From patchwork Fri Mar 1 22:58:09 2019 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Paul Burton X-Patchwork-Id: 1050512 X-Patchwork-Delegate: bpf@iogearbox.net Return-Path: X-Original-To: patchwork-incoming-netdev@ozlabs.org Delivered-To: patchwork-incoming-netdev@ozlabs.org Authentication-Results: ozlabs.org; spf=none (mailfrom) smtp.mailfrom=vger.kernel.org (client-ip=209.132.180.67; helo=vger.kernel.org; envelope-from=netdev-owner@vger.kernel.org; receiver=) Authentication-Results: ozlabs.org; dmarc=none (p=none dis=none) header.from=mips.com Authentication-Results: ozlabs.org; dkim=pass (1024-bit key; unprotected) header.d=wavesemi.onmicrosoft.com header.i=@wavesemi.onmicrosoft.com header.b="CzQ6zYf6"; dkim-atps=neutral Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by ozlabs.org (Postfix) with ESMTP id 44B4b50Fmdz9s70 for ; Sat, 2 Mar 2019 09:58:24 +1100 (AEDT) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727025AbfCAW6P (ORCPT ); Fri, 1 Mar 2019 17:58:15 -0500 Received: from mail-eopbgr690107.outbound.protection.outlook.com ([40.107.69.107]:60976 "EHLO NAM04-CO1-obe.outbound.protection.outlook.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1726337AbfCAW6O (ORCPT ); Fri, 1 Mar 2019 17:58:14 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=wavesemi.onmicrosoft.com; s=selector1-wavecomp-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=7D0uQdkK/KTND7GsuRV58wX5LztBFCV+ZAvSqjr3hfo=; b=CzQ6zYf6Uj+UfuuZP0jZkbwtUx3zMuEYWabXuareGVj59M9afYQfSA8fct97TLEwQde6VZbNwSxbpzWcDw3wHcfImMbHQRXeoTcRcp+HDNnN0Isnssc0iPyxUcN1bkFYb9eMJ+h9+afmRAeEztIu64R6f+97MbWhiI0oQXdsMEs= Received: from MWHPR2201MB1277.namprd22.prod.outlook.com (10.174.162.17) by MWHPR2201MB1712.namprd22.prod.outlook.com (10.164.206.154) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.1665.18; Fri, 1 Mar 2019 22:58:10 +0000 Received: from MWHPR2201MB1277.namprd22.prod.outlook.com ([fe80::b8d4:8f0d:d6d1:4018]) by MWHPR2201MB1277.namprd22.prod.outlook.com ([fe80::b8d4:8f0d:d6d1:4018%3]) with mapi id 15.20.1665.017; Fri, 1 Mar 2019 22:58:10 +0000 From: Paul Burton To: "linux-mips@vger.kernel.org" , "bpf@vger.kernel.org" , "netdev@vger.kernel.org" CC: "linux-kernel@vger.kernel.org" , Paul Burton , Alexei Starovoitov , Daniel Borkmann , Martin KaFai Lau , Song Liu , Yonghong Song , "stable@vger.kernel.org" Subject: [PATCH] MIPS: eBPF: Fix icache flush end address Thread-Topic: [PATCH] MIPS: eBPF: Fix icache flush end address Thread-Index: AQHU0II9QjuLpQE7bEiWH3F6aW3bIQ== Date: Fri, 1 Mar 2019 22:58:09 +0000 Message-ID: <20190301225743.8632-1-paul.burton@mips.com> Accept-Language: en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-clientproxiedby: BYAPR11CA0104.namprd11.prod.outlook.com (2603:10b6:a03:f4::45) To MWHPR2201MB1277.namprd22.prod.outlook.com (2603:10b6:301:24::17) authentication-results: spf=none (sender IP is ) smtp.mailfrom=pburton@wavecomp.com; x-ms-exchange-messagesentrepresentingtype: 