From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id AAD52C433F5 for ; Tue, 26 Oct 2021 13:56:33 +0000 (UTC) Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by mail.kernel.org (Postfix) with ESMTP id 3E34B61002 for ; Tue, 26 Oct 2021 13:56:33 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.4.1 mail.kernel.org 3E34B61002 Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=gmail.com Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=kvack.org Received: by kanga.kvack.org (Postfix) id 41A69940008; Tue, 26 Oct 2021 09:56:32 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 3C99F940007; Tue, 26 Oct 2021 09:56:32 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 29129940008; Tue, 26 Oct 2021 09:56:32 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from forelay.hostedemail.com (smtprelay0053.hostedemail.com [216.40.44.53]) by kanga.kvack.org (Postfix) with ESMTP id 1B31F940007 for ; Tue, 26 Oct 2021 09:56:32 -0400 (EDT) Received: from smtpin19.hostedemail.com (10.5.19.251.rfc1918.com [10.5.19.251]) by forelay01.hostedemail.com (Postfix) with ESMTP id C855A184B2F22 for ; Tue, 26 Oct 2021 13:56:31 +0000 (UTC) X-FDA: 78738738582.19.5164356 Received: from mail-io1-f49.google.com (mail-io1-f49.google.com [209.85.166.49]) by imf11.hostedemail.com (Postfix) with ESMTP id 727B0F0000B2 for ; Tue, 26 Oct 2021 13:56:31 +0000 (UTC) Received: by mail-io1-f49.google.com with SMTP id b188so20477019iof.8 for ; Tue, 26 Oct 2021 06:56:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=OCNly9Pv6GVtqK5WKlYGGpWZ1IwDTUSNcWIUnGMQ4tQ=; b=i7RAxoJj6vRHJO/QOSjI/2wZP40Tm49lxjwUghVRA9loicQXFZNhM0MArl94d+vLjQ 3ONCBgOGm6/Tzkk6/rbzph3fyWGtvF06KCpw5TQuJV+IYTHQLBvZq/yAsOXYH5zO2znh 0zjKS2Yzo3vcuKLciR7vPdHTMj2n1hFo604EAkwzdVdDIC4TDCtH88vI9tlkTdFe6ovD fUtyJV7cBcB5modNsKwvWcaeO4hCblmIqUYnQtEfhNC7w/zLGp7dGfWhIz6QBgu1TWLw 8Ux1Iqr2m7VjjSxbnvmsTLhMEWmkZE4cIbSrm9U8IZMkRyp3VWpS9uj1z99yX47jDUJn YTpg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=OCNly9Pv6GVtqK5WKlYGGpWZ1IwDTUSNcWIUnGMQ4tQ=; b=ruarvoVDkTbaL0aSPu4oa/3aaj4DVfxR+XWnf2Hg5qtdCdMJP4i2FEMNfURzEj8sDO 8Ys/+VfnYLRagfteXYCVnYIDNW9qvAp5nYX6HvcOXQRVnBzniqq7hd4jU3HvAZyBhvHK RhrnE1KhrD9hjL5ic7d7/qqaruvvIKSL+61uhYt9iL84nqWKre8/e3rfo3WfK9iK6oso RGIl46U9z5XuHOXyNAvpswue17gdw7haTO0eJg9kIBYS2SICt+GHYJTl+FC7sWHBXnQB dgA/iP2r/qAr44hglPqaUIo8cpKlFchd8l+MxCNc/yjmsanPXJdYUji6NMcIEekIZKh/ NMKA== X-Gm-Message-State: AOAM530qKnpYKkg7zoMp4cdjZ5YS4t0k78LxAeHjc0fOYRGcAhmwvdau eN8RWs5R9oUZ8TgGjbOe0mu5Hr/8+fXNLJ5WgZ0= X-Google-Smtp-Source: ABdhPJw6DOg4zAXK3lnhpAIkXs7o2KoNL0GRJkIrWvXjuD/QZ3ItZtbM3RgVBE1XgEfOYoA0wxJIHxgbtWr7mAbD35g= X-Received: by 2002:a02:a483:: with SMTP id d3mr6171868jam.23.1635256590773; Tue, 26 Oct 2021 06:56:30 -0700 (PDT) MIME-Version: 1.0 References: <20211025083315.4752-1-laoar.shao@gmail.com> <20211025083315.4752-9-laoar.shao@gmail.com> <202110251421.7056ACF84@keescook> <20211026091211.569a7ba2@gandalf.local.home> In-Reply-To: <20211026091211.569a7ba2@gandalf.local.home> From: Yafang Shao Date: Tue, 26 Oct 2021 21:55:54 +0800 Message-ID: Subject: Re: [PATCH v6 08/12] tools/bpf/bpftool/skeleton: make it adopt to task comm size change To: Steven Rostedt Cc: Kees Cook , Andrew Morton , Mathieu Desnoyers , Arnaldo Carvalho de Melo , Petr Mladek , Peter Zijlstra , Al Viro , Valentin Schneider , Qiang Zhang , robdclark , christian , Dietmar Eggemann , Ingo Molnar , Juri Lelli , Vincent Guittot , David Miller , Jakub Kicinski , Alexei Starovoitov , Daniel Borkmann , Andrii Nakryiko , Martin Lau , Song Liu , Yonghong Song , john fastabend , KP Singh , dennis.dalessandro@cornelisnetworks.com, mike.marciniszyn@cornelisnetworks.com, dledford@redhat.com, jgg@ziepe.ca, linux-rdma@vger.kernel.org, netdev , bpf , "linux-perf-use." , linux-fsdevel@vger.kernel.org, Linux MM , LKML , kernel test robot , kbuild test robot , Andrii Nakryiko Content-Type: text/plain; charset="UTF-8" X-Stat-Signature: yxgyqtta7he54yjac795uk9zdzxydq5d Authentication-Results: imf11.hostedemail.com; dkim=pass header.d=gmail.com header.s=20210112 header.b=i7RAxoJj; spf=pass (imf11.hostedemail.com: domain of laoar.shao@gmail.com designates 209.85.166.49 as permitted sender) smtp.mailfrom=laoar.shao@gmail.com; dmarc=pass (policy=none) header.from=gmail.com X-Rspamd-Server: rspam04 X-Rspamd-Queue-Id: 727B0F0000B2 X-HE-Tag: 1635256591-233167 X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On Tue, Oct 26, 2021 at 9:12 PM Steven Rostedt wrote: > > On Tue, 26 Oct 2021 10:18:51 +0800 > Yafang Shao wrote: > > > > So, if we're ever going to copying these buffers out of the kernel (I > > > don't know what the object lifetime here in bpf is for "e", etc), we > > > should be zero-padding (as get_task_comm() does). > > > > > > Should this, instead, be using a bounce buffer? > > > > The comment in bpf_probe_read_kernel_str_common() says > > > > : /* > > : * The strncpy_from_kernel_nofault() call will likely not fill the > > : * entire buffer, but that's okay in this circumstance as we're probing > > : * arbitrary memory anyway similar to bpf_probe_read_*() and might > > : * as well probe the stack. Thus, memory is explicitly cleared > > : * only in error case, so that improper users ignoring return > > : * code altogether don't copy garbage; otherwise length of string > > : * is returned that can be used for bpf_perf_event_output() et al. > > : */ > > > > It seems that it doesn't matter if the buffer is filled as that is > > probing arbitrary memory. > > > > > > > > get_task_comm(comm, task->group_leader); > > > > This helper can't be used by the BPF programs, as it is not exported to BPF. > > > > > bpf_probe_read_kernel_str(&e.comm, sizeof(e.comm), comm); > > I guess Kees is worried that e.comm will have something exported to user > space that it shouldn't. But since e is part of the BPF program, does the > BPF JIT take care to make sure everything on its stack is zero'd out, such > that a user BPF couldn't just read various items off its stack and by doing > so, see kernel memory it shouldn't be seeing? > Understood. It can leak information to the user if the user buffer is large enough. > I'm guessing it does, otherwise this would be a bigger issue than this > patch series. > I will think about how to fix it. At first glance, it seems we'd better introduce a new BPF helper like bpf_probe_read_kernel_str_pad(). -- Thanks Yafang