* [PATCH] bpf: Initialize IMA hash helper output buffers
@ 2026-09-27 12:14 Jiale Yao
2026-09-28 7:38 ` Alexei Starovoitov
0 siblings, 1 reply; 3+ messages in thread
From: Jiale Yao @ 2026-09-27 12:14 UTC (permalink / raw)
To: KP Singh, Matt Bobrowski, Alexei Starovoitov, Daniel Borkmann,
Andrii Nakryiko, Eduard Zingerman, Kumar Kartikeya Dwivedi,
Martin KaFai Lau, Song Liu, Yonghong Song, Jiri Olsa,
Emil Tsalapatis, Ihor Solodrai, Roberto Sassu, bpf, linux-kernel
Cc: Jiale Yao, stable
The output arguments of bpf_ima_inode_hash() and bpf_ima_file_hash()
are marked as ARG_PTR_TO_UNINIT_MEM, so the verifier considers the full
range initialized after either helper returns. The IMA hash functions,
however, leave the buffer unchanged on error and only copy the digest
length on success. A BPF program can therefore read stale data from
the untouched portion of the buffer.
Clear the full destination before calling into IMA so every byte is
initialized on all return paths.
Fixes: 27672f0d280a ("bpf: Add a BPF helper for getting the IMA hash of an inode")
Fixes: 174b16946e39 ("bpf-lsm: Introduce new helper bpf_ima_file_hash()")
Cc: stable@vger.kernel.org
Signed-off-by: Jiale Yao <yaojiale02@163.com>
---
kernel/bpf/bpf_lsm.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/kernel/bpf/bpf_lsm.c b/kernel/bpf/bpf_lsm.c
index 82c5988417a0..bc08c039dc85 100644
--- a/kernel/bpf/bpf_lsm.c
+++ b/kernel/bpf/bpf_lsm.c
@@ -168,6 +168,7 @@ static const struct bpf_func_proto bpf_bprm_opts_set_proto = {
BPF_CALL_3(bpf_ima_inode_hash, struct inode *, inode, void *, dst, u32, size)
{
+ memset(dst, 0, size);
return ima_inode_hash(inode, dst, size);
}
@@ -192,6 +193,7 @@ static const struct bpf_func_proto bpf_ima_inode_hash_proto = {
BPF_CALL_3(bpf_ima_file_hash, struct file *, file, void *, dst, u32, size)
{
+ memset(dst, 0, size);
return ima_file_hash(file, dst, size);
}
--
2.34.1
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH] bpf: Initialize IMA hash helper output buffers
2026-09-27 12:14 [PATCH] bpf: Initialize IMA hash helper output buffers Jiale Yao
@ 2026-09-28 7:38 ` Alexei Starovoitov
2026-09-28 11:43 ` Matt Bobrowski
0 siblings, 1 reply; 3+ messages in thread
From: Alexei Starovoitov @ 2026-09-28 7:38 UTC (permalink / raw)
To: Jiale Yao, KP Singh, Matt Bobrowski, Daniel Borkmann,
Andrii Nakryiko, Eduard Zingerman, Kumar Kartikeya Dwivedi,
Martin KaFai Lau, Song Liu, Yonghong Song, Jiri Olsa,
Emil Tsalapatis, Ihor Solodrai, Roberto Sassu, bpf, linux-kernel
Cc: stable
On Sun, Sep 27, 2026 at 08:14 PM Jiale Yao <yaojiale02@163.com> wrote:
> The output arguments of bpf_ima_inode_hash() and bpf_ima_file_hash()
> are marked as ARG_PTR_TO_UNINIT_MEM, so the verifier considers the full
> range initialized after either helper returns. The IMA hash functions,
> however, leave the buffer unchanged on error and only copy the digest
> length on success. A BPF program can therefore read stale data from
> the untouched portion of the buffer.
That's not a bug.
These helpers are available to LSM progs only and LSM progs
require CAP_PERFMON to load.
With CAP_PERFMON the verifier allows reading uninitialized stack
with or without the helper call.
Since commit 5da4a9f26fca ("bpf: Preserve stack initialization for
generic output buffers") MEM_UNINIT helpers don't have to write
the whole buffer.
pw-bot: cr
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH] bpf: Initialize IMA hash helper output buffers
2026-09-28 7:38 ` Alexei Starovoitov
@ 2026-09-28 11:43 ` Matt Bobrowski
0 siblings, 0 replies; 3+ messages in thread
From: Matt Bobrowski @ 2026-09-28 11:43 UTC (permalink / raw)
To: Alexei Starovoitov
Cc: Jiale Yao, KP Singh, Daniel Borkmann, Andrii Nakryiko,
Eduard Zingerman, Kumar Kartikeya Dwivedi, Martin KaFai Lau,
Song Liu, Yonghong Song, Jiri Olsa, Emil Tsalapatis,
Ihor Solodrai, Roberto Sassu, bpf, linux-kernel, stable
On Mon, Sep 28, 2026 at 07:38:57AM +0000, Alexei Starovoitov wrote:
> On Sun, Sep 27, 2026 at 08:14 PM Jiale Yao <yaojiale02@163.com> wrote:
> > The output arguments of bpf_ima_inode_hash() and bpf_ima_file_hash()
> > are marked as ARG_PTR_TO_UNINIT_MEM, so the verifier considers the full
> > range initialized after either helper returns. The IMA hash functions,
> > however, leave the buffer unchanged on error and only copy the digest
> > length on success. A BPF program can therefore read stale data from
> > the untouched portion of the buffer.
>
> That's not a bug.
> These helpers are available to LSM progs only and LSM progs
> require CAP_PERFMON to load.
> With CAP_PERFMON the verifier allows reading uninitialized stack
> with or without the helper call.
>
> Since commit 5da4a9f26fca ("bpf: Preserve stack initialization for
> generic output buffers") MEM_UNINIT helpers don't have to write
> the whole buffer.
I suppose it's also worth noting that the return value already advises
the caller how much of the destination buffer is meaningful. On error,
nothing is written. On success, the returned hash_algo value identifies
the digest, and only that many bytes are written, so an oversized buffer
is expected to be only partially filled. This is also by design as
bpf_ima_{inode,file}_hash() already recommend passing a buffer large
enough for the largest possible hash (being IMA_MAX_DIGEST_SIZE). A
caller that honours the return value literally never needs to read the
untouched bytes.
With that said, this is a NACK from me.
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-09-28 11:44 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-27 12:14 [PATCH] bpf: Initialize IMA hash helper output buffers Jiale Yao
2026-09-28 7:38 ` Alexei Starovoitov
2026-09-28 11:43 ` Matt Bobrowski
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®