1 x-mailer: git-send-email 2.21.0 x-originating-ip: [67.207.99.198] x-ms-publictraffictype: Email x-ms-office365-filtering-correlation-id: 505f46a1-6a24-4398-4409-08d69e995fd5 x-microsoft-antispam: BCL:0; PCL:0; RULEID:(2390118)(7020095)(4652040)(8989299)(4534185)(4627221)(201703031133081)(201702281549075)(8990200)(5600127)(711020)(4605104)(2017052603328)(7153060)(7193020); SRVR:MWHPR2201MB1712; x-ms-traffictypediagnostic: MWHPR2201MB1712: x-microsoft-exchange-diagnostics: =?iso-8859-1?q?1=3BMWHPR2201MB1712=3B23?= =?iso-8859-1?q?=3AY6AUrjOfGAUrK1UqYhSj7607jP/rXXyft5NxkNryRb2AlPzW?= =?iso-8859-1?q?pVmZFGc6TkDwDJFBGqh9bInQeSDOo4pETWTldYMxSlSipWIvoYg?= =?iso-8859-1?q?6pvpUt/vp5WnmWYcRZqJGB/pzER9qT3wRvd4WDvXMLE7Wa5UBRK?= =?iso-8859-1?q?hqDMuspVxp1LNg1xCLXstX0dzfdUTC0ifxqpVikW87TPP9PliT3?= =?iso-8859-1?q?JgSOHhxQqy1wP0Sneg2bhExtPX/TUzTXZZOL3pEiVknomo+Bo+9?= =?iso-8859-1?q?5Q7DE8Nbab2tRhgww4RH0m41HAu1qWMw9OvjsLEojHGMXyZO/y8?= =?iso-8859-1?q?vvRyTg9jwqcWXxicFQ0hx3qmqArDUERwsT6vYXVd8F8v8a5MDxR?= =?iso-8859-1?q?gEK9zcJjD1KVqxEeVBJeQ6R/5ml1QkBb+TOaJOqKtNy6PHE4wZN?= =?iso-8859-1?q?a7WKA3lahhn04tIx7x3z+Z1W5UwozzSpea3Q2CWLccSCBpGifSA?= =?iso-8859-1?q?IjzKg/GMnNNN9p0OPA12QXv3/NuCwopFhAC4dMuNaL/9FSpBBP0?= =?iso-8859-1?q?ZkfE/qr3LdqEI3Zr6BCdQTbzY0uW1WeuqEfIHbobu/HVpxaznd9?= =?iso-8859-1?q?QZucV6A63fIlL7YhU51CufqSmbt+k43CgaE9v5cAlYyysnDUOw0?= =?iso-8859-1?q?5gfdCy4T6WgHudCgliUqtf+qnvUltCY7e0tTutZDzk8/QNClvu4?= =?iso-8859-1?q?yp/VXGCUx6y55UlsWaTX+MLwdw72H6V0MnEq8E6yUH5qUTNe44J?= =?iso-8859-1?q?Axl+mYIXfHFEfO2AjcPVOnl61r7f0N3RX/sB9+hWA3T9rMtCuFo?= =?iso-8859-1?q?CTvy8kDeUgnwZ703YW37YX6EVFP/p7+mHAOPokffsjHXbDBOkfi?= =?iso-8859-1?q?NyPkG24Yaatgxzpr1mUMYGKlAc6rR924mLg2ubCGzhWyN1H8CSG?= =?iso-8859-1?q?9cNEJNVNsnlsrWA2RPt26v5g7RWmvlxL5YQgp39NZA9r7k4J7fF?= =?iso-8859-1?q?DHnSNeHIR7I49N5/xdQa4oh8VJlL1/1O9ZfjjykuzlbD1NgkLsb?= =?iso-8859-1?q?4CACJtKwztqHjddz/17xzTjhlRqoLiZ5lozTv3zudz7eKf4TQG4?= =?iso-8859-1?q?1vBy4y7ySfNjUtkL1IwNDbO05GXnKagho3US7eXv1QT6QGo9Gs0?= =?iso-8859-1?q?HiY1RrlYWn0O0uVL0TSh5CftckXWif1qy99O1mB5nzCMdBrXeDY?= =?iso-8859-1?q?cRwUooKCuGjAf8h/UpkUsLB7lkbORrdkefluGBsgUk1GTtdkqCF?= =?iso-8859-1?q?TwPttBY8kkwVc+LPJKGU4rAmO/z3HB/uWL/fyZ0FJv/rGovZ/1I?= =?iso-8859-1?q?lflE2LwTw4BQ733NrDVYVVB676N0s8xDEEoj3s=3D?= x-microsoft-antispam-prvs: x-forefront-prvs: 09634B1196 x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(39840400004)(136003)(376002)(396003)(346002)(366004)(199004)(189003)(316002)(6116002)(3846002)(99286004)(2201001)(1076003)(186003)(7736002)(5660300002)(2616005)(7416002)(105586002)(44832011)(14444005)(256004)(52116002)(486006)(386003)(6506007)(81166006)(81156014)(8676002)(476003)(305945005)(2906002)(97736004)(4326008)(54906003)(110136005)(42882007)(66066001)(6436002)(6486002)(26005)(53936002)(2501003)(71190400001)(71200400001)(478600001)(50226002)(8936002)(6512007)(25786009)(14454004)(102836004)(106356001)(36756003)(68736007); DIR:OUT; SFP:1102; SCL:1; SRVR:MWHPR2201MB1712; H:MWHPR2201MB1277.namprd22.