Received: by 2002:a05:6a10:5bc5:0:0:0:0 with SMTP id os5csp1520502pxb; Tue, 26 Oct 2021 10:29:15 -0700 (PDT) X-Google-Smtp-Source: ABdhPJwQjHyN6m2vH5SOOX8PAg0nIqq7z09ey/Oh8l/5x+o11pqOSArR0RCrPbq+1DHHLBKvFRac X-Received: by 2002:a05:6402:1499:: with SMTP id e25mr17713899edv.263.1635269355336; Tue, 26 Oct 2021 10:29:15 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1635269355; cv=none; d=google.com; s=arc-20160816; b=yNAqflDIBlBE6psZK5ILPhoiydAy3bBR90Etgdzg7TFaPhOS6y18rjhjax+VrEBECp UmMgBhZlwD9KvZY+Hkp1UWH0m+PeLRa08phsYdEB8dDa+IczqWncP586/eDeA2rBSWxR S3dsfHxZ0B/kIpcj+7mBgGjG/snwAeHak0OjQo72M0bmm9QX5X9Owibhwi0W8jFCfwrZ JGjEkvsl52SVs1nJyIKuYzRI+RU6aW06aAfC6x5yE2HgpCgX80cIfGMP9FJap0sYtVsU YZopGBEMRTgOWm9yjYtanQ7YHPaGms4u8gBqlBu6mk8n+KUMyRknu/cQd3GMKkJECsgr tDUw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:dkim-signature; bh=jiKBRIJ90WYjcORFiV3ORltYZSK2q2sAgdSrdSfFfbc=; b=f40/o3Zy3YVv5LkxPRAhEF7/9KiDD64fZlJoInm08Bc+xAVGPZRD70jBBaebBDdog/ xLawwUoQA+L3Xx2zvc/hPEnBPtEtxRZZGSdrMnvaPoM2Fk0OPvHv8vyZwLooqkqjHJHO ZQDf7HjERu8+4EH+pzxwIO/a/GLvNwKpPbsvrqiKSi880Pz0CpINPXGJf434DoUENAZt cQeX4sHV9WUpHe8LM70TVUc8uAiSoKzURJvbOwdTaBBBfyaL+ZLmTk8jYk3WQl66KXgS BK8n6w6qjnQK01sEkHvDSFjNcLykzbGVTrQhEq1+zIEEAJL1LsTlfrSA62P3ygHw7tpb 1zEg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20210112 header.b="B5oi/7UC"; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id y4si7528471eda.23.2021.10.26.10.28.50; Tue, 26 Oct 2021 10:29:15 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20210112 header.b="B5oi/7UC"; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S236298AbhJZOFj (ORCPT + 99 others); Tue, 26 Oct 2021 10:05:39 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:49176 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S230119AbhJZOFg (ORCPT ); Tue, 26 Oct 2021 10:05:36 -0400 Received: from mail-io1-xd29.google.com (mail-io1-xd29.google.com [IPv6:2607:f8b0:4864:20::d29]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id BE0E2C061745; Tue, 26 Oct 2021 07:03:12 -0700 (PDT) Received: by mail-io1-xd29.google.com with SMTP id y67so20530792iof.10; Tue, 26 Oct 2021 07:03:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=jiKBRIJ90WYjcORFiV3ORltYZSK2q2sAgdSrdSfFfbc=; b=B5oi/7UCVk36Kltqk5jv0UWKsgnlcJbT+p8jfJZ/39b+wWQ3ihMQCSae2vo2AfNYOV rGFEUlC++DoWLCCqPMJWHJOt1HSJyZFJtvVv49eAiawK7btNdoGSa1NDCwrmtXk1QKNU vSBGb2llMudk+OZOc4MAqtj9ZyDt/GRG5Xmh0lZMLJUQfXLqcWmfnbKyPUvZsUevSp7r Uav5pLsgxuo7NBSBiLlXImmOZ8jx2FcsOPxBS44VwbmHXKYUQ4BPjNlZX9zlsc+Tru3f yRRWGvhcXHKmK3hoxpjQGpduRdkJH6Mb3jiEyDSm0HHk/BZg1ycg8Ak+iPaRmnDBUB5W DujA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=jiKBRIJ90WYjcORFiV3ORltYZSK2q2sAgdSrdSfFfbc=; b=JKmwxkkuMTKXFa90Thvjdh0ADxxPITJbFnr9TxxQpGIOeClQzQjWpmyC4sAWRawLGJ UzNthgk5zd74rGJTOH4bwhuOUsDDsU9rLlXtFXsONRNuIj7CDlSnkPYa8b7+1aQ9fMtB OrZFOKemdfjfg5j6h9d3S9/2stCoILE7UY9qmrNlefSP8xOQW+7eN+34/rAYuFK0Xg7N wtDu695kVwfiwmpjHz5x5PzL14+HUbZm7YXbtxD7+0ZqIW6+UnH5QIOqCgToqHfTBs/N JKu0W7Rv1zVFpMJr6+a5pqcfKQrrq8mAMv7Ix4Q2u85hVOPFyYHwXpRox4Z9AvacDDiG i3QQ== X-Gm-Message-State: AOAM531ZEV9xo19PMmyMOejzjjpz5FduXyXAymyzOSyTQctKxHvf3xsQ 4Sh6s3VSDgjC5PogcEDBQm8eDakQ8rVMUrAAtog= X-Received: by 2002:a05:6638:2257:: with SMTP id m23mr249515jas.139.1635256992171; Tue, 26 Oct 2021 07:03:12 -0700 (PDT) MIME-Version: 1.0 References: <20211025083315.4752-1-laoar.shao@gmail.com> <20211025083315.4752-9-laoar.shao@gmail.com> <202110251421.7056ACF84@keescook> <20211026091211.569a7ba2@gandalf.local.home> In-Reply-To: From: Yafang Shao Date: Tue, 26 Oct 2021 22:02:36 +0800 Message-ID: Subject: Re: [PATCH v6 08/12] tools/bpf/bpftool/skeleton: make it adopt to task comm size change To: Steven Rostedt Cc: Kees Cook , Andrew Morton , Mathieu Desnoyers , Arnaldo Carvalho de Melo , Petr Mladek , Peter Zijlstra , Al Viro , Valentin Schneider , Qiang Zhang , robdclark , christian , Dietmar Eggemann , Ingo Molnar , Juri Lelli , Vincent Guittot , David Miller , Jakub Kicinski , Alexei Starovoitov , Daniel Borkmann , Andrii Nakryiko , Martin Lau , Song Liu , Yonghong Song , john fastabend , KP Singh , dennis.dalessandro@cornelisnetworks.com, mike.marciniszyn@cornelisnetworks.com, dledford@redhat.com, jgg@ziepe.ca, linux-rdma@vger.kernel.org, netdev , bpf , "linux-perf-use." , linux-fsdevel@vger.kernel.org, Linux MM , LKML , kernel test robot , kbuild test robot , Andrii Nakryiko Content-Type: text/plain; charset="UTF-8" Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Tue, Oct 26, 2021 at 9:55 PM Yafang Shao wrote: > > On Tue, Oct 26, 2021 at 9:12 PM Steven Rostedt wrote: > > > > On Tue, 26 Oct 2021 10:18:51 +0800 > > Yafang Shao wrote: > > > > > > So, if we're ever going to copying these buffers out of the kernel (I > > > > don't know what the object lifetime here in bpf is for "e", etc), we > > > > should be zero-padding (as get_task_comm() does). > > > > > > > > Should this, instead, be using a bounce buffer? > > > > > > The comment in bpf_probe_read_kernel_str_common() says > > > > > > : /* > > > : * The strncpy_from_kernel_nofault() call will likely not fill the > > > : * entire buffer, but that's okay in this circumstance as we're probing > > > : * arbitrary memory anyway similar to bpf_probe_read_*() and might > > > : * as well probe the stack. Thus, memory is explicitly cleared > > > : * only in error case, so that improper users ignoring return > > > : * code altogether don't copy garbage; otherwise length of string > > > : * is returned that can be used for bpf_perf_event_output() et al. > > > : */ > > > > > > It seems that it doesn't matter if the buffer is filled as that is > > > probing arbitrary memory. > > > > > > > > > > > get_task_comm(comm, task->group_leader); > > > > > > This helper can't be used by the BPF programs, as it is not exported to BPF. > > > > > > > bpf_probe_read_kernel_str(&e.comm, sizeof(e.comm), comm); > > > > I guess Kees is worried that e.comm will have something exported to user > > space that it shouldn't. But since e is part of the BPF program, does the > > BPF JIT take care to make sure everything on its stack is zero'd out, such > > that a user BPF couldn't just read various items off its stack and by doing > > so, see kernel memory it shouldn't be seeing? > > > Ah, you mean the BPF JIT has already avoided leaking information to user. I will check the BPF JIT code first. > Understood. > It can leak information to the user if the user buffer is large enough. > > > > I'm guessing it does, otherwise this would be a bigger issue than this > > patch series. > > > > I will think about how to fix it. > At first glance, it seems we'd better introduce a new BPF helper like > bpf_probe_read_kernel_str_pad(). > > -- > Thanks > Yafang -- Thanks Yafang