Atomic RMW verification records an instruction pointer type only when the
current destination is PTR_TO_ARENA. A second path can therefore reach the
same instruction with an ordinary pointer without comparing it against the
saved arena type.

The post-verification fixup uses the saved type to rewrite the instruction
to BPF_PROBE_ATOMIC for every path. Record the actual destination type for
all atomic RMW paths so the existing mismatch check rejects incompatible
uses of one instruction.

Fixes: d503a04f8bc0 ("bpf: Add support for certain atomics in bpf_arena to x86 
JIT")
Signed-off-by: Yiyang Chen <[email protected]>
---
 kernel/bpf/verifier.c | 8 +++-----
 1 file changed, 3 insertions(+), 5 deletions(-)

diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
index 164d16c243ca6..3d672f6665bec 100644
--- a/kernel/bpf/verifier.c
+++ b/kernel/bpf/verifier.c
@@ -6509,11 +6509,9 @@ static int check_atomic_rmw(struct bpf_verifier_env *env,
        if (err)
                return err;
 
-       if (is_arena_reg(env, insn->dst_reg)) {
-               err = save_aux_ptr_type(env, PTR_TO_ARENA, false);
-               if (err)
-                       return err;
-       }
+       err = save_aux_ptr_type(env, dst_reg->type, false);
+       if (err)
+               return err;
        /* Check whether we can write into the same memory. */
        err = check_mem_access(env, env->insn_idx, dst_reg, 
argno_from_reg(insn->dst_reg), insn->off,
                               BPF_SIZE(insn->code), BPF_WRITE, -1, true, 
false);

-- 
2.43.0


Reply via email to