Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1705896 > unrolled thread

[RFC PATCH 0/2] bpf_trace_printk() fixes

Started byJames Hogan <james.hogan@imgtec.com>
First post2017-08-08 00:30 +0200
Last post2017-08-11 18:50 +0200
Articles 9 — 3 participants

Back to article view | Back to linux.kernel


Contents

  [RFC PATCH 0/2] bpf_trace_printk() fixes James Hogan <james.hogan@imgtec.com> - 2017-08-08 00:30 +0200
    [RFC PATCH 2/2] bpf: Initialise mod[] in bpf_trace_printk James Hogan <james.hogan@imgtec.com> - 2017-08-08 00:30 +0200
      Re: [RFC PATCH 2/2] bpf: Initialise mod[] in bpf_trace_printk Daniel Borkmann <daniel@iogearbox.net> - 2017-08-08 10:50 +0200
        Re: [RFC PATCH 2/2] bpf: Initialise mod[] in bpf_trace_printk David Miller <davem@davemloft.net> - 2017-08-08 18:50 +0200
          Re: [RFC PATCH 2/2] bpf: Initialise mod[] in bpf_trace_printk James Hogan <james.hogan@imgtec.com> - 2017-08-08 23:30 +0200
            Re: [RFC PATCH 2/2] bpf: Initialise mod[] in bpf_trace_printk David Miller <davem@davemloft.net> - 2017-08-09 00:00 +0200
              Re: [RFC PATCH 2/2] bpf: Initialise mod[] in bpf_trace_printk James Hogan <james.hogan@imgtec.com> - 2017-08-09 09:40 +0200
                Re: [RFC PATCH 2/2] bpf: Initialise mod[] in bpf_trace_printk Daniel Borkmann <daniel@iogearbox.net> - 2017-08-09 22:40 +0200
                  Re: [RFC PATCH 2/2] bpf: Initialise mod[] in bpf_trace_printk Daniel Borkmann <daniel@iogearbox.net> - 2017-08-11 18:50 +0200

#1705896 — [RFC PATCH 0/2] bpf_trace_printk() fixes

FromJames Hogan <james.hogan@imgtec.com>
Date2017-08-08 00:30 +0200
Subject[RFC PATCH 0/2] bpf_trace_printk() fixes
Message-ID<ubYH8-6KG-7@gated-at.bofh.it>
A couple of RFC fixes for bpf_trace_printk(). The first affects 32-bit
architectures in particular, the second is a theoretical uninitialised
variable fix.

Cc: Alexei Starovoitov <ast@kernel.org>
Cc: Daniel Borkmann <daniel@iogearbox.net>
Cc: Steven Rostedt <rostedt@goodmis.org>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: netdev@vger.kernel.org

James Hogan (2):
  bpf: Fix bpf_trace_printk on 32-bit architectures
  bpf: Initialise mod[] in bpf_trace_printk

 kernel/trace/bpf_trace.c | 28 +++++++++++++++++++++++-----
 1 file changed, 23 insertions(+), 5 deletions(-)

-- 
2.13.2

[toc] | [next] | [standalone]


#1705900 — [RFC PATCH 2/2] bpf: Initialise mod[] in bpf_trace_printk

FromJames Hogan <james.hogan@imgtec.com>
Date2017-08-08 00:30 +0200
Subject[RFC PATCH 2/2] bpf: Initialise mod[] in bpf_trace_printk
Message-ID<ubYH8-6KG-21@gated-at.bofh.it>
In reply to#1705896
In bpf_trace_printk(), the elements in mod[] are left uninitialised, but
they are then incremented to track the width of the formats. Zero
initialise the array just in case the memory contains non-zero values on
entry.

