mirror of
https://github.com/raspberrypi/linux.git
synced 2025-12-06 10:00:17 +00:00
arm64: bpf: fix mod-by-zero case
commit14e589ff4aupstream. Turns out in the case of modulo by zero in a BPF program: A = A % X; (X == 0) the expected behavior is to terminate with return value 0. The bug in JIT is exposed by a new test case [1]. [1] https://lkml.org/lkml/2015/11/4/499 Signed-off-by: Zi Shen Lim <zlim.lnx@gmail.com> Reported-by: Yang Shi <yang.shi@linaro.org> Reported-by: Xi Wang <xi.wang@gmail.com> CC: Alexei Starovoitov <ast@plumgrid.com> Fixes:e54bcde3d6("arm64: eBPF JIT compiler") Signed-off-by: Catalin Marinas <catalin.marinas@arm.com> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
committed by
Greg Kroah-Hartman
parent
40c5dde6eb
commit
f22c64cd07
@@ -269,6 +269,8 @@ static int build_insn(const struct bpf_insn *insn, struct jit_ctx *ctx)
|
|||||||
break;
|
break;
|
||||||
case BPF_ALU | BPF_DIV | BPF_X:
|
case BPF_ALU | BPF_DIV | BPF_X:
|
||||||
case BPF_ALU64 | BPF_DIV | BPF_X:
|
case BPF_ALU64 | BPF_DIV | BPF_X:
|
||||||
|
case BPF_ALU | BPF_MOD | BPF_X:
|
||||||
|
case BPF_ALU64 | BPF_MOD | BPF_X:
|
||||||
{
|
{
|
||||||
const u8 r0 = bpf2a64[BPF_REG_0];
|
const u8 r0 = bpf2a64[BPF_REG_0];
|
||||||
|
|
||||||
@@ -281,16 +283,19 @@ static int build_insn(const struct bpf_insn *insn, struct jit_ctx *ctx)
|
|||||||
check_imm26(jmp_offset);
|
check_imm26(jmp_offset);
|
||||||
emit(A64_B(jmp_offset), ctx);
|
emit(A64_B(jmp_offset), ctx);
|
||||||
/* else */
|
/* else */
|
||||||
|
switch (BPF_OP(code)) {
|
||||||
|
case BPF_DIV:
|
||||||
emit(A64_UDIV(is64, dst, dst, src), ctx);
|
emit(A64_UDIV(is64, dst, dst, src), ctx);
|
||||||
break;
|
break;
|
||||||
}
|
case BPF_MOD:
|
||||||
case BPF_ALU | BPF_MOD | BPF_X:
|
|
||||||
case BPF_ALU64 | BPF_MOD | BPF_X:
|
|
||||||
ctx->tmp_used = 1;
|
ctx->tmp_used = 1;
|
||||||
emit(A64_UDIV(is64, tmp, dst, src), ctx);
|
emit(A64_UDIV(is64, tmp, dst, src), ctx);
|
||||||
emit(A64_MUL(is64, tmp, tmp, src), ctx);
|
emit(A64_MUL(is64, tmp, tmp, src), ctx);
|
||||||
emit(A64_SUB(is64, dst, dst, tmp), ctx);
|
emit(A64_SUB(is64, dst, dst, tmp), ctx);
|
||||||
break;
|
break;
|
||||||
|
}
|
||||||
|
break;
|
||||||
|
}
|
||||||
case BPF_ALU | BPF_LSH | BPF_X:
|
case BPF_ALU | BPF_LSH | BPF_X:
|
||||||
case BPF_ALU64 | BPF_LSH | BPF_X:
|
case BPF_ALU64 | BPF_LSH | BPF_X:
|
||||||
emit(A64_LSLV(is64, dst, dst, src), ctx);
|
emit(A64_LSLV(is64, dst, dst, src), ctx);
|
||||||
|
|||||||
Reference in New Issue
Block a user