Thread (26 messages) 26 messages, 7 authors, 2020-06-03

Re: Self-XORing BPF registers is undefined behavior

From: Alexander Potapenko <glider@google.com>
Date: 2020-06-03 16:33:56

On Wed, Jun 3, 2020 at 5:37 PM Edward Cree [off-list ref] wrote:
On 02/06/2020 18:32, Alexei Starovoitov wrote:
quoted
The target for bpf codegen is JITs.
bpf interpreter is simulating hw.
For now if you want UB fuzzer running in your environment please add
_out_of_tree_ patch that inits all interpreter registers to zero.
+1 to all the above.
Noted, thank you.
Also, note that you can still fuzz BPF JITs by building the kernel
 without the interpreter: CONFIG_BPF_JIT_ALWAYS_ON.
Unfortunately KMSAN doesn't play well with JITed code. To be able to
detect uninit bugs in JIT, we'll need to instrument the generated code
as well.


-- 
Alexander Potapenko
Software Engineer

Google Germany GmbH
Erika-Mann-Straße, 33
80636 München

Geschäftsführer: Paul Manicle, Halimah DeLaine Prado
Registergericht und -nummer: Hamburg, HRB 86891
Sitz der Gesellschaft: Hamburg
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help