fix(ebpf): relax MySQL split header length check#11794
Open
yinjiping wants to merge 1 commit into
Open
Conversation
| count += 4; | ||
| com = buf[0]; | ||
| point_1 = buf[2]; | ||
| point_2 = buf[4]; |
Contributor
Author
There was a problem hiding this comment.
#define INFER_BUF_MAX 32
/*
* BPF Tail Calls context
*/
struct infer_data_s {
__u32 len;
char data[INFER_BUF_MAX * 2];
};
infer_mysql_message(infer_buf, count,
conn_info))
传递参数是 infer_buf, 他是固定大小的事先缓存内存块,mysql的推断用到的数据不会超过32字节, 推断的数据在9字节以内进行,因此不会出现越界情况,另外我count < 9检查防止脏数据。
/*
* To prevent stale data from a previous map value remaining in
* the unused portion of `__infer_buf->data` when the current
* syscall provides fewer than 9 bytes of actual data.
*/
if (count < 9) {
point_1 = point_2 = 0;
}
我测试内核 4.14, 4.19, 5.15 正常
When MySQL packet header is read separately, prev_count == 4 means the 4-byte MySQL header has already been cached and the current buffer starts from the payload. The packet payload length in the MySQL header does not necessarily equal the current syscall read/write length. Requiring len == count may cause valid split packets to skip MySQL inference. Remove this strict check and always parse seq from the cached header and command bytes from the current payload buffer in the prev_count == 4 path. The later full packet length validation is still kept for initial protocol confirmation.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

When MySQL packet header is read separately, prev_count == 4 means the 4-byte MySQL header has already been cached and the current buffer starts from the payload.
The packet payload length in the MySQL header does not necessarily equal the current syscall read/write length. Requiring len == count may cause valid split packets to skip MySQL inference.
Remove this strict check and always parse seq from the cached header and command bytes from the current payload buffer in the prev_count == 4 path. The later full packet length validation is still kept for initial protocol confirmation.
This PR is for:
Affected branches