aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorHou Tao <houtao1@huawei.com>2022-03-09 20:33:18 +0800
committerAlexei Starovoitov <ast@kernel.org>2022-03-16 15:12:18 -0700
commit73e14451f39e54f83ea3badb6d6b8a423f901845 (patch)
tree137bebfa791a5058aa800f7a4a6d7b9081bbe6d0
parentMerge branch 'Remove libcap dependency from bpf selftests' (diff)
downloadlinux-dev-73e14451f39e54f83ea3badb6d6b8a423f901845.tar.xz
linux-dev-73e14451f39e54f83ea3badb6d6b8a423f901845.zip
bpf, x86: Fall back to interpreter mode when extra pass fails
Extra pass for subprog jit may fail (e.g. due to bpf_jit_harden race), but bpf_func is not cleared for the subprog and jit_subprogs will succeed. The running of the bpf program may lead to oops because the memory for the jited subprog image has already been freed. So fall back to interpreter mode by clearing bpf_func/jited/jited_len when extra pass fails. Signed-off-by: Hou Tao <houtao1@huawei.com> Signed-off-by: Alexei Starovoitov <ast@kernel.org> Link: https://lore.kernel.org/bpf/20220309123321.2400262-2-houtao1@huawei.com
-rw-r--r--arch/x86/net/bpf_jit_comp.c11
1 files changed, 9 insertions, 2 deletions
diff --git a/arch/x86/net/bpf_jit_comp.c b/arch/x86/net/bpf_jit_comp.c
index e6ff8f4f9ea4..ec3f00be2ac5 100644
--- a/arch/x86/net/bpf_jit_comp.c
+++ b/arch/x86/net/bpf_jit_comp.c
@@ -2335,7 +2335,13 @@ out_image:
sizeof(rw_header->size));
bpf_jit_binary_pack_free(header, rw_header);
}
+ /* Fall back to interpreter mode */
prog = orig_prog;
+ if (extra_pass) {
+ prog->bpf_func = NULL;
+ prog->jited = 0;
+ prog->jited_len = 0;
+ }
goto out_addrs;
}
if (image) {
@@ -2384,8 +2390,9 @@ out_image:
* Both cases are serious bugs and justify WARN_ON.
*/
if (WARN_ON(bpf_jit_binary_pack_finalize(prog, header, rw_header))) {
- prog = orig_prog;
- goto out_addrs;
+ /* header has been freed */
+ header = NULL;
+ goto out_image;
}
bpf_tail_call_direct_fixup(prog);