[PATCH] net: bpf_jit: fix an off-one bug in x86_64 cond jump target

Subsystems: bpf jit for x86 64-bit, bpf [general] (safe dynamic programs and tools), the rest, x86 architecture (32-bit and 64-bit)

STALE5375d

2 messages, 2 authors, 2011-12-19 · open the first message on its own page

[PATCH] net: bpf_jit: fix an off-one bug in x86_64 cond jump target

From: Eric Dumazet <hidden>
Date: 2011-12-17 21:39:13

From: Markus Kötter <redacted>

x86 jump instruction size is 2 or 5 bytes (near/long jump), not 2 or 6
bytes.

In case a conditional jump is followed by a long jump, conditional jump
target is one byte past the start of target instruction.

Signed-off-by: Markus Kötter <redacted>
Signed-off-by: Eric Dumazet <redacted>
---

libpcap expression to reproduce the bug :

"(tcp and portrange 0-1024) or (udp and portrange 1025-2048)"

 arch/x86/net/bpf_jit_comp.c |    4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/arch/x86/net/bpf_jit_comp.c b/arch/x86/net/bpf_jit_comp.c
index bfab3fa..7b65f75 100644
--- a/arch/x86/net/bpf_jit_comp.c
+++ b/arch/x86/net/bpf_jit_comp.c
@@ -568,8 +568,8 @@ cond_branch:			f_offset = addrs[i + filter[i].jf] - addrs[i];
 					break;
 				}
 				if (filter[i].jt != 0) {
-					if (filter[i].jf)
-						t_offset += is_near(f_offset) ? 2 : 6;
+					if (filter[i].jf && f_offset)
+						t_offset += is_near(f_offset) ? 2 : 5;
 					EMIT_COND_JMP(t_op, t_offset);
 					if (filter[i].jf)
 						EMIT_JMP(f_offset);

Re: [PATCH] net: bpf_jit: fix an off-one bug in x86_64 cond jump target

From: David Miller <davem@davemloft.net>
Date: 2011-12-19 20:49:02

From: Eric Dumazet <redacted>
Date: Sat, 17 Dec 2011 22:39:08 +0100
From: Markus Kötter <redacted>

x86 jump instruction size is 2 or 5 bytes (near/long jump), not 2 or 6
bytes.

In case a conditional jump is followed by a long jump, conditional jump
target is one byte past the start of target instruction.

Signed-off-by: Markus Kötter <redacted>
Signed-off-by: Eric Dumazet <redacted>
Applied and queued up for -stable, thanks!
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help