Re: [PATCH bpf] bpf: fix off-by-one error in adjust_subprog_starts

From: Y Song
Date: Fri Nov 16 2018 - 19:44:52 EST


On Fri, Nov 16, 2018 at 12:00 PM Edward Cree <ecree@xxxxxxxxxxxxxx> wrote:
>
> When patching in a new sequence for the first insn of a subprog, the start
> of that subprog does not change (it's the first insn of the sequence), so
> adjust_subprog_starts should check start <= off (rather than < off).
> Also added a test to test_verifier.c (it's essentially the syz reproducer).
>
> Fixes: cc8b0b92a169 ("bpf: introduce function calls (function boundaries)")
> Reported-by: syzbot+4fc427c7af994b0948be@xxxxxxxxxxxxxxxxxxxxxxxxx
> Signed-off-by: Edward Cree <ecree@xxxxxxxxxxxxxx>

Acked-by: Yonghong Song <yhs@xxxxxx>