bpf: Fix verifier assumptions of bpf_d_path's output buffer

JIRA: https://issues.redhat.com/browse/RHEL-139985

commit ac44dcc788b950606793e8f9690c30925f59df02
Author: Shuran Liu <electronlsr@gmail.com>
Date:   Sat Dec 6 22:12:09 2025 +0800

    bpf: Fix verifier assumptions of bpf_d_path's output buffer

    Commit 37cce22dbd51 ("bpf: verifier: Refactor helper access type
    tracking") started distinguishing read vs write accesses performed by
    helpers.

    The second argument of bpf_d_path() is a pointer to a buffer that the
    helper fills with the resulting path. However, its prototype currently
    uses ARG_PTR_TO_MEM without MEM_WRITE.

    Before 37cce22dbd51, helper accesses were conservatively treated as
    potential writes, so this mismatch did not cause issues. Since that
    commit, the verifier may incorrectly assume that the buffer contents
    are unchanged across the helper call and base its optimizations on this
    wrong assumption. This can lead to misbehaviour in BPF programs that
    read back the buffer, such as prefix comparisons on the returned path.

    Fix this by marking the second argument of bpf_d_path() as
    ARG_PTR_TO_MEM | MEM_WRITE so that the verifier correctly models the
    write to the caller-provided buffer.

    Fixes: 37cce22dbd51 ("bpf: verifier: Refactor helper access type tracking")
    Co-developed-by: Zesen Liu <ftyg@live.com>
    Signed-off-by: Zesen Liu <ftyg@live.com>
    Co-developed-by: Peili Gao <gplhust955@gmail.com>
    Signed-off-by: Peili Gao <gplhust955@gmail.com>
    Co-developed-by: Haoran Ni <haoran.ni.cs@gmail.com>
    Signed-off-by: Haoran Ni <haoran.ni.cs@gmail.com>
    Signed-off-by: Shuran Liu <electronlsr@gmail.com>
    Reviewed-by: Matt Bobrowski <mattbobrowski@google.com>
    Link: https://lore.kernel.org/r/20251206141210.3148-2-electronlsr@gmail.com
    Signed-off-by: Alexei Starovoitov <ast@kernel.org>

Signed-off-by: Jerome Marchand <jmarchan@redhat.com>
This commit is contained in:
Jerome Marchand
2026-05-07 17:59:10 +02:00
parent 8107fe05a2
commit 5fb3417351
+1 -1
View File
@@ -965,7 +965,7 @@ static const struct bpf_func_proto bpf_d_path_proto = {
.ret_type = RET_INTEGER,
.arg1_type = ARG_PTR_TO_BTF_ID,
.arg1_btf_id = &bpf_d_path_btf_ids[0],
.arg2_type = ARG_PTR_TO_MEM,
.arg2_type = ARG_PTR_TO_MEM | MEM_WRITE,
.arg3_type = ARG_CONST_SIZE_OR_ZERO,
.allowed = bpf_d_path_allowed,
};