From: Jiri Olsa <jolsa@kernel.org> Date: 2021-05-05 13:25:45
We can't currently allow to attach functions with variable arguments.
The problem is that we should save all the registers for arguments,
which is probably doable, but if caller uses more than 6 arguments,
we need stack data, which will be wrong, because of the extra stack
frame we do in bpf trampoline, so we could crash.
Also currently there's malformed trampoline code generated for such
functions at the moment as described in:
https://lore.kernel.org/bpf/20210429212834.82621-1-jolsa@kernel.org/
Signed-off-by: Jiri Olsa <jolsa@kernel.org>
---
kernel/bpf/btf.c | 13 +++++++++++++
1 file changed, 13 insertions(+)
@@ -5206,6 +5206,13 @@ int btf_distill_func_proto(struct bpf_verifier_log *log,m->ret_size=ret;for(i=0;i<nargs;i++){+if(i==nargs-1&&args[i].type==0){+bpf_log(log,+"The function %s with variable args is unsupported.\n",+tname);+return-EINVAL;++}ret=__get_type_size(btf,args[i].type,&t);if(ret<0){bpf_log(log,
@@ -5213,6 +5220,12 @@ int btf_distill_func_proto(struct bpf_verifier_log *log,tname,i,btf_kind_str[BTF_INFO_KIND(t->info)]);return-EINVAL;}+if(ret==0){+bpf_log(log,+"The function %s has malformed void argument.\n",+tname);+return-EINVAL;+}m->arg_size[i]=ret;}m->nr_args=nargs;
On Wed, May 5, 2021 at 6:42 AM Jiri Olsa [off-list ref] wrote:
We can't currently allow to attach functions with variable arguments.
The problem is that we should save all the registers for arguments,
which is probably doable, but if caller uses more than 6 arguments,
we need stack data, which will be wrong, because of the extra stack
frame we do in bpf trampoline, so we could crash.
Also currently there's malformed trampoline code generated for such
functions at the moment as described in:
https://lore.kernel.org/bpf/20210429212834.82621-1-jolsa@kernel.org/
Signed-off-by: Jiri Olsa <jolsa@kernel.org>
---
@@ -5206,6 +5206,13 @@ int btf_distill_func_proto(struct bpf_verifier_log *log,m->ret_size=ret;for(i=0;i<nargs;i++){+if(i==nargs-1&&args[i].type==0){+bpf_log(log,+"The function %s with variable args is unsupported.\n",+tname);+return-EINVAL;++}ret=__get_type_size(btf,args[i].type,&t);if(ret<0){bpf_log(log,
@@ -5213,6 +5220,12 @@ int btf_distill_func_proto(struct bpf_verifier_log *log,tname,i,btf_kind_str[BTF_INFO_KIND(t->info)]);return-EINVAL;}+if(ret==0){+bpf_log(log,+"The function %s has malformed void argument.\n",+tname);+return-EINVAL;+}m->arg_size[i]=ret;}m->nr_args=nargs;--
Hello:
This patch was applied to bpf/bpf.git (refs/heads/master):
On Wed, 5 May 2021 15:25:29 +0200 you wrote:
We can't currently allow to attach functions with variable arguments.
The problem is that we should save all the registers for arguments,
which is probably doable, but if caller uses more than 6 arguments,
we need stack data, which will be wrong, because of the extra stack
frame we do in bpf trampoline, so we could crash.
Also currently there's malformed trampoline code generated for such
functions at the moment as described in:
https://lore.kernel.org/bpf/20210429212834.82621-1-jolsa@kernel.org/
[...]
From: Daniel Borkmann <daniel@iogearbox.net> Date: 2021-05-06 23:32:00
On 5/5/21 8:45 PM, Andrii Nakryiko wrote:
On Wed, May 5, 2021 at 6:42 AM Jiri Olsa [off-list ref] wrote:
quoted
We can't currently allow to attach functions with variable arguments.
The problem is that we should save all the registers for arguments,
which is probably doable, but if caller uses more than 6 arguments,
we need stack data, which will be wrong, because of the extra stack
frame we do in bpf trampoline, so we could crash.
Also currently there's malformed trampoline code generated for such
functions at the moment as described in:
https://lore.kernel.org/bpf/20210429212834.82621-1-jolsa@kernel.org/
Signed-off-by: Jiri Olsa <jolsa@kernel.org>
---
@@ -5206,6 +5206,13 @@ int btf_distill_func_proto(struct bpf_verifier_log *log,m->ret_size=ret;for(i=0;i<nargs;i++){+if(i==nargs-1&&args[i].type==0){+bpf_log(log,+"The function %s with variable args is unsupported.\n",+tname);+return-EINVAL;+
(Jiri, fyi, I removed this extra newline while applying. Please scan for such
things before submitting.)
quoted
+ }
ret = __get_type_size(btf, args[i].type, &t);
if (ret < 0) {
bpf_log(log,
@@ -5213,6 +5220,12 @@ int btf_distill_func_proto(struct bpf_verifier_log *log, tname, i, btf_kind_str[BTF_INFO_KIND(t->info)]); return -EINVAL; }+ if (ret == 0) {+ bpf_log(log,+ "The function %s has malformed void argument.\n",+ tname);+ return -EINVAL;+ } m->arg_size[i] = ret; } m->nr_args = nargs;--
From: Jiri Olsa <hidden> Date: 2021-05-07 08:13:25
On Fri, May 07, 2021 at 01:31:54AM +0200, Daniel Borkmann wrote:
On 5/5/21 8:45 PM, Andrii Nakryiko wrote:
quoted
On Wed, May 5, 2021 at 6:42 AM Jiri Olsa [off-list ref] wrote:
quoted
We can't currently allow to attach functions with variable arguments.
The problem is that we should save all the registers for arguments,
which is probably doable, but if caller uses more than 6 arguments,
we need stack data, which will be wrong, because of the extra stack
frame we do in bpf trampoline, so we could crash.
Also currently there's malformed trampoline code generated for such
functions at the moment as described in:
https://lore.kernel.org/bpf/20210429212834.82621-1-jolsa@kernel.org/
Signed-off-by: Jiri Olsa <jolsa@kernel.org>
---
@@ -5206,6 +5206,13 @@ int btf_distill_func_proto(struct bpf_verifier_log *log,m->ret_size=ret;for(i=0;i<nargs;i++){+if(i==nargs-1&&args[i].type==0){+bpf_log(log,+"The function %s with variable args is unsupported.\n",+tname);+return-EINVAL;+
(Jiri, fyi, I removed this extra newline while applying. Please scan for such
things before submitting.)