selftests/bpf: Check overflow in optional buffer
authorDaniel Rosenberg <drosen@google.com>
Sat, 6 May 2023 01:31:32 +0000 (18:31 -0700)
committerAlexei Starovoitov <ast@kernel.org>
Sat, 6 May 2023 23:42:57 +0000 (16:42 -0700)
This ensures we still reject invalid memory accesses in buffers that are
marked optional.

Signed-off-by: Daniel Rosenberg <drosen@google.com>
Link: https://lore.kernel.org/r/20230506013134.2492210-4-drosen@google.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
tools/testing/selftests/bpf/progs/dynptr_fail.c

index efe4ce72d00e66b67bbe2aea0af27d13883d1aee..c2f0e18af95169f501e8c119c531684d146bef0c 100644 (file)
@@ -1665,3 +1665,23 @@ int clone_xdp_packet_data(struct xdp_md *xdp)
 
        return 0;
 }
+
+/* Buffers that are provided must be sufficiently long */
+SEC("?cgroup_skb/egress")
+__failure __msg("memory, len pair leads to invalid memory access")
+int test_dynptr_skb_small_buff(struct __sk_buff *skb)
+{
+       struct bpf_dynptr ptr;
+       char buffer[8] = {};
+       __u64 *data;
+
+       if (bpf_dynptr_from_skb(skb, 0, &ptr)) {
+               err = 1;
+               return 1;
+       }
+
+       /* This may return NULL. SKB may require a buffer */
+       data = bpf_dynptr_slice(&ptr, 0, buffer, 9);
+
+       return !!data;
+}