From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1D81CC77B75 for ; Mon, 22 May 2023 20:35:44 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id AE953900003; Mon, 22 May 2023 16:35:43 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id A72AC900002; Mon, 22 May 2023 16:35:43 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 9135C900003; Mon, 22 May 2023 16:35:43 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0010.hostedemail.com [216.40.44.10]) by kanga.kvack.org (Postfix) with ESMTP id 780CB900002 for ; Mon, 22 May 2023 16:35:43 -0400 (EDT) Received: from smtpin16.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay01.hostedemail.com (Postfix) with ESMTP id 4D2661C7243 for ; Mon, 22 May 2023 20:35:43 +0000 (UTC) X-FDA: 80819046966.16.55B1667 Received: from dfw.source.kernel.org (dfw.source.kernel.org [139.178.84.217]) by imf01.hostedemail.com (Postfix) with ESMTP id 87AA140006 for ; Mon, 22 May 2023 20:35:41 +0000 (UTC) Authentication-Results: imf01.hostedemail.com; dkim=pass header.d=kernel.org header.s=k20201202 header.b=W5XbiWtu; dmarc=pass (policy=none) header.from=kernel.org; spf=pass (imf01.hostedemail.com: domain of jolsa@kernel.org designates 139.178.84.217 as permitted sender) smtp.mailfrom=jolsa@kernel.org ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1684787741; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=0vkmP33swkoemQ83h4cPLqEiFRHwHuf0oWbTqFZPouI=; b=7UA7j74OW4mL/ofamAtUXnYNkInGcKaxvLZMagNE/VER+XbYknDWTMPeKqYPUL+PFT891d wrjhKqsz0gPiVopJQu8VA0U5T7FM66nILnQVYtSIZKe/rLf+2GJ9cE29YzMUAb59hjC4qH GfJJvwr/73h56r4f0bw7Ib609SRo6uY= ARC-Authentication-Results: i=1; imf01.hostedemail.com; dkim=pass header.d=kernel.org header.s=k20201202 header.b=W5XbiWtu; dmarc=pass (policy=none) header.from=kernel.org; spf=pass (imf01.hostedemail.com: domain of jolsa@kernel.org designates 139.178.84.217 as permitted sender) smtp.mailfrom=jolsa@kernel.org ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1684787741; a=rsa-sha256; cv=none; b=T+uzRghT5dSAwkTJLI8Ad2sAe13k0os+SOWKqdvObDDqiwii0XVjkBV1iCkou/ksR/DSWn zknX5Kr2R6PuS1cRRsPlYWgc9465Ua7rtKHVjmBnyNcqSMYOd4yTXojS7gWeD3Z4BpS1Fa IQmTTzj/VBjY8+oRLrgosDZUXLDZXL4= Received: from smtp.kernel.org (relay.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by dfw.source.kernel.org (Postfix) with ESMTPS id AB48162BD2; Mon, 22 May 2023 20:35:40 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id 05A3CC4339B; Mon, 22 May 2023 20:35:34 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1684787740; bh=hPFjOzuSnoN/PTZCIZOnbk80dddEgF6LEUhE4eMCblA=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=W5XbiWtuhMenbbX2eUsoinsN+8nRR/kk7KRzLM8u5n0ct6UJ6TQgEMjP7g7qlnGGs 