Skip to content

Commit 7f12c33

Browse files
charmitroborkmann
authored andcommitted
net, bpf: Fix RCU usage in task_cls_state() for BPF programs
The commit ee97163 ("bpf: Allow some trace helpers for all prog types") made bpf_get_cgroup_classid_curr helper available to all BPF program types, not just networking programs. This helper calls __task_get_classid() which internally calls task_cls_state() requiring rcu_read_lock_bh_held(). This works in networking/tc context where RCU BH is held, but triggers an RCU warning when called from other contexts like BPF syscall programs that run under rcu_read_lock_trace(): WARNING: suspicious RCU usage 6.15.0-rc4-syzkaller-g079e5c56a5c4 #0 Not tainted ----------------------------- net/core/netclassid_cgroup.c:24 suspicious rcu_dereference_check() usage! Fix this by also accepting rcu_read_lock_held() and rcu_read_lock_trace_held() as valid RCU contexts in the task_cls_state() function. This ensures the helper works correctly in all needed RCU contexts where it might be called, regular RCU, RCU BH (for networking), and RCU trace (for BPF syscall programs). Fixes: ee97163 ("bpf: Allow some trace helpers for all prog types") Reported-by: [email protected] Signed-off-by: Charalampos Mitrodimas <[email protected]> Signed-off-by: Daniel Borkmann <[email protected]> Acked-by: Daniel Borkmann <[email protected]> Link: https://lore.kernel.org/bpf/[email protected] Closes: https://syzkaller.appspot.com/bug?extid=b4169a1cfb945d2ed0ec
1 parent f1c0257 commit 7f12c33

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

net/core/netclassid_cgroup.c

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,9 @@ static inline struct cgroup_cls_state *css_cls_state(struct cgroup_subsys_state
2121
struct cgroup_cls_state *task_cls_state(struct task_struct *p)
2222
{
2323
return css_cls_state(task_css_check(p, net_cls_cgrp_id,
24-
rcu_read_lock_bh_held()));
24+
rcu_read_lock_held() ||
25+
rcu_read_lock_bh_held() ||
26+
rcu_read_lock_trace_held()));
2527
}
2628
EXPORT_SYMBOL_GPL(task_cls_state);
2729

0 commit comments

Comments
 (0)