* [PATCH bpf 0/2] Add return value check for BPF_LSM_CGROUP
@ 2026-05-23 8:58 Xu Kuohai
2026-05-23 8:58 ` [PATCH bpf 1/2] bpf: " Xu Kuohai
2026-05-23 8:58 ` [PATCH bpf 2/2] selftests/bpf: Add return value tests for lsm cgroup Xu Kuohai
0 siblings, 2 replies; 5+ messages in thread
From: Xu Kuohai @ 2026-05-23 8:58 UTC (permalink / raw)
To: bpf, linux-kernel
Cc: Alexei Starovoitov, Daniel Borkmann, Andrii Nakryiko,
Martin KaFai Lau, Eduard Zingerman, Kumar Kartikeya Dwivedi,
Yonghong Song, Stanislav Fomichev, Matt Bobrowski, Quan Sun
Quan Sun reported a NULL pointer dereference caused by invalid return value of
BPF_LSM_CGROUP program [1].
The cause is that the BPF_LSM_CGROUP programs use bpf_set_retval() helper to
set return value for the target LSM hook, and the value is not validated,
making any arbitrary value legally accepted.
To fix it, add return value check for BPF_LSM_CGROUP programs.
[1] https://lore.kernel.org/all/567d3206-74a5-44e5-99c6-779c425f399e@std.uestc.edu.cn
Xu Kuohai (2):
bpf: Add return value check for BPF_LSM_CGROUP
selftests/bpf: Add return value tests for lsm cgroup
kernel/bpf/verifier.c | 10 +++++
.../selftests/bpf/progs/verifier_lsm.c | 45 +++++++++++++++++++
2 files changed, 55 insertions(+)
--
2.43.0
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH bpf 1/2] bpf: Add return value check for BPF_LSM_CGROUP
2026-05-23 8:58 [PATCH bpf 0/2] Add return value check for BPF_LSM_CGROUP Xu Kuohai
@ 2026-05-23 8:58 ` Xu Kuohai
2026-05-23 8:58 ` [PATCH bpf 2/2] selftests/bpf: Add return value tests for lsm cgroup Xu Kuohai
1 sibling, 0 replies; 5+ messages in thread
From: Xu Kuohai @ 2026-05-23 8:58 UTC (permalink / raw)
To: bpf, linux-kernel
Cc: Alexei Starovoitov, Daniel Borkmann, Andrii Nakryiko,
Martin KaFai Lau, Eduard Zingerman, Kumar Kartikeya Dwivedi,
Yonghong Song, Stanislav Fomichev, Matt Bobrowski, Quan Sun
From: Xu Kuohai <xukuohai@huawei.com>
BPF_LSM_CGROUP programs use bpf_set_retval() helper to set the return
value, but the value is not validated. This could cause kernel panic
similar to the bug fixed by commit 5d99e198be27 ("bpf, lsm: Add check
for BPF LSM return value").
Fix it by verifying the argument for bpf_set_retval() falls within the
valid return value range for the target hook.
Fixes: 69fd337a975c ("bpf: per-cgroup lsm flavor")
Reported-by: Quan Sun <2022090917019@std.uestc.edu.cn>
Closes: https://lore.kernel.org/all/567d3206-74a5-44e5-99c6-779c425f399e@std.uestc.edu.cn
Signed-off-by: Xu Kuohai <xukuohai@huawei.com>
---
kernel/bpf/verifier.c | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
index 7fb88e1cd7c4..fe60a695de55 100644
--- a/kernel/bpf/verifier.c
+++ b/kernel/bpf/verifier.c
@@ -10462,6 +10462,9 @@ static int check_helper_call(struct bpf_verifier_env *env, struct bpf_insn *insn
case BPF_FUNC_set_retval:
if (prog_type == BPF_PROG_TYPE_LSM &&
env->prog->expected_attach_type == BPF_LSM_CGROUP) {
+ struct bpf_retval_range range;
+ struct bpf_reg_state *r1 = ®s[BPF_REG_1];
+
if (!env->prog->aux->attach_func_proto->type) {
/* Make sure programs that attach to void
* hooks don't try to modify return value.