2OVjjAHxKwg5pjH9dqMzfV222zpLYZ/4BpTR7v7ZCSUSb9jtV8BcjfGrC0a/Y7Nhe8 72PtsNoXrMmSGA5Rtsqncf24gdJ8qlDxXHN3WtRUJKeMt7zKVZkNWBC+ElyUbnBE3r 9+8EDRyGXj7XaXJTyEfdXze96jJhrwyIlAESgXyTKCXz+LfKhh7NDX+ciCPw2ypc2E usyZxZNSzHp7HWwnbbdBDf9vxIu5tWnhCC7dSJYUjPRNH7Uy7lq+/9b+s74HUGmrBx KVs56ZQh4lioA== From: Jiri Olsa To: stable@vger.kernel.org Cc: Alexei Starovoitov , Daniel Borkmann , "H. Peter Anvin" , Ingo Molnar , Masami Hiramatsu , Thomas Gleixner , linux-mm@kvack.org, bpf@vger.kernel.org, x86@kernel.org, linux-kernel@vger.kernel.org, Tsahee Zidenberg , Andrii Nakryiko , Christoph Hellwig , =?UTF-8?q?Mah=C3=A9=20Tardy?= , linux-arm-kernel@lists.infradead.org Subject: [RFC PATCH stable 5.4 7/8] bpf: rework the compat kernel probe handling Date: Mon, 22 May 2023 22:33:51 +0200 Message-Id: <20230522203352.738576-8-jolsa@kernel.org> X-Mailer: git-send-email 2.40.1 In-Reply-To: <20230522203352.738576-1-jolsa@kernel.org> References: <20230522203352.738576-1-jolsa@kernel.org> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Rspamd-Server: rspam09 X-Rspamd-Queue-Id: 87AA140006 X-Stat-Signature: 9hesmxt33yie7ftp55nbr5jy4znyib1d X-Rspam-User: X-HE-Tag: 1684787741-886612 X-HE-Meta: U2FsdGVkX1856sAFsO5mituLuBTA9B+oqlwwnxWp4gPln0QY6skC//UmWJ6EH0h1/z6534NNpis7z449LYJ0JUUm2Kid989NperWjNEdxWMwgIDorsa56aFUr8sSAedRjZ5A+PJsL+oeHNGzndhugi3QVBiaj6FcpUR1ChxRAvQlwytpH/86/OLeAhuj+s5NRO+cSewr7ufsZaJm0zpXxENX0LYhNc6V+JFgHSP3unA/iY4Yz41EITAHMgviwKWhtmuy+ouyqp6X1V7WQLhmkPkLy3wohCWmyJCFh+KZHT1lr8fiYq2fAn1TtxbrjGvDM7hEC84W6YZgQPe1s5AbVLr9jXQM4B4VOA1M+V3iR9BmwPxS8LeLJFmZSTJHJgs03/DzNfshJYY5mzWvA6hOeddcWhr83XZ2PUZD034YipiTMxJaDRY6nuSxREVAB8jg0fEGoobAZDAaz9o4H2Mj+o98M4E2iS0iI2B1vSrwDK5GZGjCvNove3MgZvqPoujmO+031tRKBLIzjp1FAq+wiqDVn+bITRqG9t55/SfjCXDXPPBVDklmMGw2zEUbCRIkSbCXNUO2TqOTCYWOslaCF6WU8uZQGhJuZi1AJ9KpVmoOCS7UY+197rzjOqfat4ej5k4d7kFAAbzrCjE/KhjqKXqLQAM5rOukv7KaHJQ5K8ryznY/187TFQMpbjcXgH34h1Ym8qeAbVVegWbYIiW3k6EgzTDGA5DKzFdGhSFHp2Dwi9NERRFUMTYrBKUQNZDwNNpBPHXBIey2y9MnXqzSAsTHOxmvYonPVfGJZ70eaP2pShZYtBaUjn3WCZuDy4EBQ2OEsdadaCFhPkLoRyhQqn7DixoP2bUHjkk9PFS0D477cs34X4BbpJc3l9Sk2Z8K4tqLaJDJj+7fRLRLSj0A9beZ+IaJBTchTUzBWz69pbcAk2vyBkVjPialA9pYe7xexoJH3jk0y8ics2nMtpD 6uim63v9 qxZxuYqjdqt5ZVrFhWvSp3eQN2yUaKw0RACm3edZwbHXuKQzTDfa2S8zA7wC+sN8Mk9hqb9VGc9G5EMA8J3DTwt6W5jrS/0ussHuvNO7swwM/aKwejjUNgt/n9810CA9VMn/MMotU8g/Fmte/zfYk/kLHED9oLNsXegrsk15VFxqED0saVyexU3iXipAhSoypAPBN1Ev3iD5AIvFI1gnkUYrh+FcIhPL8rsg5JNcdXphPJ0NJEIRAJbVBG0VqPg8OSd+LdvgcudlvyWhIPULae5P63WGy8i7nUUvyjsQ2/ST2IwA4aTNzn8c6cm16PmoCTdYyhypl9fzSBeKQwerDDB4/soyE/ukG72gccvpFD6xynP6SbXCiZw91zJKvp7VloTUoDdQ3GLPyWXp04fFxXTmEuISb4V3iN7uiy3G3aIMOjy0XBoGSJJhcs0Ep0+3TL8hVVnkB3+clyZUFJHSKWnhK62nYPjRd1+cuW/ye3p+xnBDmTZb+9qnaIlhvfTNPzE8zEDVsOHK46aE= X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: