Re: [PATCH bpf] bpf: fix wrong helper enablement in cgroup local storage
On Fri, Oct 26, 2018 at 10:57:18PM +, Roman Gushchin wrote: > On Sat, Oct 27, 2018 at 12:49:02AM +0200, Daniel Borkmann wrote: > > Commit cd3394317653 ("bpf: introduce the bpf_get_local_storage() > > helper function") enabled the bpf_get_local_storage() helper also > > for BPF program types where it does not make sense to use them. > > > > They have been added both in sk_skb_func_proto() and sk_msg_func_proto() > > even though both program types are not invoked in combination with > > cgroups, and neither through BPF_PROG_RUN_ARRAY(). In the latter the > > bpf_cgroup_storage_set() is set shortly before BPF program invocation. > > > > Later, the helper bpf_get_local_storage() retrieves this prior set > > up per-cpu pointer and hands the buffer to the BPF program. The map > > argument in there solely retrieves the enum bpf_cgroup_storage_type > > from a local storage map associated with the program and based on the > > type returns either the global or per-cpu storage. However, there > > is no specific association between the program's map and the actual > > content in bpf_cgroup_storage[]. > > > > Meaning, any BPF program that would have been properly run from the > > cgroup side through BPF_PROG_RUN_ARRAY() where bpf_cgroup_storage_set() > > was performed, and that is later unloaded such that prog / maps are > > teared down will cause a use after free if that pointer is retrieved > > from programs that are not run through BPF_PROG_RUN_ARRAY() but have > > the cgroup local storage helper enabled in their func proto. > > > > Lets just remove it from the two sock_map program types to fix it. > > Auditing through the types where this helper is enabled, it appears > > that these are the only ones where it was mistakenly allowed. > > > > Fixes: cd3394317653 ("bpf: introduce the bpf_get_local_storage() helper > > function") > > Signed-off-by: Daniel Borkmann > > Cc: Roman Gushchin > > Acked-by: John Fastabend > > > Acked-by: Roman Gushchin Applied, Thanks
Re: [PATCH bpf] bpf: fix wrong helper enablement in cgroup local storage
On Sat, Oct 27, 2018 at 12:49:02AM +0200, Daniel Borkmann wrote: > Commit cd3394317653 ("bpf: introduce the bpf_get_local_storage() > helper function") enabled the bpf_get_local_storage() helper also > for BPF program types where it does not make sense to use them. > > They have been added both in sk_skb_func_proto() and sk_msg_func_proto() > even though both program types are not invoked in combination with > cgroups, and neither through BPF_PROG_RUN_ARRAY(). In the latter the > bpf_cgroup_storage_set() is set shortly before BPF program invocation. > > Later, the helper bpf_get_local_storage() retrieves this prior set > up per-cpu pointer and hands the buffer to the BPF program. The map > argument in there solely retrieves the enum bpf_cgroup_storage_type > from a local storage map associated with the program and based on the > type returns either the global or per-cpu storage. However, there > is no specific association between the program's map and the actual > content in bpf_cgroup_storage[]. > > Meaning, any BPF program that would have been properly run from the > cgroup side through BPF_PROG_RUN_ARRAY() where bpf_cgroup_storage_set() > was performed, and that is later unloaded such that prog / maps are > teared down will cause a use after free if that pointer is retrieved > from programs that are not run through BPF_PROG_RUN_ARRAY() but have > the cgroup local storage helper enabled in their func proto. > > Lets just remove it from the two sock_map program types to fix it. > Auditing through the types where this helper is enabled, it appears > that these are the only ones where it was mistakenly allowed. > > Fixes: cd3394317653 ("bpf: introduce the bpf_get_local_storage() helper > function") > Signed-off-by: Daniel Borkmann > Cc: Roman Gushchin > Acked-by: John Fastabend Acked-by: Roman Gushchin Thanks, Daniel!
[PATCH bpf] bpf: fix wrong helper enablement in cgroup local storage
Commit cd3394317653 ("bpf: introduce the bpf_get_local_storage() helper function") enabled the bpf_get_local_storage() helper also for BPF program types where it does not make sense to use them. They have been added both in sk_skb_func_proto() and sk_msg_func_proto() even though both program types are not invoked in combination with cgroups, and neither through BPF_PROG_RUN_ARRAY(). In the latter the bpf_cgroup_storage_set() is set shortly before BPF program invocation. Later, the helper bpf_get_local_storage() retrieves this prior set up per-cpu pointer and hands the buffer to the BPF program. The map argument in there solely retrieves the enum bpf_cgroup_storage_type from a local storage map associated with the program and based on the type returns either the global or per-cpu storage. However, there is no specific association between the program's map and the actual content in bpf_cgroup_storage[]. Meaning, any BPF program that would have been properly run from the cgroup side through BPF_PROG_RUN_ARRAY() where bpf_cgroup_storage_set() was performed, and that is later unloaded such that prog / maps are teared down will cause a use after free if that pointer is retrieved from programs that are not run through BPF_PROG_RUN_ARRAY() but have the cgroup local storage helper enabled in their func proto. Lets just remove it from the two sock_map program types to fix it. Auditing through the types where this helper is enabled, it appears that these are the only ones where it was mistakenly allowed. Fixes: cd3394317653 ("bpf: introduce the bpf_get_local_storage() helper function") Signed-off-by: Daniel Borkmann Cc: Roman Gushchin Acked-by: John Fastabend --- net/core/filter.c | 4 1 file changed, 4 deletions(-) diff --git a/net/core/filter.c b/net/core/filter.c index 35c6933..4d7c511 100644 --- a/net/core/filter.c +++ b/net/core/filter.c @@ -5264,8 +5264,6 @@ sk_msg_func_proto(enum bpf_func_id func_id, const struct bpf_prog *prog) return _msg_pull_data_proto; case BPF_FUNC_msg_push_data: return _msg_push_data_proto; - case BPF_FUNC_get_local_storage: - return _get_local_storage_proto; default: return bpf_base_func_proto(func_id); } @@ -5296,8 +5294,6 @@ sk_skb_func_proto(enum bpf_func_id func_id, const struct bpf_prog *prog) return _sk_redirect_map_proto; case BPF_FUNC_sk_redirect_hash: return _sk_redirect_hash_proto; - case BPF_FUNC_get_local_storage: - return _get_local_storage_proto; #ifdef CONFIG_INET case BPF_FUNC_sk_lookup_tcp: return _sk_lookup_tcp_proto; -- 2.9.5