提交 4f73379e 编写于 作者: A Alexei Starovoitov 提交者: Daniel Borkmann

bpf: verbose jump offset overflow check

Larger programs may trigger 16-bit jump offset overflow check
during instruction patching. Make this error verbose otherwise
users cannot decipher error code without printks in the verifier.
Signed-off-by: NAlexei Starovoitov <ast@kernel.org>
Signed-off-by: NDaniel Borkmann <daniel@iogearbox.net>
上级 71dde681
...@@ -438,6 +438,7 @@ struct bpf_prog *bpf_patch_insn_single(struct bpf_prog *prog, u32 off, ...@@ -438,6 +438,7 @@ struct bpf_prog *bpf_patch_insn_single(struct bpf_prog *prog, u32 off,
u32 insn_adj_cnt, insn_rest, insn_delta = len - 1; u32 insn_adj_cnt, insn_rest, insn_delta = len - 1;
const u32 cnt_max = S16_MAX; const u32 cnt_max = S16_MAX;
struct bpf_prog *prog_adj; struct bpf_prog *prog_adj;
int err;
/* Since our patchlet doesn't expand the image, we're done. */ /* Since our patchlet doesn't expand the image, we're done. */
if (insn_delta == 0) { if (insn_delta == 0) {
...@@ -453,8 +454,8 @@ struct bpf_prog *bpf_patch_insn_single(struct bpf_prog *prog, u32 off, ...@@ -453,8 +454,8 @@ struct bpf_prog *bpf_patch_insn_single(struct bpf_prog *prog, u32 off,
* we afterwards may not fail anymore. * we afterwards may not fail anymore.
*/ */
if (insn_adj_cnt > cnt_max && if (insn_adj_cnt > cnt_max &&
bpf_adj_branches(prog, off, off + 1, off + len, true)) (err = bpf_adj_branches(prog, off, off + 1, off + len, true)))
return NULL; return ERR_PTR(err);
/* Several new instructions need to be inserted. Make room /* Several new instructions need to be inserted. Make room
* for them. Likely, there's no need for a new allocation as * for them. Likely, there's no need for a new allocation as
...@@ -463,7 +464,7 @@ struct bpf_prog *bpf_patch_insn_single(struct bpf_prog *prog, u32 off, ...@@ -463,7 +464,7 @@ struct bpf_prog *bpf_patch_insn_single(struct bpf_prog *prog, u32 off,
prog_adj = bpf_prog_realloc(prog, bpf_prog_size(insn_adj_cnt), prog_adj = bpf_prog_realloc(prog, bpf_prog_size(insn_adj_cnt),
GFP_USER); GFP_USER);
if (!prog_adj) if (!prog_adj)
return NULL; return ERR_PTR(-ENOMEM);
prog_adj->len = insn_adj_cnt; prog_adj->len = insn_adj_cnt;
...@@ -1096,13 +1097,13 @@ struct bpf_prog *bpf_jit_blind_constants(struct bpf_prog *prog) ...@@ -1096,13 +1097,13 @@ struct bpf_prog *bpf_jit_blind_constants(struct bpf_prog *prog)
continue; continue;
tmp = bpf_patch_insn_single(clone, i, insn_buff, rewritten); tmp = bpf_patch_insn_single(clone, i, insn_buff, rewritten);
if (!tmp) { if (IS_ERR(tmp)) {
/* Patching may have repointed aux->prog during /* Patching may have repointed aux->prog during
* realloc from the original one, so we need to * realloc from the original one, so we need to
* fix it up here on error. * fix it up here on error.
*/ */
bpf_jit_prog_release_other(prog, clone); bpf_jit_prog_release_other(prog, clone);
return ERR_PTR(-ENOMEM); return tmp;
} }
clone = tmp; clone = tmp;
......
...@@ -6932,8 +6932,13 @@ static struct bpf_prog *bpf_patch_insn_data(struct bpf_verifier_env *env, u32 of ...@@ -6932,8 +6932,13 @@ static struct bpf_prog *bpf_patch_insn_data(struct bpf_verifier_env *env, u32 of
struct bpf_prog *new_prog; struct bpf_prog *new_prog;
new_prog = bpf_patch_insn_single(env->prog, off, patch, len); new_prog = bpf_patch_insn_single(env->prog, off, patch, len);
if (!new_prog) if (IS_ERR(new_prog)) {
if (PTR_ERR(new_prog) == -ERANGE)
verbose(env,
"insn %d cannot be patched due to 16-bit range\n",
env->insn_aux_data[off].orig_idx);
return NULL; return NULL;
}
if (adjust_insn_aux_data(env, new_prog->len, off, len)) if (adjust_insn_aux_data(env, new_prog->len, off, len))
return NULL; return NULL;
adjust_subprog_starts(env, off, len); adjust_subprog_starts(env, off, len);
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册