From: Christoph Hellwig commit 8d92db5c04d10381f4db70ed99b1b576f5db18a7 upstream. [Conflicts due to applying hunks only to the functions that were taken in 6ae08ae3dea2 upstream commit backport earlier] Instead of using the dangerous probe_kernel_read and strncpy_from_unsafe helpers, rework the compat probes to check if an address is a kernel or userspace one, and then use the low-level kernel or user probe helper shared by the proper kernel and user probe helpers. This slightly changes behavior as the compat probe on a user address doesn't check the lockdown flags, just as the pure user probes do. Signed-off-by: Christoph Hellwig Signed-off-by: Andrew Morton Cc: Alexei Starovoitov Cc: Daniel Borkmann Cc: "H. Peter Anvin" Cc: Ingo Molnar Cc: Masami Hiramatsu Cc: Thomas Gleixner Link: http://lkml.kernel.org/r/20200521152301.2587579-14-hch@lst.de Signed-off-by: Linus Torvalds --- kernel/trace/bpf_trace.c | 93 +++++++++++++++++++++++++++------------- 1 file changed, 64 insertions(+), 29 deletions(-) diff --git a/kernel/trace/bpf_trace.c b/kernel/trace/bpf_trace.c index d1fd13a47bdf..a46256f99229 100644 --- a/kernel/trace/bpf_trace.c +++ b/kernel/trace/bpf_trace.c @@ -139,65 +139,99 @@ static const struct bpf_func_proto bpf_override_return_proto = { #endif static __always_inline int -bpf_probe_read_kernel_common(void *dst, u32 size, const void *unsafe_ptr, - const bool compat) +bpf_probe_read_user_common(void *dst, u32 size, const void __user *unsafe_ptr) { - int ret = security_locked_down(LOCKDOWN_BPF_READ); + int ret; + ret = probe_user_read(dst, unsafe_ptr, size); if (unlikely(ret < 0)) - goto out; - ret = compat ? probe_kernel_read(dst, unsafe_ptr, size) : - probe_kernel_read_strict(dst, unsafe_ptr, size); - if (unlikely(ret < 0)) -out: memset(dst, 0, size); return ret; } -BPF_CALL_3(bpf_probe_read_compat, void *, dst, u32, size, - const void *, unsafe_ptr) +static __always_inline int +bpf_probe_read_user_str_common(void *dst, u32 size, + const void __user *unsafe_ptr) { - return bpf_probe_read_kernel_common(dst, size, unsafe_ptr, true); + int ret; + + ret = strncpy_from_user_nofault(dst, unsafe_ptr, size); + if (unlikely(ret < 0)) + memset(dst, 0, size); + return ret; } -static const struct bpf_func_proto bpf_probe_read_compat_proto = { - .func = bpf_probe_read_compat, - .gpl_only = true, - .ret_type = RET_INTEGER, - .arg1_type = ARG_PTR_TO_UNINIT_MEM, - .arg2_type = ARG_CONST_SIZE_OR_ZERO, - .arg3_type = ARG_ANYTHING, -}; +static __always_inline int +bpf_probe_read_kernel_common(void *dst, u32 size, const void *unsafe_ptr) +{ + int ret = security_locked_down(LOCKDOWN_BPF_READ); + + if (unlikely(ret < 0)) + goto fail; + ret = probe_kernel_read_strict(dst, unsafe_ptr, size); + if (unlikely(ret < 0)) + goto fail; + return ret; +fail: + memset(dst, 0, size); + return ret; +} static __always_inline int -bpf_probe_read_kernel_str_common(void *dst, u32 size, const void *unsafe_ptr, - const bool compat) +bpf_probe_read_kernel_str_common(void *dst, u32 size, const void *unsafe_ptr) { int ret = security_locked_down(LOCKDOWN_BPF_READ); if (unlikely(ret < 0)) - goto out; + goto fail; + /* - * The strncpy_from_unsafe_*() call will likely not fill the entire - * buffer, but that's okay in this circumstance as we're probing + * The strncpy_from_kernel_nofault() call will likely not fill the + * entire buffer, but that's okay in this circumstance as we're probing * arbitrary memory anyway similar to bpf_probe_read_*() and might * as well probe the stack. Thus, memory is explicitly cleared * only in error case, so that improper users ignoring return * code altogether don't copy garbage; otherwise length of string * is returned that can be used for bpf_perf_event_output() et al. */ - ret = compat ? strncpy_from_unsafe(dst, unsafe_ptr, size) : - strncpy_from_kernel_nofault(dst, unsafe_ptr, size); + ret = strncpy_from_kernel_nofault(dst, unsafe_ptr, size); if (unlikely(ret < 0)) -out: - memset(dst, 0, size); + goto fail; + + return 0; +fail: + memset(dst, 0, size); return ret; } +#ifdef CONFIG_ARCH_HAS_NON_OVERLAPPING_ADDRESS_SPACE +BPF_CALL_3(bpf_probe_read_compat, void *, dst, u32, size, + const void *, unsafe_ptr) +{ + if ((unsigned long)unsafe_ptr < TASK_SIZE) { + return bpf_probe_read_user_common(dst, size, + (__force void __user *)unsafe_ptr); + } + return bpf_probe_read_kernel_common(dst, size, unsafe_ptr); +} + +static const struct bpf_func_proto bpf_probe_read_compat_proto = { + .func = bpf_probe_read_compat, + .gpl_only = true, + .ret_type = RET_INTEGER, + .arg1_type = ARG_PTR_TO_UNINIT_MEM, + .arg2_type = ARG_CONST_SIZE_OR_ZERO, + .arg3_type = ARG_ANYTHING, +}; + BPF_CALL_3(bpf_probe_read_compat_str, void *, dst, u32, size, const void *, unsafe_ptr) { - return bpf_probe_read_kernel_str_common(dst, size, unsafe_ptr, true); + if ((unsigned long)unsafe_ptr < TASK_SIZE) { + return bpf_probe_read_user_str_common(dst, size, + (__force void __user *)unsafe_ptr); + } + return bpf_probe_read_kernel_str_common(dst, size, unsafe_ptr); } static const struct bpf_func_proto bpf_probe_read_compat_str_proto = { @@ -208,6 +242,7 @@ static const struct bpf_func_proto bpf_probe_read_compat_str_proto = { .arg2_type = ARG_CONST_SIZE_OR_ZERO, .arg3_type = ARG_ANYTHING, }; +#endif /* CONFIG_ARCH_HAS_NON_OVERLAPPING_ADDRESS_SPACE */ BPF_CALL_3(bpf_probe_write_user, void __user *, unsafe_ptr, const void *, src, u32, size) -- 2.40.1