]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
libbpf: Fix crash if SEC("freplace") programs don't have attach_prog_fd set
authorAndrii Nakryiko <andrii@kernel.org>
Fri, 9 Sep 2022 19:30:52 +0000 (12:30 -0700)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Fri, 21 Oct 2022 10:38:11 +0000 (12:38 +0200)
[ Upstream commit 749c202cb6ea40f4d7ac95c4a1217a7b506f43a8 ]

Fix SIGSEGV caused by libbpf trying to find attach type in vmlinux BTF
for freplace programs. It's wrong to search in vmlinux BTF and libbpf
doesn't even mark vmlinux BTF as required for freplace programs. So
trying to search anything in obj->vmlinux_btf might cause NULL
dereference if nothing else in BPF object requires vmlinux BTF.

Instead, error out if freplace (EXT) program doesn't specify
attach_prog_fd during at the load time.

Fixes: 91abb4a6d79d ("libbpf: Support attachment of BPF tracing programs to kernel modules")
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/bpf/20220909193053.577111-3-andrii@kernel.org
Signed-off-by: Sasha Levin <sashal@kernel.org>
tools/lib/bpf/libbpf.c

index 50d41815f431a7498ac92f17b3fa41332d3e9c85..f6f4be0a247490a42c7c75a0dc98031a0de770ef 100644 (file)
@@ -9056,11 +9056,15 @@ static int libbpf_find_attach_btf_id(struct bpf_program *prog, const char *attac
        int err = 0;
 
        /* BPF program's BTF ID */
-       if (attach_prog_fd) {
+       if (prog->type == BPF_PROG_TYPE_EXT || attach_prog_fd) {
+               if (!attach_prog_fd) {
+                       pr_warn("prog '%s': attach program FD is not set\n", prog->name);
+                       return -EINVAL;
+               }
                err = libbpf_find_prog_btf_id(attach_name, attach_prog_fd);
                if (err < 0) {
-                       pr_warn("failed to find BPF program (FD %d) BTF ID for '%s': %d\n",
-                                attach_prog_fd, attach_name, err);
+                       pr_warn("prog '%s': failed to find BPF program (FD %d) BTF ID for '%s': %d\n",
+                                prog->name, attach_prog_fd, attach_name, err);
                        return err;
                }
                *btf_obj_fd = 0;
@@ -9077,7 +9081,8 @@ static int libbpf_find_attach_btf_id(struct bpf_program *prog, const char *attac
                err = find_kernel_btf_id(prog->obj, attach_name, attach_type, btf_obj_fd, btf_type_id);
        }
        if (err) {
-               pr_warn("failed to find kernel BTF type ID of '%s': %d\n", attach_name, err);
+               pr_warn("prog '%s': failed to find kernel BTF type ID of '%s': %d\n",
+                       prog->name, attach_name, err);
                return err;
        }
        return 0;