@@ -10469,6 +10472,13 @@ static int check_helper_call(struct bpf_verifier_env *env, struct bpf_insn *insn
verbose(env, "BPF_LSM_CGROUP that attach to void LSM hooks can't modify return value!\n");
return -EINVAL;
}
+
+ bpf_lsm_get_retval_range(env->prog, &range);
+ range.return_32bit = true;
+ if (!retval_range_within(range, r1)) {
+ verbose_invalid_scalar(env, r1, range, "At bpf_set_retval", "R1");
+ return -EINVAL;
+ }
}
break;
case BPF_FUNC_dynptr_data:
--
2.43.0
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH bpf 2/2] selftests/bpf: Add return value tests for lsm cgroup
2026-05-23 8:58 [PATCH bpf 0/2] Add return value check for BPF_LSM_CGROUP Xu Kuohai
2026-05-23 8:58 ` [PATCH bpf 1/2] bpf: " Xu Kuohai
@ 2026-05-23 8:58 ` Xu Kuohai
2026-05-25 18:43 ` Emil Tsalapatis
1 sibling, 1 reply; 5+ messages in thread
From: Xu Kuohai @ 2026-05-23 8:58 UTC (permalink / raw)
To: bpf, linux-kernel
Cc: Alexei Starovoitov, Daniel Borkmann, Andrii Nakryiko,
Martin KaFai Lau, Eduard Zingerman, Kumar Kartikeya Dwivedi,
Yonghong Song, Stanislav Fomichev, Matt Bobrowski, Quan Sun
From: Xu Kuohai <xukuohai@huawei.com>
Add tests to check return values set by bpf_set_retval() helper for lsm
cgroup programs.
Signed-off-by: Xu Kuohai <xukuohai@huawei.com>
---
.../selftests/bpf/progs/verifier_lsm.c | 45 +++++++++++++++++++
1 file changed, 45 insertions(+)
diff --git a/tools/testing/selftests/bpf/progs/verifier_lsm.c b/tools/testing/selftests/bpf/progs/verifier_lsm.c
index 38e8e9176862..2072671ed643 100644
--- a/tools/testing/selftests/bpf/progs/verifier_lsm.c
+++ b/tools/testing/selftests/bpf/progs/verifier_lsm.c
@@ -188,4 +188,49 @@ int BPF_PROG(null_check, struct file *file)
return 0;
}
+SEC("lsm_cgroup/socket_create")
+__description("lsm_cgroup with -4095~0 retval test 1")
+__success
+int BPF_PROG(lsm_cgroup_set_retval_zero_valid, struct task_struct *task)
+{
+ bpf_set_retval(0);
+ return 0;
+}
+
+SEC("lsm_cgroup/socket_create")
+__description("lsm_cgroup with -4095~0 retval test 2")
+__success
+int BPF_PROG(lsm_cgroup_set_retval_negative_valid, struct task_struct *task)
+{
+ bpf_set_retval(-12);
+ return 0;
+}
+
+SEC("lsm_cgroup/socket_create")
+__description("lsm_cgroup with -4095~0 retval test 3")
+__failure __msg("should have been in [-4095, 0]")
+int BPF_PROG(lsm_cgroup_set_retval_negative_invalid, struct task_struct *task)
+{
+ bpf_set_retval(-4096);
+ return 0;
+}
+
+SEC("lsm_cgroup/socket_create")
+__description("lsm_cgroup with -4095~0 retval test 4")
+__failure __msg("should have been in [-4095, 0]")
+int BPF_PROG(lsm_cgroup_set_retval_positive_invalid, struct task_struct *task)
+{
+ bpf_set_retval(1);
+ return 0;
+}
+
+SEC("lsm_cgroup/file_release")
+__description("lsm_cgroup bpf_set_retval on void hook test")
+__failure __msg("BPF_LSM_CGROUP that attach to void LSM hooks can't modify return value")
+int BPF_PROG(lsm_cgroup_set_retval_for_void_hook, struct file *file)
+{
+ bpf_set_retval(0);
+ return 0;
+}
+
char _license[] SEC("license") = "GPL";
--
2.43.0
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH bpf 2/2] selftests/bpf: Add return value tests for lsm cgroup
2026-05-23 8:58 ` [PATCH bpf 2/2] selftests/bpf: Add return value tests for lsm cgroup Xu Kuohai
@ 2026-05-25 18:43 ` Emil Tsalapatis
2026-05-26 7:56 ` Xu Kuohai
0 siblings, 1 reply; 5+ messages in thread
From: Emil Tsalapatis @ 2026-05-25 18:43 UTC (permalink / raw)
To: Xu Kuohai, bpf, linux-kernel
Cc: Alexei Starovoitov, Daniel Borkmann, Andrii Nakryiko,
Martin KaFai Lau, Eduard Zingerman, Kumar Kartikeya Dwivedi,
Yonghong Song, Stanislav Fomichev, Matt Bobrowski, Quan Sun
On Sat May 23, 2026 at 4:58 AM EDT, Xu Kuohai wrote:
> From: Xu Kuohai <xukuohai@huawei.com>
>
> Add tests to check return values set by bpf_set_retval() helper for lsm
> cgroup programs.
