[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-Id: <20161116.132231.466321381115973145.davem@davemloft.net>
Date: Wed, 16 Nov 2016 13:22:31 -0500 (EST)
From: David Miller <davem@...emloft.net>
To: jbacik@...com
Cc: jannh@...gle.com, ast@...nel.org, daniel@...earbox.net,
netdev@...r.kernel.org
Subject: Re: [PATCH net][v2] bpf: fix range arithmetic for bpf map access
From: Josef Bacik <jbacik@...com>
Date: Mon, 14 Nov 2016 15:45:36 -0500
> I made some invalid assumptions with BPF_AND and BPF_MOD that could result in
> invalid accesses to bpf map entries. Fix this up by doing a few things
>
> 1) Kill BPF_MOD support. This doesn't actually get used by the compiler in real
> life and just adds extra complexity.
>
> 2) Fix the logic for BPF_AND, don't allow AND of negative numbers and set the
> minimum value to 0 for positive AND's.
>
> 3) Don't do operations on the ranges if they are set to the limits, as they are
> by definition undefined, and allowing arithmetic operations on those values
> could make them appear valid when they really aren't.
>
> This fixes the testcase provided by Jann as well as a few other theoretical
> problems.
>
> Reported-by: Jann Horn <jannh@...gle.com>
> Signed-off-by: Josef Bacik <jbacik@...com>
Applied, thanks.
Powered by blists - more mailing lists