android_kernel_motorola_sm6375/kernel
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Eduard Zingerman fb192cfda9
BACKPORT: bpf: Allow reads from uninit stack
commit 6715df8d5d24655b9fd368e904028112b54c7de1 upstream.

This commits updates the following functions to allow reads from
uninitialized stack locations when env->allow_uninit_stack option is
enabled:
- check_stack_read_fixed_off()
- check_stack_range_initialized(), called from:
  - check_stack_read_var_off()
  - check_helper_mem_access()

Such change allows to relax logic in stacksafe() to treat STACK_MISC
and STACK_INVALID in a same way and make the following stack slot
configurations equivalent:

  |  Cached state    |  Current state   |
  |   stack slot     |   stack slot     |
  |------------------+------------------|
  | STACK_INVALID or | STACK_INVALID or |
  | STACK_MISC       | STACK_SPILL   or |
  |                  | STACK_MISC    or |
  |                  | STACK_ZERO    or |
  |                  | STACK_DYNPTR     |

This leads to significant verification speed gains (see below).

The idea was suggested by Andrii Nakryiko [1] and initial patch was
created by Alexei Starovoitov [2].

Currently the env->allow_uninit_stack is allowed for programs loaded
by users with CAP_PERFMON or CAP_SYS_ADMIN capabilities.

A number of test cases from verifier/*.c were expecting uninitialized
stack access to be an error. These test cases were updated to execute
in unprivileged mode (thus preserving the tests).

The test progs/test_global_func10.c expected "invalid indirect read
from stack" error message because of the access to uninitialized
memory region. This error is no longer possible in privileged mode.
The test is updated to provoke an error "invalid indirect access to
stack" because of access to invalid stack address (such error is not
verified by progs/test_global_func*.c series of tests).

The following tests had to be removed because these can't be made
unprivileged:
- verifier/sock.c:
  - "sk_storage_get(map, skb->sk, &stack_value, 1): partially init
  stack_value"
  BPF_PROG_TYPE_SCHED_CLS programs are not executed in unprivileged mode.
- verifier/var_off.c:
  - "indirect variable-offset stack access, max_off+size > max_initialized"
  - "indirect variable-offset stack access, uninitialized"
  These tests verify that access to uninitialized stack values is
  detected when stack offset is not a constant. However, variable
  stack access is prohibited in unprivileged mode, thus these tests
  are no longer valid.

 * * *

Here is veristat log comparing this patch with current master on a
set of selftest binaries listed in tools/testing/selftests/bpf/veristat.cfg
and cilium BPF binaries (see [3]):

$ ./veristat -e file,prog,states -C -f 'states_pct<-30' master.log current.log
File                        Program                     States (A)  States (B)  States    (DIFF)
--------------------------  --------------------------  ----------  ----------  ----------------
bpf_host.o                  tail_handle_ipv6_from_host         349         244    -105 (-30.09%)
bpf_host.o                  tail_handle_nat_fwd_ipv4          1320         895    -425 (-32.20%)
bpf_lxc.o                   tail_handle_nat_fwd_ipv4          1320         895    -425 (-32.20%)
bpf_sock.o                  cil_sock4_connect                   70          48     -22 (-31.43%)
bpf_sock.o                  cil_sock4_sendmsg                   68          46     -22 (-32.35%)
bpf_xdp.o                   tail_handle_nat_fwd_ipv4          1554         803    -751 (-48.33%)
bpf_xdp.o                   tail_lb_ipv4                      6457        2473   -3984 (-61.70%)
bpf_xdp.o                   tail_lb_ipv6                      7249        3908   -3341 (-46.09%)
pyperf600_bpf_loop.bpf.o    on_event                           287         145    -142 (-49.48%)
strobemeta.bpf.o            on_event                         15915        4772  -11143 (-70.02%)
strobemeta_nounroll2.bpf.o  on_event                         17087        3820  -13267 (-77.64%)
xdp_synproxy_kern.bpf.o     syncookie_tc                     21271        6635  -14636 (-68.81%)
xdp_synproxy_kern.bpf.o     syncookie_xdp                    23122        6024  -17098 (-73.95%)
--------------------------  --------------------------  ----------  ----------  ----------------

Note: I limited selection by states_pct<-30%.

