bpf: don't set id on after map lookup with ptr_to_map_val return
In the verifier there is no such semantics where registers with
PTR_TO_MAP_VALUE type have an id assigned to them. This is only
used in PTR_TO_MAP_VALUE_OR_NULL and later on nullified once the
test against NULL has been pattern matched and type transformed
into PTR_TO_MAP_VALUE.
Fixes: 3e6a4b3e02
("bpf/verifier: introduce BPF_PTR_TO_MAP_VALUE")
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Cc: Roman Gushchin <guro@fb.com>
Acked-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
This commit is contained in:
parent
0962590e55
commit
4d31f30148
|
@ -2852,10 +2852,6 @@ static int check_helper_call(struct bpf_verifier_env *env, int func_id, int insn
|
||||||
regs[BPF_REG_0].type = NOT_INIT;
|
regs[BPF_REG_0].type = NOT_INIT;
|
||||||
} else if (fn->ret_type == RET_PTR_TO_MAP_VALUE_OR_NULL ||
|
} else if (fn->ret_type == RET_PTR_TO_MAP_VALUE_OR_NULL ||
|
||||||
fn->ret_type == RET_PTR_TO_MAP_VALUE) {
|
fn->ret_type == RET_PTR_TO_MAP_VALUE) {
|
||||||
if (fn->ret_type == RET_PTR_TO_MAP_VALUE)
|
|
||||||
regs[BPF_REG_0].type = PTR_TO_MAP_VALUE;
|
|
||||||
else
|
|
||||||
regs[BPF_REG_0].type = PTR_TO_MAP_VALUE_OR_NULL;
|
|
||||||
/* There is no offset yet applied, variable or fixed */
|
/* There is no offset yet applied, variable or fixed */
|
||||||
mark_reg_known_zero(env, regs, BPF_REG_0);
|
mark_reg_known_zero(env, regs, BPF_REG_0);
|
||||||
/* remember map_ptr, so that check_map_access()
|
/* remember map_ptr, so that check_map_access()
|
||||||
|
@ -2868,7 +2864,12 @@ static int check_helper_call(struct bpf_verifier_env *env, int func_id, int insn
|
||||||
return -EINVAL;
|
return -EINVAL;
|
||||||
}
|
}
|
||||||
regs[BPF_REG_0].map_ptr = meta.map_ptr;
|
regs[BPF_REG_0].map_ptr = meta.map_ptr;
|
||||||
regs[BPF_REG_0].id = ++env->id_gen;
|
if (fn->ret_type == RET_PTR_TO_MAP_VALUE) {
|
||||||
|
regs[BPF_REG_0].type = PTR_TO_MAP_VALUE;
|
||||||
|
} else {
|
||||||
|
regs[BPF_REG_0].type = PTR_TO_MAP_VALUE_OR_NULL;
|
||||||
|
regs[BPF_REG_0].id = ++env->id_gen;
|
||||||
|
}
|
||||||
} else if (fn->ret_type == RET_PTR_TO_SOCKET_OR_NULL) {
|
} else if (fn->ret_type == RET_PTR_TO_SOCKET_OR_NULL) {
|
||||||
int id = acquire_reference_state(env, insn_idx);
|
int id = acquire_reference_state(env, insn_idx);
|
||||||
if (id < 0)
|
if (id < 0)
|
||||||
|
|
Loading…
Reference in New Issue