Fixes: 9c959c863f82 ("tracing: Allow BPF programs to call bpf_trace_printk()")
Signed-off-by: James Hogan <james.hogan@imgtec.com>
Cc: Alexei Starovoitov <ast@kernel.org>
Cc: Daniel Borkmann <daniel@iogearbox.net>
Cc: Steven Rostedt <rostedt@goodmis.org>
Cc: Ingo Molnar <mingo@redhat.com>
Cc: netdev@vger.kernel.org
---
When I checked (on MIPS32), the elements tended to have the value zero
anyway (does BPF zero the stack or something clever?), so this is a
purely theoretical fix.
---
 kernel/trace/bpf_trace.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/kernel/trace/bpf_trace.c b/kernel/trace/bpf_trace.c
index 32dcbe1b48f2..86a52857d941 100644
--- a/kernel/trace/bpf_trace.c
+++ b/kernel/trace/bpf_trace.c
@@ -129,7 +129,7 @@ BPF_CALL_5(bpf_trace_printk, char *, fmt, u32, fmt_size, u64, arg1,
 	   u64, arg2, u64, arg3)
 {
 	bool str_seen = false;
-	int mod[3] = {};
+	int mod[3] = { 0, 0, 0 };
 	int fmt_cnt = 0;
 	u64 unsafe_addr;
 	char buf[64];
-- 
2.13.2

[toc] | [prev] | [next] | [standalone]


#1706185 — Re: [RFC PATCH 2/2] bpf: Initialise mod[] in bpf_trace_printk

FromDaniel Borkmann <daniel@iogearbox.net>
Date2017-08-08 10:50 +0200
SubjectRe: [RFC PATCH 2/2] bpf: Initialise mod[] in bpf_trace_printk
Message-ID<uc8na-5sU-53@gated-at.bofh.it>
In reply to#1705900
On 08/08/2017 12:25 AM, James Hogan wrote:
> In bpf_trace_printk(), the elements in mod[] are left uninitialised, but
> they are then incremented to track the width of the formats. Zero
> initialise the array just in case the memory contains non-zero values on
> entry.
>
> Fixes: 9c959c863f82 ("tracing: Allow BPF programs to call bpf_trace_printk()")
> Signed-off-by: James Hogan <james.hogan@imgtec.com>
> Cc: Alexei Starovoitov <ast@kernel.org>
> Cc: Daniel Borkmann <daniel@iogearbox.net>
> Cc: Steven Rostedt <rostedt@goodmis.org>
> Cc: Ingo Molnar <mingo@redhat.com>
> Cc: netdev@vger.kernel.org
> ---
> When I checked (on MIPS32), the elements tended to have the value zero
> anyway (does BPF zero the stack or something clever?), so this is a
> purely theoretical fix.
> ---
>   kernel/trace/bpf_trace.c | 2 +-
>   1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/kernel/trace/bpf_trace.c b/kernel/trace/bpf_trace.c
> index 32dcbe1b48f2..86a52857d941 100644
> --- a/kernel/trace/bpf_trace.c
> +++ b/kernel/trace/bpf_trace.c
> @@ -129,7 +129,7 @@ BPF_CALL_5(bpf_trace_printk, char *, fmt, u32, fmt_size, u64, arg1,
>   	   u64, arg2, u64, arg3)
>   {
>   	bool str_seen = false;
> -	int mod[3] = {};
> +	int mod[3] = { 0, 0, 0 };

I'm probably missing something, but is the behavior of gcc wrt
above initializers different on mips (it zeroes just fine on x86
at least)? If yes, we'd probably need a cocci script to also check
rest of the kernel given this is used in a number of places. Hm,
could you elaborate?

>   	int fmt_cnt = 0;
>   	u64 unsafe_addr;
>   	char buf[64];
>

[toc] | [prev] | [next] | [standalone]


#1706758 — Re: [RFC PATCH 2/2] bpf: Initialise mod[] in bpf_trace_printk

FromDavid Miller <davem@davemloft.net>
Date2017-08-08 18:50 +0200
SubjectRe: [RFC PATCH 2/2] bpf: Initialise mod[] in bpf_trace_printk
Message-ID<ucfRE-2BI-23@gated-at.bofh.it>
In reply to#1706185
From: Daniel Borkmann <daniel@iogearbox.net>
Date: Tue, 08 Aug 2017 10:46:52 +0200