Inspection of differences in pyperf600_bpf_loop behavior shows that
the following patch for the test removes almost all differences:

    - a/tools/testing/selftests/bpf/progs/pyperf.h
    + b/tools/testing/selftests/bpf/progs/pyperf.h
    @ -266,8 +266,8 @ int __on_event(struct bpf_raw_tracepoint_args *ctx)
            }

            if (event->pthread_match || !pidData->use_tls) {
    -               void* frame_ptr;
    -               FrameData frame;
    +               void* frame_ptr = 0;
    +               FrameData frame = {};
                    Symbol sym = {};
                    int cur_cpu = bpf_get_smp_processor_id();

W/o this patch the difference comes from the following pattern
(for different variables):

    static bool get_frame_data(... FrameData *frame ...)
    {
        ...
        bpf_probe_read_user(&frame->f_code, ...);
        if (!frame->f_code)
            return false;
        ...
        bpf_probe_read_user(&frame->co_name, ...);
        if (frame->co_name)
            ...;
    }

    int __on_event(struct bpf_raw_tracepoint_args *ctx)
    {
        FrameData frame;
        ...
        get_frame_data(... &frame ...) // indirectly via a bpf_loop & callback
        ...
    }

    SEC("raw_tracepoint/kfree_skb")
    int on_event(struct bpf_raw_tracepoint_args* ctx)
    {
        ...
        ret |= __on_event(ctx);
        ret |= __on_event(ctx);
        ...
    }

With regards to value `frame->co_name` the following is important:
- Because of the conditional `if (!frame->f_code)` each call to
  __on_event() produces two states, one with `frame->co_name` marked
  as STACK_MISC, another with it as is (and marked STACK_INVALID on a
  first call).
- The call to bpf_probe_read_user() does not mark stack slots
  corresponding to `&frame->co_name` as REG_LIVE_WRITTEN but it marks
  these slots as BPF_MISC, this happens because of the following loop
  in the check_helper_call():

	for (i = 0; i < meta.access_size; i++) {
		err = check_mem_access(env, insn_idx, meta.regno, i, BPF_B,
				       BPF_WRITE, -1, false);
		if (err)
			return err;
	}

  Note the size of the write, it is a one byte write for each byte
  touched by a helper. The BPF_B write does not lead to write marks
  for the target stack slot.
- Which means that w/o this patch when second __on_event() call is
  verified `if (frame->co_name)` will propagate read marks first to a
  stack slot with STACK_MISC marks and second to a stack slot with
  STACK_INVALID marks and these states would be considered different.

[1] https://lore.kernel.org/bpf/CAEf4BzY3e+ZuC6HUa8dCiUovQRg2SzEk7M-dSkqNZyn=xEmnPA@mail.gmail.com/
[2] https://lore.kernel.org/bpf/CAADnVQKs2i1iuZ5SUGuJtxWVfGYR9kDgYKhq3rNV+kBLQCu7rA@mail.gmail.com/
[3] git@github.com:anakryiko/cilium.git

