Contributors: 3
Author Tokens Token Proportion Commits Commit Proportion
Mykyta Yatsenko 303 73.37% 1 25.00%
Amery Hung 108 26.15% 2 50.00%
Yonghong Song 2 0.48% 1 25.00%
Total 413 4


// SPDX-License-Identifier: GPL-2.0
/* Copyright (c) 2025 Meta Platforms, Inc. and affiliates. */

#include <vmlinux.h>
#include <string.h>
#include <stdbool.h>
#include <bpf/bpf_tracing.h>
#include "bpf_misc.h"

char _license[] SEC("license") = "GPL";

int err;
void *user_ptr;

SEC("lsm/file_open")
__failure
__msg("Unreleased reference id=")
int on_nanosleep_unreleased_ref(void *ctx)
{
	struct task_struct *task = bpf_get_current_task_btf();
	struct file *file = bpf_get_task_exe_file(task);
	struct bpf_dynptr dynptr;

	if (!file)
		return 0;

	err = bpf_dynptr_from_file(file, 0, &dynptr);
	return err ? 1 : 0;
}

SEC("xdp")
__failure
__msg("Expected a dynptr of type file as R1")
int xdp_wrong_dynptr_type(struct xdp_md *xdp)
{
	struct bpf_dynptr dynptr;

	bpf_dynptr_from_xdp(xdp, 0, &dynptr);
	bpf_dynptr_file_discard(&dynptr);
	return 0;
}

SEC("xdp")
__failure
__msg("Expected an initialized dynptr as R1")
int xdp_no_dynptr_type(struct xdp_md *xdp)
{
	struct bpf_dynptr dynptr;

	bpf_dynptr_file_discard(&dynptr);
	return 0;
}

SEC("lsm/file_open")
__failure
__msg("Leaking reference id={{[0-9]+}} alloc_insn={{[0-9]+}}. Release it first.")
int use_file_dynptr_after_put_file(void *ctx)
{
	struct task_struct *task = bpf_get_current_task_btf();
	struct file *file = bpf_get_task_exe_file(task);
	struct bpf_dynptr dynptr;
	char buf[64];

	if (!file)
		return 0;

	if (bpf_dynptr_from_file(file, 0, &dynptr))
		goto out;

	/* this should fail - file dynptr should be discarded first to prevent resource leak */
	bpf_put_file(file);

	bpf_dynptr_read(buf, sizeof(buf), &dynptr, 0, 0);
	return 0;

out:
	bpf_dynptr_file_discard(&dynptr);
	bpf_put_file(file);
	return 0;
}

SEC("lsm/file_open")
__failure
__msg("Leaking reference id={{[0-9]+}} alloc_insn={{[0-9]+}}. Release it first.")
int use_file_dynptr_slice_after_put_file(void *ctx)
{
	struct task_struct *task = bpf_get_current_task_btf();
	struct file *file = bpf_get_task_exe_file(task);
	struct bpf_dynptr dynptr;
	char buf[1];
	const char *data;

	if (!file)
		return 0;

	if (bpf_dynptr_from_file(file, 0, &dynptr))
		goto out;

	data = bpf_dynptr_slice(&dynptr, 0, buf, sizeof(buf));
	if (!data)
		goto out;

	/* this should fail - file dynptr should be discarded first to prevent resource leak */
	bpf_put_file(file);

	return data[0];

out:
	bpf_dynptr_file_discard(&dynptr);
	bpf_put_file(file);
	return 0;
}