fix(driver/modern_bpf): read signal_deliver siginfo via BPF_CORE_READ - #3119
Conversation
Signal tracepoints can receive the `SEND_SIG_NOINFO` (0) and
`SEND_SIG_PRIV` (1) sentinels in place of a real `kernel_siginfo`
pointer. Since `SEND_SIG_PRIV` survives a NULL check, kernel commit
77515ab12e49 ("bpf: Mark signal tracepoint siginfo arguments as
scalar") lists `signal_generate` and `signal_deliver` in
`raw_tp_null_args[]` and exposes the `info` argument to `tp_btf`
programs as a scalar.
With that change the verifier rejects the direct `info->...` accesses
in the `signal_deliver` program with "invalid mem access 'scalar'",
and since all programs are loaded together the modern probe fails to
load entirely (seen on 6.18.53).
Read the fields through `BPF_CORE_READ` instead. It is accepted both
when `info` is a scalar and when it is a BTF pointer, so older
kernels keep working. The resulting `spid` values are unchanged.
Link: torvalds/linux@77515ab
Signed-off-by: Adnan Ali <adduali1310@hotmail.com>
Perf diff from master - unit testsHeap diff from master - unit testsHeap diff from master - scap fileBenchmarks diff from master |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #3119 +/- ##
=======================================
Coverage 76.71% 76.71%
=======================================
Files 303 303
Lines 34393 34393
Branches 5151 5149 -2
=======================================
Hits 26386 26386
Misses 8007 8007
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
LGTM label has been added. DetailsGit tree hash: b3ec0173e4485f1923acdb7fbf81a072d887c35f |
|
cc @gnosek |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: adduali1310, leogr, terror96 The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
/milestone 0.26.1 |
Signal tracepoints can receive the
SEND_SIG_NOINFO(0) andSEND_SIG_PRIV(1) sentinels in place of a realkernel_siginfopointer. SinceSEND_SIG_PRIVsurvives a NULL check, kernel commit 77515ab12e49 ("bpf: Mark signal tracepoint siginfo arguments as scalar") listssignal_generateandsignal_deliverinraw_tp_null_args[]and exposes theinfoargument totp_btfprograms as a scalar.With that change the verifier rejects the direct
info->...accesses in thesignal_deliverprogram with "invalid mem access 'scalar'", and since all programs are loaded together the modern probe fails to load entirely (seen on 6.18.53).Read the fields through
BPF_CORE_READinstead. It is accepted both wheninfois a scalar and when it is a BTF pointer, so older kernels keep working. The resultingspidvalues are unchanged.Link: torvalds/linux@77515ab
What type of PR is this?
/kind bug
Any specific area of the project related to this PR?
/area driver-modern-bpf
What this PR does / why we need it:
Newer kernels add
signal_generateandsignal_delivertoraw_tp_null_args[]and expose theirinfoargument totp_btfprograms as a scalar, because it can be theSEND_SIG_PRIV(1) sentinel rather than a realpointer. The verifier then rejects the direct
info->...dereferences in oursignal_deliverprogram (invalid mem access 'scalar') and the whole modern probe fails to load (seen on 6.18.53).This switches those reads to
BPF_CORE_READ, which the verifier accepts for both the scalar and the BTF pointer case, so older kernels are unaffected. The kmod is not affected.Kernel commit: 77515ab12e49 ("bpf: Mark signal tracepoint siginfo arguments as scalar")
Which issue(s) this PR fixes:
Fixes #3118
Special notes for your reviewer:
Does this PR introduce a user-facing change?:
No