diff options
| author | Kumar Kartikeya Dwivedi <memxor@gmail.com> | 2026-08-08 02:39:33 +0200 |
|---|---|---|
| committer | Eduard Zingerman <eddyz87@gmail.com> | 2026-08-08 03:03:26 -0700 |
| commit | fd6094ac877cf5efe6702c0cfc86802dd9a4f322 (patch) | |
| tree | a33f0a071e9a7011a1e5e382dd2eda9ce22dc019 | |
| parent | 2d4de9a493a01e977914517bcc43b7b9a63ee50b (diff) | |
| download | linux-fd6094ac877cf5efe6702c0cfc86802dd9a4f322.tar.gz linux-fd6094ac877cf5efe6702c0cfc86802dd9a4f322.zip | |
bpf: Reject tracing/freplace progs for struct_ops with arena args
Reject tracing and freplace attachments to a target program with arena
context arguments. The struct_ops indirect trampoline converts those
arguments before entering the target, so a generic tracing trampoline
would otherwise expose arena offsets using the target BTF pointer type.
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Acked-by: Eduard Zingerman <eddyz87@gmail.com>
Link: https://patch.msgid.link/20260808003938.3486067-14-memxor@gmail.com
Signed-off-by: Eduard Zingerman <eddyz87@gmail.com>
| -rw-r--r-- | kernel/bpf/verifier.c | 10 |
1 files changed, 10 insertions, 0 deletions
diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c index 7d527f7c899e..add3affc5703 100644 --- a/kernel/bpf/verifier.c +++ b/kernel/bpf/verifier.c @@ -19068,6 +19068,16 @@ int bpf_check_attach_target(struct bpf_verifier_log *log, bpf_log(log, "Subprog %s doesn't exist\n", tname); return -EINVAL; } + /* + * A struct_ops indirect trampoline converts arena arguments + * before invoking its program. A tracing or extension program + * attached to the main program would see the converted offset as a + * regular BTF pointer. + */ + if (subprog == 0 && bpf_prog_has_arena_ctx_arg(tgt_prog)) { + bpf_log(log, "Cannot attach to a target with arena context arguments\n"); + return -EOPNOTSUPP; + } if (aux->func && aux->func[subprog]->aux->exception_cb) { bpf_log(log, "%s programs cannot attach to exception callback\n", |
