Received: by 2002:a05:6a10:206:0:0:0:0 with SMTP id 6csp4734188pxj; Wed, 9 Jun 2021 00:03:27 -0700 (PDT) X-Google-Smtp-Source: ABdhPJx288uHVuMh4aQ3QjSWqseY9grwQpWv0K79iTFd8NfgeDVte/2APN3C9R2YmQN/2/7HywrE X-Received: by 2002:a17:906:eca7:: with SMTP id qh7mr27761347ejb.143.1623222206788; Wed, 09 Jun 2021 00:03:26 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1623222206; cv=none; d=google.com; s=arc-20160816; b=N+cWNI2fPQowxYoc37dWJVnrAaSCbq1XC7rVTo0EUjZFJ/gZTQRId6QGuP723BLfBE EjifQ+MTCVakyGL6CbC4tzFqjyOO1m1ksjvLn5fnhSJHmcBhjljo+s/ZGMXmiXYaJ3Ng /n5tmsmRxQlPN/FuIW80PvPd9V5Tz0MviYGA5dwiJb7jxggRpwUGCMKe7m1WYE+PFSEw yjlpkPX9ZgBv5cmprpCD+PnV/82sDRCQdk5ecgXhAsdYJlyxoVJpxebDC6d+N1g+Zcv7 eszKVDeryEAS1lLSHKwPNxOstOTq0dX3Iy/YkKTXPUdHwY26wzh23PFWpJ0k/T7EU5u1 /biA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :user-agent:references:in-reply-to:message-id:date:subject:cc:to :from:dkim-signature; bh=CiGU1WGkdXqdyKaaV4ZkjfutY4QknrmdJ3gkYF79S0w=; b=L3HNRs/MB+s6ucn3NodlWbt78u72jn6sWrMNweVpq1f7ZYjfm8uN55CEPyZh4YNw09 vvnhj1J1A25JoAsUR+JLx7HTV7pvAJz91zLIuptDIuIhgrXHssvvQ7wwu/lc3RkRoZQ0 L+e6dkexqB1nsdR3TarAF7xWlchcnHiBQV/QqUsz3SxMOQKGxErBl/eJ+WKcWIfrfJGD 38ngknNwfeYfzKtQqbGcjupBAEJQTLXDa1tdSGrK/6ypijJxniGPITxM9zbKatu4MkHP ijQU33n4+5eC97IVq7e8Sc6gISeMhpcNECyPgNCMkPRBvzf407Ar2oanogD1t/SEQ/LL wnzA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@linuxfoundation.org header.s=korg header.b=Xw3W+8aj; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linuxfoundation.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id g21si1455433edw.335.2021.06.09.00.03.03; Wed, 09 Jun 2021 00:03:26 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@linuxfoundation.org header.s=korg header.b=Xw3W+8aj; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linuxfoundation.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S234645AbhFHShO (ORCPT + 99 others); Tue, 8 Jun 2021 14:37:14 -0400 Received: from mail.kernel.org ([198.145.29.99]:57600 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S234639AbhFHSfP (ORCPT ); Tue, 8 Jun 2021 14:35:15 -0400 Received: by mail.kernel.org (Postfix) with ESMTPSA id 4B3E2613CB; Tue, 8 Jun 2021 18:32:08 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1623177128; bh=DinYSjk+XniPqbHEC1wDQ/sUB7X9GxsBfF6ozuUjLbk=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=Xw3W+8ajaSTAdX8yxSlO4K963y4eZlM3bpZYZoFzXpEnlXwMhtKgbHU2ctPL038zC wMuP+HRpVgLXSn52E+Jd8imlrPYL+uHL+kgCOsoJD7t8ofVfLiSfvhBtbps43szIZS tlIJX3XJm4NlHZfCkLmyhOyJ5r+mWDilX5iCmlz4= From: Greg Kroah-Hartman To: linux-kernel@vger.kernel.org, stable@vger.kernel.org Cc: Greg Kroah-Hartman , Piotr Krysiuk , Daniel Borkmann , Alexei Starovoitov Subject: [PATCH 4.14 42/47] bpf: Fix mask direction swap upon off reg sign change Date: Tue, 8 Jun 2021 20:27:25 +0200 Message-Id: <20210608175931.863713046@linuxfoundation.org> X-Mailer: git-send-email 2.32.0 In-Reply-To: <20210608175930.477274100@linuxfoundation.org> References: <20210608175930.477274100@linuxfoundation.org> User-Agent: quilt/0.66 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Daniel Borkmann commit bb01a1bba579b4b1c5566af24d95f1767859771e upstream. Masking direction as indicated via mask_to_left is considered to be calculated once and then used to derive pointer limits. Thus, this needs to be placed into bpf_sanitize_info instead so we can pass it to sanitize_ptr_alu() call after the pointer move. Piotr noticed a corner case where the off reg causes masking direction change which then results in an incorrect final aux->alu_limit. Fixes: 7fedb63a8307 ("bpf: Tighten speculative pointer arithmetic mask") Reported-by: Piotr Krysiuk Signed-off-by: Daniel Borkmann Reviewed-by: Piotr Krysiuk Acked-by: Alexei Starovoitov Signed-off-by: Greg Kroah-Hartman --- kernel/bpf/verifier.c | 22 ++++++++++++---------- 1 file changed, 12 insertions(+), 10 deletions(-) --- a/kernel/bpf/verifier.c +++ b/kernel/bpf/verifier.c @@ -2033,18 +2033,10 @@ enum { }; static int retrieve_ptr_limit(const struct bpf_reg_state *ptr_reg, - const struct bpf_reg_state *off_reg, - u32 *alu_limit, u8 opcode) + u32 *alu_limit, bool mask_to_left) { - bool off_is_neg = off_reg->smin_value < 0; - bool mask_to_left = (opcode == BPF_ADD && off_is_neg) || - (opcode == BPF_SUB && !off_is_neg); u32 max = 0, ptr_limit = 0; - if (!tnum_is_const(off_reg->var_off) && - (off_reg->smin_value < 0) != (off_reg->smax_value < 0)) - return REASON_BOUNDS; - switch (ptr_reg->type) { case PTR_TO_STACK: /* Offset 0 is out-of-bounds, but acceptable start for the @@ -2112,6 +2104,7 @@ static bool sanitize_needed(u8 opcode) struct bpf_sanitize_info { struct bpf_insn_aux_data aux; + bool mask_to_left; }; static int sanitize_ptr_alu(struct bpf_verifier_env *env, @@ -2143,7 +2136,16 @@ static int sanitize_ptr_alu(struct bpf_v if (vstate->speculative) goto do_sim; - err = retrieve_ptr_limit(ptr_reg, off_reg, &alu_limit, opcode); + if (!commit_window) { + if (!tnum_is_const(off_reg->var_off) && + (off_reg->smin_value < 0) != (off_reg->smax_value < 0)) + return REASON_BOUNDS; + + info->mask_to_left = (opcode == BPF_ADD && off_is_neg) || + (opcode == BPF_SUB && !off_is_neg); + } + + err = retrieve_ptr_limit(ptr_reg, &alu_limit, info->mask_to_left); if (err < 0) return err;