> On 08/08/2017 12:25 AM, James Hogan wrote:
>> In bpf_trace_printk(), the elements in mod[] are left uninitialised,
>> but
>> they are then incremented to track the width of the formats. Zero
>> initialise the array just in case the memory contains non-zero values
>> on
>> entry.
>>
>> Fixes: 9c959c863f82 ("tracing: Allow BPF programs to call
>> bpf_trace_printk()")
>> Signed-off-by: James Hogan <james.hogan@imgtec.com>
>> Cc: Alexei Starovoitov <ast@kernel.org>
>> Cc: Daniel Borkmann <daniel@iogearbox.net>
>> Cc: Steven Rostedt <rostedt@goodmis.org>
>> Cc: Ingo Molnar <mingo@redhat.com>
>> Cc: netdev@vger.kernel.org
>> ---
>> When I checked (on MIPS32), the elements tended to have the value zero
>> anyway (does BPF zero the stack or something clever?), so this is a
>> purely theoretical fix.
>> ---
>>   kernel/trace/bpf_trace.c | 2 +-
>>   1 file changed, 1 insertion(+), 1 deletion(-)
>>
>> diff --git a/kernel/trace/bpf_trace.c b/kernel/trace/bpf_trace.c
>> index 32dcbe1b48f2..86a52857d941 100644
>> --- a/kernel/trace/bpf_trace.c
>> +++ b/kernel/trace/bpf_trace.c
>> @@ -129,7 +129,7 @@ BPF_CALL_5(bpf_trace_printk, char *, fmt, u32,
>> fmt_size, u64, arg1,
>>   	   u64, arg2, u64, arg3)
>>   {
>>   	bool str_seen = false;
>> -	int mod[3] = {};
>> +	int mod[3] = { 0, 0, 0 };
> 
> I'm probably missing something, but is the behavior of gcc wrt
> above initializers different on mips (it zeroes just fine on x86
> at least)? If yes, we'd probably need a cocci script to also check
> rest of the kernel given this is used in a number of places. Hm,
> could you elaborate?

This change is not necessary at all.

An empty initializer must clear the whole object to zero.

"theoretical" fix indeed... :-(

[toc] | [prev] | [next] | [standalone]


#1706893 — Re: [RFC PATCH 2/2] bpf: Initialise mod[] in bpf_trace_printk

FromJames Hogan <james.hogan@imgtec.com>
Date2017-08-08 23:30 +0200
SubjectRe: [RFC PATCH 2/2] bpf: Initialise mod[] in bpf_trace_printk
Message-ID<uckeB-5SA-1@gated-at.bofh.it>
In reply to#1706758
On 8 August 2017 17:48:57 BST, David Miller <davem@davemloft.net> wrote:
>From: Daniel Borkmann <daniel@iogearbox.net>
>Date: Tue, 08 Aug 2017 10:46:52 +0200
>
>> On 08/08/2017 12:25 AM, James Hogan wrote:
>>> In bpf_trace_printk(), the elements in mod[] are left uninitialised,
>>> but
>>> they are then incremented to track the width of the formats. Zero
>>> initialise the array just in case the memory contains non-zero
>values
>>> on
>>> entry.
>>>
>>> Fixes: 9c959c863f82 ("tracing: Allow BPF programs to call
>>> bpf_trace_printk()")
>>> Signed-off-by: James Hogan <james.hogan@imgtec.com>
>>> Cc: Alexei Starovoitov <ast@kernel.org>
>>> Cc: Daniel Borkmann <daniel@iogearbox.net>
>>> Cc: Steven Rostedt <rostedt@goodmis.org>
>>> Cc: Ingo Molnar <mingo@redhat.com>
>>> Cc: netdev@vger.kernel.org
>>> ---
>>> When I checked (on MIPS32), the elements tended to have the value
>zero
>>> anyway (does BPF zero the stack or something clever?), so this is a
>>> purely theoretical fix.
>>> ---
>>>   kernel/trace/bpf_trace.c | 2 +-
>>>   1 file changed, 1 insertion(+), 1 deletion(-)
>>>
>>> diff --git a/kernel/trace/bpf_trace.c b/kernel/trace/bpf_trace.c
>>> index 32dcbe1b48f2..86a52857d941 100644
>>> --- a/kernel/trace/bpf_trace.c
>>> +++ b/kernel/trace/bpf_trace.c
>>> @@ -129,7 +129,7 @@ BPF_CALL_5(bpf_trace_printk, char *, fmt, u32,
>>> fmt_size, u64, arg1,
>>>   	   u64, arg2, u64, arg3)
>>>   {
>>>   	bool str_seen = false;
>>> -	int mod[3] = {};
>>> +	int mod[3] = { 0, 0, 0 };
>> 
>> I'm probably missing something, but is the behavior of gcc wrt
>> above initializers different on mips (it zeroes just fine on x86
>> at least)? If yes, we'd probably need a cocci script to also check
>> rest of the kernel given this is used in a number of places. Hm,
>> could you elaborate?
>
>This change is not necessary at all.
>
>An empty initializer must clear the whole object to zero.
>
>"theoretical" fix indeed... :-(

