Re: [PATCH] bpf: fix missing checks of the return value of check_reg_arg

From: Alexei Starovoitov
Date: Tue Dec 25 2018 - 02:25:50 EST


On Tue, Dec 25, 2018 at 01:17:10AM -0600, Kangjie Lu wrote:
> check_reg_arg() may fail. This fix inserts checks for its return value.
> If check_reg_arg() fails, issues an error message.
>
> Signed-off-by: Kangjie Lu <kjlu@xxxxxxx>
> ---
> kernel/bpf/verifier.c | 15 ++++++++++++---
> 1 file changed, 12 insertions(+), 3 deletions(-)
>
> diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
> index 51ba84d4d34a..fde91a5c0b5a 100644
> --- a/kernel/bpf/verifier.c
> +++ b/kernel/bpf/verifier.c
> @@ -2619,7 +2619,10 @@ static int check_func_call(struct bpf_verifier_env *env, struct bpf_insn *insn,
> /* after the call registers r0 - r5 were scratched */
> for (i = 0; i < CALLER_SAVED_REGS; i++) {
> mark_reg_not_init(env, caller->regs, caller_saved[i]);
> - check_reg_arg(env, caller_saved[i], DST_OP_NO_MARK);
> + err = check_reg_arg(env, caller_saved[i], DST_OP_NO_MARK);
> + if (err)
> + verbose(env,
> + "check_reg_arg() fails in setting caller saved regs\n");

Such patch was already posted.
These calls cannot fail.
I prefer to leave them as-is.