Re: [PATCH bpf-next v4 00/20] Add return value range check for BPF LSM

2024-07-18 Thread Xu Kuohai
On 7/19/2024 10:13 AM, Paul Moore wrote: On Fri, Jul 12, 2024 at 5:44 PM Paul Moore wrote: On Thu, Jul 11, 2024 at 7:13 AM Xu Kuohai wrote: From: Xu Kuohai LSM BPF prog returning a positive number attached to the hook file_alloc_security makes kernel panic. Here is a panic log: [ 441.235

Re: [PATCH bpf-next v4 00/20] Add return value range check for BPF LSM

2024-07-18 Thread Paul Moore
On Fri, Jul 12, 2024 at 5:44 PM Paul Moore wrote: > On Thu, Jul 11, 2024 at 7:13 AM Xu Kuohai wrote: > > From: Xu Kuohai > > > > LSM BPF prog returning a positive number attached to the hook > > file_alloc_security makes kernel panic. > > > > Here is a panic log: > > > > [ 441.235774] BUG: kern

Re: [PATCH bpf-next v4 00/20] Add return value range check for BPF LSM

2024-07-12 Thread Paul Moore
On Thu, Jul 11, 2024 at 7:13 AM Xu Kuohai wrote: > > From: Xu Kuohai > > LSM BPF prog returning a positive number attached to the hook > file_alloc_security makes kernel panic. > > Here is a panic log: > > [ 441.235774] BUG: kernel NULL pointer dereference, address: 09 > [ 441.23674

Re: [PATCH bpf-next v4 00/20] Add return value range check for BPF LSM

2024-07-12 Thread Paul Moore
On Fri, Jul 12, 2024 at 11:56 AM Paul Moore wrote: > On Thu, Jul 11, 2024 at 7:13 AM Xu Kuohai wrote: > > > > From: Xu Kuohai > > > > LSM BPF prog returning a positive number attached to the hook > > file_alloc_security makes kernel panic. > > ... > > > Xu Kuohai (20): > > lsm: Refactor return

Re: [PATCH bpf-next v4 00/20] Add return value range check for BPF LSM

2024-07-12 Thread Paul Moore
On Thu, Jul 11, 2024 at 7:13 AM Xu Kuohai wrote: > > From: Xu Kuohai > > LSM BPF prog returning a positive number attached to the hook > file_alloc_security makes kernel panic. ... > Xu Kuohai (20): > lsm: Refactor return value of LSM hook vm_enough_memory > lsm: Refactor return value of LS

[PATCH bpf-next v4 00/20] Add return value range check for BPF LSM

2024-07-11 Thread Xu Kuohai
From: Xu Kuohai LSM BPF prog returning a positive number attached to the hook file_alloc_security makes kernel panic. Here is a panic log: [ 441.235774] BUG: kernel NULL pointer dereference, address: 09 [ 441.236748] #PF: supervisor write access in kernel mode [ 441.237429] #PF: