Files
linux-stable-mirror/tools/testing/selftests/bpf/progs/file_reader_fail.c
T
Amery HungandAlexei Starovoitov d83d4f63cb selftests/bpf: Use bpf_dynptr_slice() to read file dynptr in leak test
use_file_dynptr_slice_after_put_file() reads the dynptr via
bpf_dynptr_data(), which always returns NULL for a read-only file
dynptr, making the example confusing. Switch to bpf_dynptr_slice(), the
correct read API for file dynptrs, and read (rather than write) the slice
since it is read-only. The test still fails as expected.

Acked-by: Eduard Zingerman <eddyz87@gmail.com>
Signed-off-by: Amery Hung <ameryhung@gmail.com>
Link: https://lore.kernel.org/r/20260605202056.1780352-6-ameryhung@gmail.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
2026-06-05 14:18:20 -07:00

113 lines
2.3 KiB
C

// SPDX-License-Identifier: GPL-2.0
/* Copyright (c) 2025 Meta Platforms, Inc. and affiliates. */
#include <vmlinux.h>
#include <string.h>
#include <stdbool.h>
#include <bpf/bpf_tracing.h>
#include "bpf_misc.h"
char _license[] SEC("license") = "GPL";
int err;
void *user_ptr;
SEC("lsm/file_open")
__failure
__msg("Unreleased reference id=")
int on_nanosleep_unreleased_ref(void *ctx)
{
struct task_struct *task = bpf_get_current_task_btf();
struct file *file = bpf_get_task_exe_file(task);
struct bpf_dynptr dynptr;
if (!file)
return 0;
err = bpf_dynptr_from_file(file, 0, &dynptr);
return err ? 1 : 0;
}
SEC("xdp")
__failure
__msg("Expected a dynptr of type file as R1")
int xdp_wrong_dynptr_type(struct xdp_md *xdp)
{
struct bpf_dynptr dynptr;
bpf_dynptr_from_xdp(xdp, 0, &dynptr);
bpf_dynptr_file_discard(&dynptr);
return 0;
}
SEC("xdp")
__failure
__msg("Expected an initialized dynptr as R1")
int xdp_no_dynptr_type(struct xdp_md *xdp)
{
struct bpf_dynptr dynptr;
bpf_dynptr_file_discard(&dynptr);
return 0;
}
SEC("lsm/file_open")
__failure
__msg("Leaking reference id={{[0-9]+}} alloc_insn={{[0-9]+}}. Release it first.")
int use_file_dynptr_after_put_file(void *ctx)
{
struct task_struct *task = bpf_get_current_task_btf();
struct file *file = bpf_get_task_exe_file(task);
struct bpf_dynptr dynptr;
char buf[64];
if (!file)
return 0;
if (bpf_dynptr_from_file(file, 0, &dynptr))
goto out;
/* this should fail - file dynptr should be discarded first to prevent resource leak */
bpf_put_file(file);
bpf_dynptr_read(buf, sizeof(buf), &dynptr, 0, 0);
return 0;
out:
bpf_dynptr_file_discard(&dynptr);
bpf_put_file(file);
return 0;
}
SEC("lsm/file_open")
__failure
__msg("Leaking reference id={{[0-9]+}} alloc_insn={{[0-9]+}}. Release it first.")
int use_file_dynptr_slice_after_put_file(void *ctx)
{
struct task_struct *task = bpf_get_current_task_btf();
struct file *file = bpf_get_task_exe_file(task);
struct bpf_dynptr dynptr;
char buf[1];
const char *data;
if (!file)
return 0;
if (bpf_dynptr_from_file(file, 0, &dynptr))
goto out;
data = bpf_dynptr_slice(&dynptr, 0, buf, sizeof(buf));
if (!data)
goto out;
/* this should fail - file dynptr should be discarded first to prevent resource leak */
bpf_put_file(file);
return data[0];
out:
bpf_dynptr_file_discard(&dynptr);
bpf_put_file(file);
return 0;
}