On Thu, Apr 28, 2016 at 3:56 AM, Alexei Starovoitov <a...@fb.com> wrote: > The commit 35578d798400 ("bpf: Implement function bpf_perf_event_read() that > get the selected hardware PMU conuter") > introduced clever way to check bpf_helper<->map_type compatibility. > Later on commit a43eec304259 ("bpf: introduce bpf_perf_event_output() > helper") adjusted > the logic and inadvertently broke it. > Get rid of the clever bool compare and go back to two-way check > from map and from helper perspective. > > Fixes: a43eec304259 ("bpf: introduce bpf_perf_event_output() helper") > Reported-by: Jann Horn <ja...@google.com> > Signed-off-by: Alexei Starovoitov <a...@kernel.org> > Signed-off-by: Daniel Borkmann <dan...@iogearbox.net> > --- > kernel/bpf/verifier.c | 65 > +++++++++++++++++++++++++++++++-------------------- > 1 file changed, 40 insertions(+), 25 deletions(-) > > diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c > index 89bcaa0966da..c5c17a62f509 100644 > --- a/kernel/bpf/verifier.c > +++ b/kernel/bpf/verifier.c [...] > + case BPF_MAP_TYPE_PROG_ARRAY: > + if (func_id != BPF_FUNC_tail_call) > + goto error; > + break; > + case BPF_MAP_TYPE_PERF_EVENT_ARRAY: > + if (func_id != BPF_FUNC_perf_event_read && > + func_id != BPF_FUNC_perf_event_output) > + goto error; > + break; > + case BPF_MAP_TYPE_STACK_TRACE: > + if (func_id != BPF_FUNC_get_stackid) > + goto error; > + break; > + default: > + break; > + } > + > + /* ... and second from the function itself. */ > + switch (func_id) { > + case BPF_FUNC_tail_call: > + if (map->map_type != BPF_MAP_TYPE_PROG_ARRAY) > + goto error; > + break; > + case BPF_FUNC_perf_event_read: > + case BPF_FUNC_perf_event_output: > + if (map->map_type != BPF_MAP_TYPE_PERF_EVENT_ARRAY) > + goto error; > + break; > + case BPF_FUNC_get_stackid: > + if (map->map_type != BPF_MAP_TYPE_STACK_TRACE) > + goto error; > + break; > + default: > + break; > }
Looks good to me.