summaryrefslogtreecommitdiff
path: root/mm/page_counter.c
diff options
context:
space:
mode:
authorJann Horn <jannh@google.com>2018-10-05 18:17:59 +0200
committerDaniel Borkmann <daniel@iogearbox.net>2018-10-05 18:41:45 +0200
commitb799207e1e1816b09e7a5920fbb2d5fcf6edd681 (patch)
treec3e93b0287fc25e137120342f98953362a27a555 /mm/page_counter.c
parentb0584ea66d73919cbf5878a3420a837f06ab8396 (diff)
downloadlwn-b799207e1e1816b09e7a5920fbb2d5fcf6edd681.tar.gz
lwn-b799207e1e1816b09e7a5920fbb2d5fcf6edd681.zip
bpf: 32-bit RSH verification must truncate input before the ALU op
When I wrote commit 468f6eafa6c4 ("bpf: fix 32-bit ALU op verification"), I assumed that, in order to emulate 64-bit arithmetic with 32-bit logic, it is sufficient to just truncate the output to 32 bits; and so I just moved the register size coercion that used to be at the start of the function to the end of the function. That assumption is true for almost every op, but not for 32-bit right shifts, because those can propagate information towards the least significant bit. Fix it by always truncating inputs for 32-bit ops to 32 bits. Also get rid of the coerce_reg_to_size() after the ALU op, since that has no effect. Fixes: 468f6eafa6c4 ("bpf: fix 32-bit ALU op verification") Acked-by: Daniel Borkmann <daniel@iogearbox.net> Signed-off-by: Jann Horn <jannh@google.com> Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Diffstat (limited to 'mm/page_counter.c')
0 files changed, 0 insertions, 0 deletions