summaryrefslogtreecommitdiff
path: root/tools/testing/selftests/bpf/progs/verifier_btf_flex_array.c
blob: 59b84261f6226a3c20a771fcab48945c5636ac16 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
// SPDX-License-Identifier: GPL-2.0

#include <vmlinux.h>
#include <bpf/bpf_helpers.h>

#include "bpf_experimental.h"
#include "bpf_misc.h"

struct test_empty_event {};

struct test_flex_batch {
	int nr;
	struct test_empty_event events[];
};

struct map_value {
	struct test_flex_batch __kptr *batch;
};

struct {
	__uint(type, BPF_MAP_TYPE_ARRAY);
	__type(key, int);
	__type(value, struct map_value);
	__uint(max_entries, 1);
} batches SEC(".maps");

SEC("syscall")
__description("btf walk into flexible array of zero-sized elements")
__failure __msg("access beyond struct test_flex_batch at off 4 size 1")
int stash_and_peek(void *ctx)
{
	struct test_flex_batch *b, *old;
	struct map_value *v;
	int key = 0;

	v = bpf_map_lookup_elem(&batches, &key);
	if (!v)
		return 0;

	b = bpf_obj_new(struct test_flex_batch);
	if (!b)
		return 0;
	b->nr = 1;

	old = bpf_kptr_xchg(&v->batch, b);
	if (old)
		bpf_obj_drop(old);

	b = v->batch;
	if (!b)
		return 0;

	return b->nr + *(char *)&b->events[0];
}

char _license[] SEC("license") = "GPL";