]> www.infradead.org Git - users/jedix/linux-maple.git/commit
net: filter: make JITs zero A for SKF_AD_ALU_XOR_X
authorRabin Vincent <rabin@rab.in>
Tue, 5 Jan 2016 15:23:07 +0000 (16:23 +0100)
committerChuck Anderson <chuck.anderson@oracle.com>
Thu, 26 May 2016 22:43:22 +0000 (15:43 -0700)
commitc1200473a6c04f33fa7fb8c63fcaf2017b67d64b
treeddbd8b9b79d15928b0551d6c83da05781e1f240f
parent3ef0199fb21a8e7b5496cc1862efc22868b04d03
net: filter: make JITs zero A for SKF_AD_ALU_XOR_X

Orabug: 23330547

[ Upstream commit 55795ef5469290f89f04e12e662ded604909e462 ]

The SKF_AD_ALU_XOR_X ancillary is not like the other ancillary data
instructions since it XORs A with X while all the others replace A with
some loaded value.  All the BPF JITs fail to clear A if this is used as
the first instruction in a filter.  This was found using american fuzzy
lop.

Add a helper to determine if A needs to be cleared given the first
instruction in a filter, and use this in the JITs.  Except for ARM, the
rest have only been compile-tested.

Fixes: 3480593131e0 ("net: filter: get rid of BPF_S_* enum")
Signed-off-by: Rabin Vincent <rabin@rab.in>
Acked-by: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
(cherry picked from commit 5596242a6263ece70ee14f3b6861f02b8dc82d11)

Signed-off-by: Dan Duval <dan.duval@oracle.com>
arch/arm/net/bpf_jit_32.c
arch/mips/net/bpf_jit.c
arch/powerpc/net/bpf_jit_comp.c
arch/sparc/net/bpf_jit_comp.c
include/linux/filter.h