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1; received-spf: None (protection.outlook.com: wavecomp.com does not designate permitted sender hosts) x-ms-exchange-senderadcheck: 1 x-microsoft-antispam-message-info: 99p/MpIJjqXs5OAkrwpL2l5pRSXTEKHOPQP83798NaKVde059olqv8LAqHDRfkS5bGhPgRd/vJkIq58y9CIEZGIAEXJ+xIRHwzMbGv54S2pV3xlwy/miEcR5RwWJCHy4t0PMyCtQ546hfjMG0XG2eecfhq06kpRUgqBOjhB2vqaLwXNIcVDP+GbF/cg+BQ2siyynzGJyR36AzM9oUv92noYzNYng7sNEzv87PKo0SSOgtYdAC5kMxCdP2s0keXlVXM06GSXZYW0edNgUWgogUYplmn0qohZHG47k15JVw3p2Rqa7wTVWzBM0DWWfttE2ob6dsdlq+ApTOuBKsEcbCL8m8CumO7b94lf6XEt/ayrfLg99U9smTDe1RJsIGRFxcP/iVDUADVp8C/OH2Sq7H1wyEv/BBLIGEgEa1uF0nV4= MIME-Version: 1.0 X-OriginatorOrg: mips.com X-MS-Exchange-CrossTenant-Network-Message-Id: 505f46a1-6a24-4398-4409-08d69e995fd5 X-MS-Exchange-CrossTenant-originalarrivaltime: 01 Mar 2019 22:58:10.0275 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 463607d3-1db3-40a0-8a29-970c56230104 X-MS-Exchange-CrossTenant-mailboxtype: HOSTED X-MS-Exchange-Transport-CrossTenantHeadersStamped: MWHPR2201MB1712 Sender: netdev-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: netdev@vger.kernel.org The MIPS eBPF JIT calls flush_icache_range() in order to ensure the icache observes the code that we just wrote. Unfortunately it gets the end address calculation wrong due to some bad pointer arithmetic. The struct jit_ctx target field is of type pointer to u32, and as such adding one to it will increment the address being pointed to by 4 bytes. Therefore in order to find the address of the end of the code we simply need to add the number of 4 byte instructions emitted, but we mistakenly add the number of instructions multiplied by 4. This results in the call to flush_icache_range() operating on a memory region 4x larger than intended, which is always wasteful and can cause crashes if we overrun into an unmapped page. Fix this by correcting the pointer arithmetic to remove the bogus multiplication, and use braces to remove the need for a set of brackets whilst also making it obvious that the target field is a pointer. Signed-off-by: Paul Burton Fixes: b6bd53f9c4e8 ("MIPS: Add missing file for eBPF JIT.") Cc: Alexei Starovoitov Cc: Daniel Borkmann Cc: Martin KaFai Lau Cc: Song Liu Cc: Yonghong Song Cc: netdev@vger.kernel.org Cc: bpf@vger.kernel.org Cc: linux-mips@vger.kernel.org Cc: stable@vger.kernel.org # v4.13+ --- arch/mips/net/ebpf_jit.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/arch/mips/net/ebpf_jit.c b/arch/mips/net/ebpf_jit.c index 76e9bf88d3b9..0effd3cba9a7 100644 --- a/arch/mips/net/ebpf_jit.c +++ b/arch/mips/net/ebpf_jit.c @@ -1819,7 +1819,7 @@ struct bpf_prog *bpf_int_jit_compile(struct bpf_prog *prog) /* Update the icache */ flush_icache_range((unsigned long)ctx.target, - (unsigned long)(ctx.target + ctx.idx * sizeof(u32))); + (unsigned long)&ctx.target[ctx.idx]); if (bpf_jit_enable > 1) /* Dump JIT code */