diff options
| author | Kumar Kartikeya Dwivedi <memxor@gmail.com> | 2026-09-04 10:43:19 +0200 |
|---|---|---|
| committer | Alexei Starovoitov <ast@kernel.org> | 2026-09-04 07:58:36 -0700 |
| commit | 6668ed271eaefaa63e686bdfbedaeb7b8e492722 (patch) | |
| tree | 58e8288fead484f6755ad0815fc74c3742663761 /lib/decompress.c | |
| download | linux-stable-6668ed271eaefaa63e686bdfbedaeb7b8e492722.tar.gz linux-stable-6668ed271eaefaa63e686bdfbedaeb7b8e492722.zip | |
selftests/bpf: Reject graph kptr use after RCU unlockgrafted
Add a sleepable verifier test that loads a graph-node local kptr in an
explicit RCU read-side critical section, then passes its node to
bpf_rbtree_remove() after the section ends.
Before the verifier fix, the stale NON_OWN_REF flag makes the node look like
a live borrowed reference and the program is accepted. After the fix, the
pointer is demoted without NON_OWN_REF and the graph kfunc argument is
rejected.
Also exercise a graph kptr loaded while a spin lock provides implicit RCU
protection. The pointer must be invalidated when the lock is released, which
guards the required ordering between non-owning-reference invalidation and
RCU demotion.
Update the existing fault-protected load test state description. The
post-unlock pointer no longer carries NON_OWN_REF, but remains readable
because the load is rewritten to use BPF_PROBE_MEM.
Signed-off-by: Kumar Kartikeya Dwivedi <memxor@gmail.com>
Link: https://lore.kernel.org/r/20260904084325.52250-7-memxor@gmail.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Diffstat (limited to 'lib/decompress.c')
| -rw-r--r-- | lib/decompress.c | 83 |
1 files changed, 83 insertions, 0 deletions
diff --git a/lib/decompress.c b/lib/decompress.c new file mode 100644 index 000000000..778547158 --- /dev/null +++ b/lib/decompress.c @@ -0,0 +1,83 @@ +// SPDX-License-Identifier: GPL-2.0 +/* + * decompress.c + * + * Detect the decompression method based on magic number + */ + +#include <linux/decompress/generic.h> + +#include <linux/decompress/bunzip2.h> +#include <linux/decompress/unlzma.h> +#include <linux/decompress/unxz.h> +#include <linux/decompress/inflate.h> +#include <linux/decompress/unlzo.h> +#include <linux/decompress/unlz4.h> +#include <linux/decompress/unzstd.h> + +#include <linux/types.h> +#include <linux/string.h> +#include <linux/init.h> +#include <linux/printk.h> + +#ifndef CONFIG_DECOMPRESS_GZIP +# define gunzip NULL +#endif +#ifndef CONFIG_DECOMPRESS_BZIP2 +# define bunzip2 NULL +#endif +#ifndef CONFIG_DECOMPRESS_LZMA +# define unlzma NULL +#endif +#ifndef CONFIG_DECOMPRESS_XZ +# define unxz NULL +#endif +#ifndef CONFIG_DECOMPRESS_LZO +# define unlzo NULL +#endif +#ifndef CONFIG_DECOMPRESS_LZ4 +# define unlz4 NULL +#endif +#ifndef CONFIG_DECOMPRESS_ZSTD +# define unzstd NULL +#endif + +struct compress_format { + unsigned char magic[2]; + const char *name; + decompress_fn decompressor; +}; + +static const struct compress_format compressed_formats[] __initconst = { + { .magic = {0x1f, 0x8b}, .name = "gzip", .decompressor = gunzip }, + { .magic = {0x1f, 0x9e}, .name = "gzip", .decompressor = gunzip }, + { .magic = {0x42, 0x5a}, .name = "bzip2", .decompressor = bunzip2 }, + { .magic = {0x5d, 0x00}, .name = "lzma", .decompressor = unlzma }, + { .magic = {0xfd, 0x37}, .name = "xz", .decompressor = unxz }, + { .magic = {0x89, 0x4c}, .name = "lzo", .decompressor = unlzo }, + { .magic = {0x02, 0x21}, .name = "lz4", .decompressor = unlz4 }, + { .magic = {0x28, 0xb5}, .name = "zstd", .decompressor = unzstd }, + { /* sentinel */ } +}; + +decompress_fn __init decompress_method(const unsigned char *inbuf, long len, + const char **name) +{ + const struct compress_format *cf; + + if (len < 2) { + if (name) + *name = NULL; + return NULL; /* Need at least this much... */ + } + + pr_debug("Compressed data magic: %#.2x %#.2x\n", inbuf[0], inbuf[1]); + + for (cf = compressed_formats; cf->name; cf++) + if (!memcmp(inbuf, cf->magic, 2)) + break; + + if (name) + *name = cf->name; + return cf->decompressor; +} |
