Re: [PATCH] bpf: Initialize IMA hash helper output buffers
From: Matt Bobrowski
Date: Mon Sep 28 2026 - 07:57:22 EST
On Mon, Sep 28, 2026 at 07:38:57AM +0000, Alexei Starovoitov wrote:
> On Sun, Sep 27, 2026 at 08:14 PM Jiale Yao <yaojiale02@xxxxxxx> wrote:
> > The output arguments of bpf_ima_inode_hash() and bpf_ima_file_hash()
> > are marked as ARG_PTR_TO_UNINIT_MEM, so the verifier considers the full
> > range initialized after either helper returns. The IMA hash functions,
> > however, leave the buffer unchanged on error and only copy the digest
> > length on success. A BPF program can therefore read stale data from
> > the untouched portion of the buffer.
>
> That's not a bug.
> These helpers are available to LSM progs only and LSM progs
> require CAP_PERFMON to load.
> With CAP_PERFMON the verifier allows reading uninitialized stack
> with or without the helper call.
>
> Since commit 5da4a9f26fca ("bpf: Preserve stack initialization for
> generic output buffers") MEM_UNINIT helpers don't have to write
> the whole buffer.
I suppose it's also worth noting that the return value already advises
the caller how much of the destination buffer is meaningful. On error,
nothing is written. On success, the returned hash_algo value identifies
the digest, and only that many bytes are written, so an oversized buffer
is expected to be only partially filled. This is also by design as
bpf_ima_{inode,file}_hash() already recommend passing a buffer large
enough for the largest possible hash (being IMA_MAX_DIGEST_SIZE). A
caller that honours the return value literally never needs to read the
untouched bytes.
With that said, this is a NACK from me.