bpf_arena_free_pages() can be called with a scalar arena address. The
runtime reconstructs a full user address from the arena base and the low
32 bits before returning the range to the arena free tree. A scalar one
page below the arena base can otherwise produce an out-of-domain free-tree
offset and make a later allocation return an address below the arena
mapping.

Patch 1 rejects frees whose reconstructed full user address is below
user_vm_start. Patch 2 adds verifier_arena coverage for the
scalar-below-base case.

Changes in v2:
- Add Reviewed-by tags from Emil Tsalapatis.
- Remove the empty inline asm from the selftest.

v1: 
https://lore.kernel.org/bpf/[email protected]/

Yiyang Chen (2):
  bpf: Reject arena frees below the arena base
  selftests/bpf: Cover scalar arena frees below the base

 kernel/bpf/arena.c                                 |  2 ++
 tools/testing/selftests/bpf/progs/verifier_arena.c | 40 +++++++++++++++++++---
 2 files changed, 37 insertions(+), 5 deletions(-)

base-commit: 1d91ea01185656ac3ee63c5f9f6f8bde3c746b3d
-- 
2.34.1


Reply via email to