cool, i hadn't realised unmentioned elements in an initialiser are always zeroed, even when non-global/static, so had interpreted the whole array as uninitialised. learn something new every day :-) sorry for the noise.

cheers
James

[toc] | [prev] | [next] | [standalone]


#1706900 — Re: [RFC PATCH 2/2] bpf: Initialise mod[] in bpf_trace_printk

FromDavid Miller <davem@davemloft.net>
Date2017-08-09 00:00 +0200
SubjectRe: [RFC PATCH 2/2] bpf: Initialise mod[] in bpf_trace_printk
Message-ID<uckHE-64i-25@gated-at.bofh.it>
In reply to#1706893
From: James Hogan <james.hogan@imgtec.com>
Date: Tue, 08 Aug 2017 22:20:05 +0100

> cool, i hadn't realised unmentioned elements in an initialiser are
> always zeroed, even when non-global/static, so had interpreted the
> whole array as uninitialised. learn something new every day :-)
> sorry for the noise.

You didn't have to know in the first place, you could have simply
compiled the code into assembler by running:

	make kernel/trace/bpf_trace.s

and seen for yourself before putting all of this time and effort into
this patch and discussion.

If you don't know what the compiler does, simply look!

[toc] | [prev] | [next] | [standalone]


#1707102 — Re: [RFC PATCH 2/2] bpf: Initialise mod[] in bpf_trace_printk

FromJames Hogan <james.hogan@imgtec.com>
Date2017-08-09 09:40 +0200
SubjectRe: [RFC PATCH 2/2] bpf: Initialise mod[] in bpf_trace_printk
Message-ID<uctKW-3Wi-15@gated-at.bofh.it>
In reply to#1706900

[Multipart message — attachments visible in raw view] — view raw

On Tue, Aug 08, 2017 at 02:54:33PM -0700, David Miller wrote:
> From: James Hogan <james.hogan@imgtec.com>
> Date: Tue, 08 Aug 2017 22:20:05 +0100
> 
> > cool, i hadn't realised unmentioned elements in an initialiser are
> > always zeroed, even when non-global/static, so had interpreted the
> > whole array as uninitialised. learn something new every day :-)
> > sorry for the noise.
> 
> You didn't have to know in the first place, you could have simply
> compiled the code into assembler by running:
> 
> 	make kernel/trace/bpf_trace.s
> 
> and seen for yourself before putting all of this time and effort into
> this patch and discussion.
> 
> If you don't know what the compiler does, simply look!

Well, thats the danger of wrongly thinking I already knew what it did in
this case. Anyway like I said, I'm sorry for the noise and wasting your
time (but please consider looking at the other patch which is certainly
a more real issue).

Thanks
James

[toc] | [prev] | [next] | [standalone]


#1707875 — Re: [RFC PATCH 2/2] bpf: Initialise mod[] in bpf_trace_printk

FromDaniel Borkmann <daniel@iogearbox.net>
Date2017-08-09 22:40 +0200
SubjectRe: [RFC PATCH 2/2] bpf: Initialise mod[] in bpf_trace_printk
Message-ID<ucFVO-3Rs-65@gated-at.bofh.it>
In reply to#1707102
On 08/09/2017 09:39 AM, James Hogan wrote:
[...]
> time (but please consider looking at the other patch which is certainly
> a more real issue).

Sorry for the delay, started looking into that and whether we
have some other options, I'll get back to you on this.