Suggested-by: Andrii Nakryiko <andrii@kernel.org>
Co-developed-by: Alexei Starovoitov <ast@kernel.org>
Change-Id: I80629cd663a28da7499da586c34adb97417233bb
Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
Acked-by: Andrii Nakryiko <andrii@kernel.org>
Link: https://lore.kernel.org/r/20230219200427.606541-2-eddyz87@gmail.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Maxim Mikityanskiy <maxim@isovalent.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2026-01-14 18:13:10 -08:00
..
bpf BACKPORT: bpf: Allow reads from uninit stack 2026-01-14 18:13:10 -08:00
cgroup UPSTREAM: bpf: Refactor bpf_link update handling 2025-12-23 13:36:15 -08:00
configs
debug kdb: Use the passed prompt in kdb_position_cursor() 2024-08-19 05:33:40 +02:00
dma Merge tag 'ASB-2024-10-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina 2024-10-09 18:08:17 +00:00
events UPSTREAM: bpf: Fail PERF_EVENT_IOC_SET_BPF when bpf_get_[stack|stackid] cannot work 2026-01-14 18:12:08 -08:00
gcov gcov: add support for GCC 15 2025-12-03 12:45:19 +01:00
irq Merge branch 'android11-5.4-lts' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina 2025-10-08 15:23:13 +03:00
livepatch UPSTREAM: ftrace: Introduce PERMANENT ftrace_ops flag 2025-12-23 13:35:45 -08:00
locking Merge tag 'ASB-2025-06-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina 2025-06-30 10:49:17 +03:00
power Merge tag 'ASB-2025-10-06_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina 2025-10-08 15:17:54 +03:00
printk BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
rcu UPSTREAM: rcu-tasks: Add an RCU Tasks Trace to simplify protection of tracing hooks 2026-01-14 18:12:26 -08:00
sched BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
time BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
trace UPSTREAM: bpf: rework the compat kernel probe handling 2026-01-14 18:12:55 -08:00
.gitignore
acct.c acct: perform last write from workqueue 2025-03-13 12:43:26 +01:00
async.c treewide: Remove uninitialized_var() usage 2023-06-09 10:29:01 +02:00
audit.c audit: Send netlink ACK before setting connection in auditd_set 2024-02-23 08:24:54 +01:00
audit.h audit: log AUDIT_TIME_* records only from rules 2022-04-15 14:18:04 +02:00
audit_fsnotify.c audit: fix potential double free on error path from fsnotify_add_inode_mark 2022-09-05 10:27:38 +02:00
audit_tree.c
audit_watch.c audit: don't WARN_ON_ONCE(!current->mm) in audit_exe_compare() 2023-11-28 16:50:18 +00:00
auditfilter.c
auditsc.c audit: fix possible soft lockup in __audit_inode_child() 2023-09-23 10:59:46 +02:00
backtracetest.c treewide: Replace DECLARE_TASKLET() with DECLARE_TASKLET_OLD() 2023-04-20 12:07:32 +02:00
bounds.c bounds: Use the right number of bits for power-of-two CONFIG_NR_CPUS 2024-05-02 16:18:37 +02:00
capability.c
cfi.c
compat.c sched_getaffinity: don't assume 'cpumask_size()' is fully initialized 2023-04-05 11:16:42 +02:00
configs.c
context_tracking.c
cpu.c hrtimers: Handle CPU state correctly on hotplug 2025-02-01 18:18:51 +01:00
cpu_pm.c
crash_core.c
crash_dump.c
cred.c Revert "cred: switch to using atomic_long_t" 2024-01-03 17:00:08 +00:00
delayacct.c
dma.c
exec_domain.c
exit.c UPSTREAM: umd: Track user space drivers with struct pid 2026-01-14 18:12:15 -08:00
extable.c UPSTREAM: bpf: Remove bpf_image tree 2025-12-23 13:36:07 -08:00
fail_function.c kernel/fail_function: fix memory leak with using debugfs_lookup() 2023-03-11 16:44:15 +01:00
fork.c UPSTREAM: rcu-tasks: Add an RCU Tasks Trace to simplify protection of tracing hooks 2026-01-14 18:12:26 -08:00
freezer.c
futex.c Merge 5.4.246 into android11-5.4-lts 2023-06-20 19:13:58 +00:00
gen_kheaders.sh Merge tag 'ASB-2025-03-05_11-5.4' into android13-5.4-lahaina 2025-04-12 09:31:28 +00:00
