Re: [PATCH] fsverity: Fix bpf_get_fsverity_digest() dynptr assumptions

Song Liu <[email protected]> Sat, 1 Aug 2026 14:02:15 -0700
Newsgroups dev.linux.lists.fsverity,org.kernel.vger.bpf,org.kernel.vger.linux-kernel,org.kernel.vger.stable
Message-ID <CAPhsuW6dpxd56e3QT8AfwYPsNs3JCS_Tk8waWzNiX0en8Hha3w@mail.gmail.com>
On Thu, Jul 30, 2026 at 5:43=E2=80=AFPM Eric Biggers <[email protected]> =
wrote:
>
> The BPF verifier and the dynptr abstraction ensure that the memory space
> referenced by a dynptr remains valid.  They do not, however, provide any
> guarantee that the contents of the memory are stable.  kfuncs are
> expected to remain memory-safe even if concurrent modifications occur.
>
> bpf_get_fsverity_digest() didn't follow that: it could crash if
> arg->digest_size was concurrently modified.
>
> Fix that by using the known-good value hash_alg->digest_size instead.
>
> Also correctly handle sizes over INT_MAX, which previously caused an
> integer overflow and crash.  __bpf_dynptr_size() returns a u64.
>
> Fixes: 67814c00de31 ("bpf, fsverity: Add kfunc bpf_get_fsverity_digest")
> Cc: [email protected]
> Signed-off-by: Eric Biggers <[email protected]>

Looks good to me. Thanks for the fix!

Acked-by: Song Liu <[email protected]>