fprobe_fgraph_entry() sizes a shadow-stack reservation in one walk of
the per-ip fprobe list and fills it in a second walk, both under
rcu_read_lock() only. A fprobe registered on an already-live ip can
become visible between the two walks, so the fill walk processes an
exit_handler the sizing walk did not count and used runs past
reserved_words. If the sizing walk counted nothing, fgraph_data is NULL
and the first write_fprobe_header() faults:

  Oops: general protection fault, probably for non-canonical address ...
  KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
  RIP: 0010:fprobe_fgraph_entry+0xa38/0xf10 kernel/trace/fprobe.c:167
  Call Trace:
   <TASK>
   function_graph_enter_regs+0x44c/0xa10 kernel/trace/fgraph.c:677
   ftrace_graph_func+0xc5/0x140 arch/x86/kernel/ftrace.c:671
   __kernel_text_address+0x9/0x40 kernel/extable.c:78
   arch_stack_walk+0x117/0x170 arch/x86/kernel/stacktrace.c:26
   kmem_cache_free+0x188/0x580 mm/slub.c:6378
   tcp_data_queue+0x18d/0x6550 net/ipv4/tcp_input.c:5590
   [...]
   </TASK>

The list cannot be frozen across the two walks, so skip a node that does
not fit the reservation and count it as missed.

Fixes: 4346ba160409 ("fprobe: Rewrite fprobe on function-graph tracer")
Signed-off-by: Sechang Lim <[email protected]>
---
 kernel/trace/fprobe.c | 10 ++++++++++
 1 file changed, 10 insertions(+)

diff --git a/kernel/trace/fprobe.c b/kernel/trace/fprobe.c
index f378613ad120..f215990b9061 100644
--- a/kernel/trace/fprobe.c
+++ b/kernel/trace/fprobe.c
@@ -613,6 +613,16 @@ static int fprobe_fgraph_entry(struct ftrace_graph_ent 
*trace, struct fgraph_ops
                        continue;
 
                data_size = fp->entry_data_size;
+               /*
+                * The list may have grown since it was sized, so this node
+                * may not fit. Skip it as missed rather than overrun the
+                * reservation.
+                */
+               if (fp->exit_handler &&
+                   used + FPROBE_HEADER_SIZE_IN_LONG + SIZE_IN_LONG(data_size) 
> reserved_words) {
+                       fp->nmissed++;
+                       continue;
+               }
                if (data_size && fp->exit_handler)
                        data = fgraph_data + used + FPROBE_HEADER_SIZE_IN_LONG;
                else
-- 
2.43.0


Reply via email to