groups.c BACKPORT: mm: remove the pgprot argument to __vmalloc 2026-01-14 17:48:09 -08:00
hung_task.c
iomem.c
irq_work.c UPSTREAM: irq_work: Convert flags to atomic_t 2025-12-23 13:35:39 -08:00
jump_label.c
kallsyms.c
kcmp.c
Kconfig.freezer
Kconfig.hz
Kconfig.locks
Kconfig.preempt
kcov.c
kexec.c
kexec_core.c kexec: fix a memory leak in crash_shrink_memory() 2023-07-27 08:37:10 +02:00
kexec_elf.c kexec: initialize ELF lowest address to ULONG_MAX 2025-04-10 14:29:41 +02:00
kexec_file.c kexec: support purgatories with .text.hot sections 2023-06-21 15:44:10 +02:00
kexec_internal.h
kheaders.c kheaders: Use array declaration instead of char 2023-05-17 11:35:33 +02:00
kmod.c
kprobes.c BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
ksysfs.c
kthread.c This is the 5.4.285 stable release 2024-11-09 11:29:17 +00:00
latencytop.c BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
Makefile UPSTREAM: bpf: Add kernel module with user mode driver that populates bpffs. 2026-01-14 18:12:16 -08:00
module-internal.h
module.c BACKPORT: mm: remove the pgprot argument to __vmalloc 2026-01-14 17:48:09 -08:00
module_signature.c
module_signing.c
notifier.c
nsproxy.c
padata.c padata: Reset next CPU when reorder sequence wraps around 2025-10-29 14:00:01 +01:00
panic.c panic: Flush kernel log buffer at the end 2024-04-13 12:51:37 +02:00
params.c module: ensure that kobject_put() is safe for module type kobjects 2025-06-04 14:32:27 +02:00
pid.c Merge tag 'ASB-2025-12-01_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina 2025-12-04 19:21:35 +02:00
pid_namespace.c BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
profile.c profiling: fix shift too large makes kernel panic 2022-08-25 11:18:02 +02:00
ptrace.c ptrace: Reimplement PTRACE_KILL by always sending SIGKILL 2022-06-14 18:11:24 +02:00
range.c
reboot.c This is the 5.4.262 stable release 2023-11-29 10:18:14 +00:00
relay.c relayfs: fix out-of-bounds access in relay_file_read 2023-05-17 11:35:58 +02:00
resource.c resource: fix region_intersects() vs add_memory_driver_managed() 2024-11-08 16:20:46 +01:00
rseq.c
scs.c
seccomp.c BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
signal.c Merge tag 'ASB-2024-12-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina 2024-12-17 03:24:53 +02:00
smp.c Merge tag 'ASB-2024-11-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina 2024-11-08 15:36:32 +00:00
smpboot.c
smpboot.h
softirq.c Revert "tasklet: Introduce new initialization API" 2025-03-13 17:21:46 +00:00
stackleak.c
stacktrace.c
stop_machine.c
sys.c Merge 5.4.272 into android11-5.4-lts 2024-04-05 12:37:33 +00:00
sys_ni.c BACKPORT: epoll: wire up syscall epoll_pwait2 2025-12-22 07:42:50 +02:00
sysctl-test.c
sysctl.c BACKPORT: bpf: Sharing bpf runtime stats with BPF_ENABLE_STATS 2025-12-23 13:36:17 -08:00
sysctl_binary.c
task_work.c
taskstats.c
test_kprobes.c
torture.c
tracepoint.c UPSTREAM: module: Fix up module_notifier return values 2026-01-14 18:12:53 -08:00
tsacct.c taskstats: Cleanup the use of task->exit_code 2022-02-23 11:59:57 +01:00
ucount.c
uid16.c
uid16.h
umh.c BACKPORT: umh: Separate the user mode driver and the user mode helper support 2026-01-14 18:12:14 -08:00
up.c
user-return-notifier.c
user.c
user_namespace.c
usermode_driver.c UPSTREAM: bpf: Fix umd memory leak in copy_process() 2026-01-14 18:12:50 -08:00
utsname.c
utsname_sysctl.c BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
watchdog.c BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
watchdog_hld.c watchdog/perf: properly initialize the turbo mode timestamp and rearm counter 2024-08-19 05:33:39 +02:00
workqueue.c Merge android11-5.4.259+ (81334f2) into msm-5.4 2023-12-18 15:40:18 +05:30
workqueue_internal.h