[PATCH bpf-next 3/4] bpf: Keep untrusted PTR_TO_MEM read-only on RCU invalidation

Daniel Borkmann <[email protected]>
Newsgroups org.kernel.vger.bpf
Message-ID <[email protected]>
invalidate_rcu_protected_refs() turns MEM_RCU pointers into PTR_UNTRUSTED
ones once the RCU read-side critical section ends.

For a PTR_TO_BTF_ID base that is fine, but for a PTR_TO_MEM base the
result has to carry MEM_RDONLY as well, since the rest of the verifier
relies on the two coming as a pair (e.g. bpf_convert_ctx_accesses()).

A writable untrusted PTR_TO_MEM would otherwise end up as a plain load
or store to memory without fault protection. No in-tree kfunc produces
the combination today, thus this is mainly hardening.

Signed-off-by: Daniel Borkmann <[email protected]>
---
 kernel/bpf/verifier.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
index 8ef9418733ca..0c0dd53118d5 100644
--- a/kernel/bpf/verifier.c
+++ b/kernel/bpf/verifier.c
@@ -9054,6 +9054,9 @@ static void invalidate_rcu_protected_refs(struct bpf_verifier_env *env)
 		if (reg->type & MEM_RCU) {
 			reg->type &= ~(MEM_RCU | PTR_MAYBE_NULL);
 			reg->type |= PTR_UNTRUSTED;
+			/* An untrusted PTR_TO_MEM has to be MEM_RDONLY. */
+			if (base_type(reg->type) == PTR_TO_MEM)
+				reg->type |= MEM_RDONLY;
 		}
 	}));
 }
-- 
2.43.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.