[PATCH bpf-next 4/5] selftests/bpf: Test trusted-or-null linux_binprm->mm

Anastasios Papagiannis <[email protected]>
Newsgroups org.kernel.vger.bpf,org.kernel.vger.linux-kernel,org.kvack.linux-mm
Message-ID <[email protected]>
Add verifier coverage for the linux_binprm->mm trusted-or-null
annotation. Verify that bpf_copy_from_user_mm() accepts the pointer
after a NULL check and rejects it without one.

Signed-off-by: Anastasios Papagiannis <[email protected]>
---
 .../selftests/bpf/progs/verifier_lsm.c        | 31 +++++++++++++++++++
 1 file changed, 31 insertions(+)

diff --git a/tools/testing/selftests/bpf/progs/verifier_lsm.c b/tools/testing/selftests/bpf/progs/verifier_lsm.c
index c724bf389f5c..4fc835432af0 100644
--- a/tools/testing/selftests/bpf/progs/verifier_lsm.c
+++ b/tools/testing/selftests/bpf/progs/verifier_lsm.c
@@ -5,6 +5,10 @@
 #include <bpf/bpf_tracing.h>
 #include "bpf_misc.h"
 
+extern int bpf_copy_from_user_mm(void *dst, u32 dst__sz,
+				const void *unsafe_ptr__ign,
+				struct mm_struct *mm, u64 flags) __ksym;
+
 SEC("lsm/file_permission")
 __description("lsm bpf prog with -4095~0 retval. test 1")
 __success
@@ -212,4 +216,31 @@ __naked int retval_load_resets_bounds(void *ctx)
 	::: __clobber_all);
 }
 
+SEC("lsm.s/bprm_check_security")
+__description("null checking trusted-or-null linux_binprm mm")
+__success
+int BPF_PROG(copy_from_user_mm_with_null_check, struct linux_binprm *bprm, int ret)
+{
+	struct mm_struct *mm;
+	char dst[8];
+
+	mm = bprm->mm;
+	if (!mm)
+		return 0;
+
+	bpf_copy_from_user_mm(dst, sizeof(dst), (void *)bprm->p, mm, 0);
+	return 0;
+}
+
+SEC("lsm.s/bprm_check_security")
+__description("not null checking trusted-or-null linux_binprm mm")
+__failure __msg("Possibly NULL pointer passed to trusted R4")
+int BPF_PROG(copy_from_user_mm_without_null_check, struct linux_binprm *bprm, int ret)
+{
+	char dst[8];
+
+	bpf_copy_from_user_mm(dst, sizeof(dst), (void *)bprm->p, bprm->mm, 0);
+	return 0;
+}
+
 char _license[] SEC("license") = "GPL";
-- 
2.55.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.