diff mbox series

[v2,bpf-next,1/9] libbpf: fix detection of corrupted BPF instructions section

Message ID 20190529173611.4012579-2-andriin@fb.com
State Accepted
Delegated to: BPF Maintainers
Headers show
Series libbpf random fixes | expand

Commit Message

Andrii Nakryiko May 29, 2019, 5:36 p.m. UTC
Ensure that size of a section w/ BPF instruction is exactly a multiple
of BPF instruction size.

Signed-off-by: Andrii Nakryiko <andriin@fb.com>
---
 tools/lib/bpf/libbpf.c | 12 +++++++-----
 1 file changed, 7 insertions(+), 5 deletions(-)

Comments

Song Liu May 29, 2019, 6:01 p.m. UTC | #1
> On May 29, 2019, at 10:36 AM, Andrii Nakryiko <andriin@fb.com> wrote:
> 
> Ensure that size of a section w/ BPF instruction is exactly a multiple
> of BPF instruction size.
> 
> Signed-off-by: Andrii Nakryiko <andriin@fb.com>

Acked-by: Song Liu <songliubraving@fb.com>

> ---
> tools/lib/bpf/libbpf.c | 12 +++++++-----
> 1 file changed, 7 insertions(+), 5 deletions(-)
> 
> diff --git a/tools/lib/bpf/libbpf.c b/tools/lib/bpf/libbpf.c
> index ca4432f5b067..c6c9d632624a 100644
> --- a/tools/lib/bpf/libbpf.c
> +++ b/tools/lib/bpf/libbpf.c
> @@ -349,8 +349,11 @@ static int
> bpf_program__init(void *data, size_t size, char *section_name, int idx,
> 		  struct bpf_program *prog)
> {
> -	if (size < sizeof(struct bpf_insn)) {
> -		pr_warning("corrupted section '%s'\n", section_name);
> +	const size_t bpf_insn_sz = sizeof(struct bpf_insn);
> +
> +	if (size == 0 || size % bpf_insn_sz) {
> +		pr_warning("corrupted section '%s', size: %zu\n",
> +			   section_name, size);
> 		return -EINVAL;
> 	}
> 
> @@ -376,9 +379,8 @@ bpf_program__init(void *data, size_t size, char *section_name, int idx,
> 			   section_name);
> 		goto errout;
> 	}
> -	prog->insns_cnt = size / sizeof(struct bpf_insn);
> -	memcpy(prog->insns, data,
> -	       prog->insns_cnt * sizeof(struct bpf_insn));
> +	prog->insns_cnt = size / bpf_insn_sz;
> +	memcpy(prog->insns, data, size);
> 	prog->idx = idx;
> 	prog->instances.fds = NULL;
> 	prog->instances.nr = -1;
> -- 
> 2.17.1
>
diff mbox series

Patch

diff --git a/tools/lib/bpf/libbpf.c b/tools/lib/bpf/libbpf.c
index ca4432f5b067..c6c9d632624a 100644
--- a/tools/lib/bpf/libbpf.c
+++ b/tools/lib/bpf/libbpf.c
@@ -349,8 +349,11 @@  static int
 bpf_program__init(void *data, size_t size, char *section_name, int idx,
 		  struct bpf_program *prog)
 {
-	if (size < sizeof(struct bpf_insn)) {
-		pr_warning("corrupted section '%s'\n", section_name);
+	const size_t bpf_insn_sz = sizeof(struct bpf_insn);
+
+	if (size == 0 || size % bpf_insn_sz) {
+		pr_warning("corrupted section '%s', size: %zu\n",
+			   section_name, size);
 		return -EINVAL;
 	}
 
@@ -376,9 +379,8 @@  bpf_program__init(void *data, size_t size, char *section_name, int idx,
 			   section_name);
 		goto errout;
 	}
-	prog->insns_cnt = size / sizeof(struct bpf_insn);
-	memcpy(prog->insns, data,
-	       prog->insns_cnt * sizeof(struct bpf_insn));
+	prog->insns_cnt = size / bpf_insn_sz;
+	memcpy(prog->insns, data, size);
 	prog->idx = idx;
 	prog->instances.fds = NULL;
 	prog->instances.nr = -1;