Thread (1 message) 1 message, 1 author, 2025-06-03

Re: [PATCH bpf-next v3 10/11] bpf: Allow nospec-protected var-offset stack access

From: Luis Gerhorst <hidden>
Date: 2025-06-03 21:07:36
Also in: bpf, linux-arm-kernel, linux-kselftest, lkml

Kumar Kartikeya Dwivedi [off-list ref] writes:
Hmm, while reading related code, I noticed that sanitize_check_bounds
returns 0 in case the type is not map_value or stack.
It seems like it should be returning an error, cannot check right now
but I'm pretty sure these are not the two pointer types unprivileged
programs can access?
So smells like a bug?
I now looked into this and as suspected it does not appear to be a bug
but only misleading code, I have sent a patch with a detailed
explanation and an assert:
https://lore.kernel.org/bpf/20250603204557.332447-1-luis.gerhorst@fau.de/T/#u (local)
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help