• Andrii Nakryiko's avatar
    bpf: fix precision bit propagation for BPF_ST instructions · b3b50f05
    Andrii Nakryiko authored
    When backtracking instructions to propagate precision bit for registers
    and stack slots, one class of instructions (BPF_ST) weren't handled
    causing extra stack slots to be propagated into parent state. Parent
    state might not have that much stack allocated, though, which causes
    warning on invalid stack slot usage.
    
    This patch adds handling of BPF_ST instructions:
    
    BPF_MEM | <size> | BPF_ST:   *(size *) (dst_reg + off) = imm32
    
    Reported-by: syzbot+4da3ff23081bafe74fc2@syzkaller.appspotmail.com
    Fixes: b5dc0163 ("bpf: precise scalar_value tracking")
    Cc: Alexei Starovoitov <ast@fb.com>
    Signed-off-by: default avatarAndrii Nakryiko <andriin@fb.com>
    Signed-off-by: default avatarDaniel Borkmann <daniel@iogearbox.net>
    b3b50f05
verifier.c 268 KB