After fixing the task_struct arg feel free to add:
Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
Nit: The test messages are kinda obscure, could you replace -4095~0 with "valid errno or
success" or something similar? E.g., test1/2/3/4 could be described as
"success"/"valid errno"/"invalid errno"/invalid value" instead of numbers.
>
> Signed-off-by: Xu Kuohai <xukuohai@huawei.com>
> ---
> .../selftests/bpf/progs/verifier_lsm.c | 45 +++++++++++++++++++
> 1 file changed, 45 insertions(+)
>
> diff --git a/tools/testing/selftests/bpf/progs/verifier_lsm.c b/tools/testing/selftests/bpf/progs/verifier_lsm.c
> index 38e8e9176862..2072671ed643 100644
> --- a/tools/testing/selftests/bpf/progs/verifier_lsm.c
> +++ b/tools/testing/selftests/bpf/progs/verifier_lsm.c
> @@ -188,4 +188,49 @@ int BPF_PROG(null_check, struct file *file)
> return 0;
> }
>
> +SEC("lsm_cgroup/socket_create")
> +__description("lsm_cgroup with -4095~0 retval test 1")
> +__success
> +int BPF_PROG(lsm_cgroup_set_retval_zero_valid, struct task_struct *task)
> +{
> + bpf_set_retval(0);
> + return 0;
> +}
> +
> +SEC("lsm_cgroup/socket_create")
> +__description("lsm_cgroup with -4095~0 retval test 2")
> +__success
> +int BPF_PROG(lsm_cgroup_set_retval_negative_valid, struct task_struct *task)
> +{
> + bpf_set_retval(-12);
> + return 0;
> +}
> +
> +SEC("lsm_cgroup/socket_create")
> +__description("lsm_cgroup with -4095~0 retval test 3")
> +__failure __msg("should have been in [-4095, 0]")
> +int BPF_PROG(lsm_cgroup_set_retval_negative_invalid, struct task_struct *task)
> +{
> + bpf_set_retval(-4096);
> + return 0;
> +}
> +
> +SEC("lsm_cgroup/socket_create")
> +__description("lsm_cgroup with -4095~0 retval test 4")
> +__failure __msg("should have been in [-4095, 0]")
> +int BPF_PROG(lsm_cgroup_set_retval_positive_invalid, struct task_struct *task)
> +{
> + bpf_set_retval(1);
> + return 0;
> +}
> +
> +SEC("lsm_cgroup/file_release")
> +__description("lsm_cgroup bpf_set_retval on void hook test")
> +__failure __msg("BPF_LSM_CGROUP that attach to void LSM hooks can't modify return value")
> +int BPF_PROG(lsm_cgroup_set_retval_for_void_hook, struct file *file)
> +{
> + bpf_set_retval(0);
> + return 0;
> +}
> +
> char _license[] SEC("license") = "GPL";
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH bpf 2/2] selftests/bpf: Add return value tests for lsm cgroup
2026-05-25 18:43 ` Emil Tsalapatis
@ 2026-05-26 7:56 ` Xu Kuohai
0 siblings, 0 replies; 5+ messages in thread
From: Xu Kuohai @ 2026-05-26 7:56 UTC (permalink / raw)
To: Emil Tsalapatis, bpf, linux-kernel
Cc: Alexei Starovoitov, Daniel Borkmann, Andrii Nakryiko,
Martin KaFai Lau, Eduard Zingerman, Kumar Kartikeya Dwivedi,
Yonghong Song, Stanislav Fomichev, Matt Bobrowski, Quan Sun
On 5/26/2026 2:43 AM, Emil Tsalapatis wrote:
> On Sat May 23, 2026 at 4:58 AM EDT, Xu Kuohai wrote:
>> From: Xu Kuohai <xukuohai@huawei.com>
>>
>> Add tests to check return values set by bpf_set_retval() helper for lsm
>> cgroup programs.
>
> After fixing the task_struct arg feel free to add:
>
> Reviewed-by: Emil Tsalapatis <emil@etsalapatis.com>
>
> Nit: The test messages are kinda obscure, could you replace -4095~0 with "valid errno or
> success" or something similar? E.g., test1/2/3/4 could be described as
> "success"/"valid errno"/"invalid errno"/invalid value" instead of numbers.
>
Makes sense, thanks.
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-05-26 7:56 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-05-23 8:58 [PATCH bpf 0/2] Add return value check for BPF_LSM_CGROUP Xu Kuohai
2026-05-23 8:58 ` [PATCH bpf 1/2] bpf: " Xu Kuohai
2026-05-23 8:58 ` [PATCH bpf 2/2] selftests/bpf: Add return value tests for lsm cgroup Xu Kuohai
2026-05-25 18:43 ` Emil Tsalapatis
2026-05-26 7:56 ` Xu Kuohai
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®