Skip to content

Commit 082c412

Browse files
borkmannAlexei Starovoitov
authored andcommitted
selftests/bpf: Keep verifier_map_ptr exercising ops pointer access
sashiko complained that 38498c0 ("selftests/bpf: Adjust verifier_map_ptr for the map's excl field") would slightly decrease the test coverage given before the test was against the verifier rejecting the ops pointer. Recover the old test with the right offsets and add the existing one as an additional test case. # LDLIBS=-static PKG_CONFIG='pkg-config --static' ./vmtest.sh -- ./test_progs -t verifier_map_ptr [ 1.672932] bpf_testmod: module verification failed: signature and/or required key missing - tainting kernel #637/1 verifier_map_ptr/bpf_map_ptr: read with negative offset rejected:OK #637/2 verifier_map_ptr/bpf_map_ptr: read with negative offset rejected @unpriv:OK #637/3 verifier_map_ptr/bpf_map_ptr: write rejected:OK #637/4 verifier_map_ptr/bpf_map_ptr: write rejected @unpriv:OK #637/5 verifier_map_ptr/bpf_map_ptr: read non-existent field rejected:OK #637/6 verifier_map_ptr/bpf_map_ptr: read non-existent field rejected @unpriv:OK #637/7 verifier_map_ptr/bpf_map_ptr: read beyond excl field rejected:OK #637/8 verifier_map_ptr/bpf_map_ptr: read beyond excl field rejected @unpriv:OK #637/9 verifier_map_ptr/bpf_map_ptr: read ops field accepted:OK #637/10 verifier_map_ptr/bpf_map_ptr: read ops field accepted @unpriv:OK #637/11 verifier_map_ptr/bpf_map_ptr: r = 0, map_ptr = map_ptr + r:OK #637/12 verifier_map_ptr/bpf_map_ptr: r = 0, map_ptr = map_ptr + r @unpriv:OK #637/13 verifier_map_ptr/bpf_map_ptr: r = 0, r = r + map_ptr:OK #637/14 verifier_map_ptr/bpf_map_ptr: r = 0, r = r + map_ptr @unpriv:OK #637 verifier_map_ptr:OK [...] Summary: 2/20 PASSED, 0 SKIPPED, 0 FAILED Signed-off-by: Daniel Borkmann <daniel@iogearbox.net> Link: https://lore.kernel.org/r/20260602133052.423725-4-daniel@iogearbox.net Signed-off-by: Alexei Starovoitov <ast@kernel.org>
1 parent 7fef179 commit 082c412

1 file changed

Lines changed: 30 additions & 4 deletions

File tree

tools/testing/selftests/bpf/progs/verifier_map_ptr.c

Lines changed: 30 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -72,17 +72,43 @@ __naked void bpf_map_ptr_write_rejected(void)
7272

7373
/*
7474
* struct bpf_map starts with the SHA256 hash sha[32] at offset 0 (a readable
75-
* byte array), followed by the u32 excl field at offset 32. Reading a u32 at
76-
* offset 33 runs past the end of excl and is rejected.
75+
* byte array), the u32 excl field at offset 32, and the ops pointer at offset
76+
* 40. Reading a u32 at offset 41 reaches into the middle of the ops pointer,
77+
* i.e. a partial pointer access, which is rejected.
7778
*/
7879
SEC("socket")
7980
__description("bpf_map_ptr: read non-existent field rejected")
8081
__failure
81-
__msg("access beyond the end of member excl (mend:36) in struct bpf_map with off 33 size 4")
82+
__msg("cannot access ptr member ops with moff 40 in struct bpf_map with off 41 size 4")
8283
__failure_unpriv
8384
__msg_unpriv("access is allowed only to CAP_PERFMON and CAP_SYS_ADMIN")
8485
__flag(BPF_F_ANY_ALIGNMENT)
8586
__naked void read_non_existent_field_rejected(void)
87+
{
88+
asm volatile (" \
89+
r6 = 0; \
90+
r1 = %[map_array_48b] ll; \
91+
r6 = *(u32*)(r1 + 41); \
92+
r0 = 1; \
93+
exit; \
94+
" :
95+
: __imm_addr(map_array_48b)
96+
: __clobber_all);
97+
}
98+
99+
/*
100+
* The u32 excl field spans offsets 32..35 (mend 36). Reading a u32 at offset
101+
* 33 starts inside excl but extends past its end, which the verifier rejects
102+
* as an out-of-bounds scalar access.
103+
*/
104+
SEC("socket")
105+
__description("bpf_map_ptr: read beyond excl field rejected")
106+
__failure
107+
__msg("access beyond the end of member excl (mend:36) in struct bpf_map with off 33 size 4")
108+
__failure_unpriv
109+
__msg_unpriv("access is allowed only to CAP_PERFMON and CAP_SYS_ADMIN")
110+
__flag(BPF_F_ANY_ALIGNMENT)
111+
__naked void read_beyond_excl_field_rejected(void)
86112
{
87113
asm volatile (" \
88114
r6 = 0; \
@@ -105,7 +131,7 @@ __naked void ptr_read_ops_field_accepted(void)
105131
asm volatile (" \
106132
r6 = 0; \
107133
r1 = %[map_array_48b] ll; \
108-
r6 = *(u64*)(r1 + 0); \
134+
r6 = *(u64*)(r1 + 40); \
109135
r0 = 1; \
110136
exit; \
111137
" :

0 commit comments

Comments
 (0)