 ]
"access skb fields ok" verifier test fails on s390 with the "verifier
bug. zext_dst is set, but no reg is defined" message. The first insns
of the test prog are ...
0: 61 01 00 00 00 00 00 00 ldxw %r0,[%r1+0]
8: 35 00 00 01 00 00 00 00 jge %r0,0,1
10: 61 01 00 08 00 00 00 00 ldxw %r0,[%r1+8]
... and the 3rd one is dead (this does not look intentional to me, but
this is a separate topic).
sanitize_dead_code() converts dead insns into "ja -1", but keeps
zext_dst. When opt_subreg_zext_lo32_rnd_hi32() tries to parse such
an insn, it sees this discrepancy and bails. This problem can be seen
only with JITs whose bpf_jit_needs_zext() returns true.
Fix by clearning dead insns' zext_dst.
The commits that contributed to this problem are:
1. 5aa5bd14c5 ("bpf: add initial suite for selftests"), which
introduced the test with the dead code.
2. 5327ed3d44 ("bpf: verifier: mark verified-insn with
sub-register zext flag"), which introduced the zext_dst flag.
3. 83a2881903f3 ("bpf: Account for BPF_FETCH in
insn_has_def32()"), which introduced the sanity check.
4. 9183671af6db ("bpf: Fix leakage under speculation on
mispredicted branches"), which bisect points to.
It's best to fix this on stable branches that contain the second one,
since that's the point where the inconsistency was introduced.
Fixes: 5327ed3d44 ("bpf: verifier: mark verified-insn with sub-register zext flag")
Signed-off-by: Ilya Leoshkevich <iii@linux.ibm.com>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/bpf/20210812151811.184086-2-iii@linux.ibm.com
Signed-off-by: Sasha Levin <sashal@kernel.org>
2021-08-26 08:36:17 -04:00
..
bpf
bpf: Clear zext_dst of dead insns
2021-08-26 08:36:17 -04:00
cgroup
cgroup1: fix leaked context root causing sporadic NULL deref in LTP
2021-07-31 08:19:37 +02:00
configs
debug
kdb: Make memory allocations more robust
2021-03-04 10:26:10 +01:00
dma
swiotlb: fix "x86: Don't panic if can not alloc buffer for swiotlb"
2020-11-18 19:20:32 +01:00
events
perf: Fix data race between pin_count increment/decrement
2021-06-16 11:59:44 +02:00
gcov
gcov: re-fix clang-11+ support
2021-04-14 08:24:10 +02:00
irq
genirq/timings: Prevent potential array overflow in __irq_timings_store()
2021-08-18 08:57:02 +02:00
livepatch
locking
lockding/lockdep: Avoid to find wrong lock dep path in check_irq_usage()
2021-07-14 16:53:15 +02:00
power
PM: EM: postpone creating the debugfs dir till fs_initcall
2021-03-30 14:35:28 +02:00
printk
printk: fix deadlock when kernel panic
2021-03-04 10:26:50 +01:00
rcu
srcu: Fix broken node geometry after early ssp init
2021-07-20 16:10:41 +02:00
sched
sched/fair: Fix CFS bandwidth hrtimer expiry type
2021-07-25 14:35:13 +02:00
time
timers: Move clearing of base::timer_running under base:: Lock
2021-08-12 13:21:03 +02:00
trace
tracing: Reject string operand in the histogram expression
2021-08-15 13:08:02 +02:00
.gitignore
kbuild: update config_data.gz only when the content of .config is changed
2021-05-11 14:04:16 +02:00
acct.c
async.c
audit.c
audit: fix a net reference leak in audit_list_rules_send()
2020-06-22 09:30:59 +02:00
audit.h
audit: fix a net reference leak in audit_list_rules_send()
2020-06-22 09:30:59 +02:00
audit_fsnotify.c
audit_tree.c
audit_watch.c
audit: CONFIG_CHANGE don't log internal bookkeeping as an event
2020-10-01 13:17:32 +02:00
auditfilter.c
audit: fix a net reference leak in audit_list_rules_send()
2020-06-22 09:30:59 +02:00
auditsc.c
backtracetest.c
bounds.c
capability.c
compat.c
configs.c
context_tracking.c
cpu.c
cpu/hotplug: Cure the cpusets trainwreck
2021-07-19 08:53:15 +02:00
cpu_pm.c
kernel/cpu_pm: Fix uninitted local in cpu_pm
2020-06-22 09:31:22 +02:00
crash_core.c
crash_dump.c
cred.c
keys: Fix request_key() cache
2020-01-17 19:48:42 +01:00
delayacct.c
dma.c
exec_domain.c
exit.c
don't dump the threads that had been already exiting when zapped.