Thanks,
Daniel

[toc] | [prev] | [next] | [standalone]


#1709844 — Re: [RFC PATCH 2/2] bpf: Initialise mod[] in bpf_trace_printk

FromDaniel Borkmann <daniel@iogearbox.net>
Date2017-08-11 18:50 +0200
SubjectRe: [RFC PATCH 2/2] bpf: Initialise mod[] in bpf_trace_printk
Message-ID<udlij-5Uh-27@gated-at.bofh.it>
In reply to#1707875
Hi James,

On 08/09/2017 10:34 PM, Daniel Borkmann wrote:
> On 08/09/2017 09:39 AM, James Hogan wrote:
> [...]
>> time (but please consider looking at the other patch which is certainly
>> a more real issue).
>
> Sorry for the delay, started looking into that and whether we
> have some other options, I'll get back to you on this.

Could we solve this more generically (as in: originally intended) in
the sense that we don't need to trust the gcc va_list handling; I feel
this is relying on an implementation detail? Perhaps something like
below poc patch?

Thanks again,
Daniel

 From 71f16544d455abb6bb82f7253c17c14d2a395e91 Mon Sep 17 00:00:00 2001
Message-Id: <71f16544d455abb6bb82f7253c17c14d2a395e91.1502469361.git.daniel@iogearbox.net>
From: Daniel Borkmann <daniel@iogearbox.net>
Date: Fri, 11 Aug 2017 15:56:32 +0200
Subject: [PATCH] bpf: fix bpf_trace_printk on 32 bit

Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
---
  kernel/trace/bpf_trace.c | 31 +++++++++++++++++++++++++++----
  1 file changed, 27 insertions(+), 4 deletions(-)

diff --git a/kernel/trace/bpf_trace.c b/kernel/trace/bpf_trace.c
index 3738519..d4cb36f 100644
--- a/kernel/trace/bpf_trace.c
+++ b/kernel/trace/bpf_trace.c
@@ -204,10 +204,33 @@ static const struct bpf_func_proto *bpf_get_probe_write_proto(void)
  		fmt_cnt++;
  	}

-	return __trace_printk(1/* fake ip will not be printed */, fmt,
-			      mod[0] == 2 ? arg1 : mod[0] == 1 ? (long) arg1 : (u32) arg1,
-			      mod[1] == 2 ? arg2 : mod[1] == 1 ? (long) arg2 : (u32) arg2,
-			      mod[2] == 2 ? arg3 : mod[2] == 1 ? (long) arg3 : (u32) arg3);
+#define __BPF_TP_EMIT()	__BPF_ARG3_TP()
+#define __BPF_TP(...)							\
+	__trace_printk(1 /* fake ip will not be printed */,		\
+		       fmt, ##__VA_ARGS__)
+
+#define __BPF_ARG1_TP(...)						\
+	((mod[0] == 2 || (mod[0] == 1 && __BITS_PER_LONG == 64))	\
+	  ? __BPF_TP(arg1, ##__VA_ARGS__)				\
+	  : ((mod[0] == 1 || (mod[0] == 0 && __BITS_PER_LONG == 32))	\
+	      ? __BPF_TP((long)arg1, ##__VA_ARGS__)			\
+	      : __BPF_TP((u32)arg1, ##__VA_ARGS__)))
+
+#define __BPF_ARG2_TP(...)						\
+	((mod[1] == 2 || (mod[1] == 1 && __BITS_PER_LONG == 64))	\
+	  ? __BPF_ARG1_TP(arg2, ##__VA_ARGS__)				\
+	  : ((mod[1] == 1 || (mod[1] == 0 && __BITS_PER_LONG == 32))	\
+	      ? __BPF_ARG1_TP((long)arg2, ##__VA_ARGS__)		\
+	      : __BPF_ARG1_TP((u32)arg2, ##__VA_ARGS__)))
+
+#define __BPF_ARG3_TP(...)						\
+	((mod[2] == 2 || (mod[2] == 1 && __BITS_PER_LONG == 64))	\
+	  ? __BPF_ARG2_TP(arg3, ##__VA_ARGS__)				\
+	  : ((mod[2] == 1 || (mod[2] == 0 && __BITS_PER_LONG == 32))	\
+	      ? __BPF_ARG2_TP((long)arg3, ##__VA_ARGS__)		\
+	      : __BPF_ARG2_TP((u32)arg3, ##__VA_ARGS__)))
+
+	return __BPF_TP_EMIT();
  }

  static const struct bpf_func_proto bpf_trace_printk_proto = {
-- 
1.9.3

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web