2020-11-18 19:20:31 +01:00
extable.c
fail_function.c
fail_function: Remove a redundant mutex unlock
2020-11-24 13:29:18 +01:00
fork.c
exec: Transform exec_update_mutex into a rw_semaphore
2021-01-09 13:44:55 +01:00
freezer.c
futex.c
mm, futex: fix shared futex pgoff on shmem huge page
2021-06-30 08:47:55 -04:00
gen_kheaders.sh
kbuild: add variables for compression tools
2020-09-03 11:27:10 +02:00
groups.c
hung_task.c
iomem.c
irq_work.c
jump_label.c
kallsyms.c
kallsyms: Refactor kallsyms_show_value() to take cred
2020-07-16 08:16:44 +02:00
kcmp.c
exec: Transform exec_update_mutex into a rw_semaphore
2021-01-09 13:44:55 +01:00
Kconfig.freezer
Kconfig.hz
Kconfig.locks
Kconfig.preempt
kcov.c
kexec.c
kexec_core.c
kernel: kexec: remove the lock operation of system_transition_mutex
2021-02-03 23:25:56 +01:00
kexec_elf.c
kexec_file.c
kernel: kexec_file: fix error return code of kexec_calculate_store_digests()
2021-05-19 10:08:28 +02:00
kexec_internal.h
kheaders.c
kmod.c
kmod: make request_module() return an error when autoloading is disabled
2020-04-17 10:50:22 +02:00
kprobes.c
tracing/kprobe: Fix to support kretprobe events on unloaded modules
2021-02-13 13:52:54 +01:00
ksysfs.c
kthread.c
kthread_worker: fix return value when kthread_mod_delayed_work() races with kthread_cancel_delayed_work_sync()
2021-07-14 16:53:19 +02:00
latencytop.c
Makefile
kbuild: update config_data.gz only when the content of .config is changed
2021-05-11 14:04:16 +02:00
module-internal.h
module.c
module: limit enabling module.sig_enforce
2021-06-30 08:47:42 -04:00
module_signature.c
module: harden ELF info handling
2021-04-07 14:47:38 +02:00
module_signing.c
module: harden ELF info handling
2021-04-07 14:47:38 +02:00
notifier.c
kernel/notifier.c: intercept duplicate registrations to avoid infinite loops
2020-10-01 13:17:23 +02:00
nsproxy.c
padata.c
padata: add separate cpuhp node for CPUHP_PADATA_DEAD
2020-06-17 16:40:22 +02:00
panic.c
params.c
pid.c
pid_namespace.c
profile.c
ptrace.c
ptrace: make ptrace() fail if the tracee changed its pid unexpectedly
2021-05-26 12:05:15 +02:00
range.c
reboot.c
reboot: fix overflow parsing reboot cpu number
2020-11-18 19:20:30 +01:00
relay.c
kernel/relay.c: fix memleak on destroy relay channel
2020-08-26 10:40:51 +02:00
resource.c
/dev/mem: Revoke mappings when a driver claims the region
2020-06-24 17:50:35 +02:00
rseq.c
seccomp.c
seccomp: Add missing return in non-void function
2021-03-04 10:26:45 +01:00
signal.c
ptrace: fix task_join_group_stop() for the case when current is traced
2020-11-10 12:37:24 +01:00
smp.c
smp: Fix smp_call_function_single_async prototype
2021-05-14 09:44:33 +02:00
smpboot.c
kthread: Extract KTHREAD_IS_PER_CPU
2021-02-07 15:35:49 +01:00
smpboot.h
softirq.c
stackleak.c
stacktrace.c
stop_machine.c
sys.c
kernel/sys.c: avoid copying possible padding bytes in copy_to_user
2020-10-01 13:17:23 +02:00
sys_ni.c
sysctl-test.c
kernel/sysctl-test: Add null pointer test for sysctl.c:proc_dointvec()
2020-10-01 13:17:10 +02:00
sysctl.c
sysctl.c: fix underflow value setting risk in vm_table
2021-03-17 17:03:45 +01:00
sysctl_binary.c
task_work.c
taskstats.c
taskstats: fix data-race
2020-01-09 10:19:54 +01:00
test_kprobes.c
torture.c
tracepoint.c
tracepoint: Add tracepoint_probe_register_may_exist() for BPF tracing
2021-07-14 16:53:08 +02:00
tsacct.c
ucount.c
uid16.c
uid16.h
umh.c
usermodehelper: reset umask to default before executing user process
2020-10-14 10:32:58 +02:00
up.c
smp: Fix smp_call_function_single_async prototype
2021-05-14 09:44:33 +02:00
user-return-notifier.c
user.c
user_namespace.c
utsname.c
utsname_sysctl.c
watchdog.c
watchdog/softlockup: Enforce that timestamp is valid on boot
2020-02-24 08:36:52 +01:00
watchdog_hld.c
workqueue.c
workqueue: fix UAF in pwq_unbound_release_workfn()
2021-07-31 08:19:37 +02:00
workqueue_internal.h