[PATCH bpf-next v4 0/3] bpf: prevent offloaded programs from running on host via tcx/netkit

Jiayuan Chen <[email protected]>
Newsgroups org.kernel.vger.linux-kselftest,org.kernel.vger.bpf,org.kernel.vger.linux-kernel,org.kernel.vger.netdev
Message-ID <[email protected]>
Patch 1 fixes the reported bug [1]. Patch 2 fixes an old bug that was
already there. Patch 3 is a test that reproduces the bug in patch 2.

Patch 1 has no test here: the original report already has a reproducer,
and it needs netdevsim, which is not easy to do in a selftest.

An offloaded program runs on the NIC, so its bpf_func is set to
bpf_prog_warn_on_exec(). tcx, netkit and XDP run programs on the host, so
attaching an offloaded program to them hits the WARN on the first packet.
Patch 1 adds the check in bpf_mprog_attach(), the one place both tcx and
netkit go through. Patch 2 moves the XDP check into dev_xdp_install() so
the bpf_xdp_link_update() path is covered too.


[1]: https://lore.kernel.org/bpf/[email protected]/
 ------------[ cut here ]------------
 attempt to execute device eBPF program on the host!
 WARNING: kernel/bpf/offload.c:420 at 0x0, CPU#0: poc/337
 PKRU: 55555554
 Call Trace:
  <TASK>
  __dev_queue_xmit+0x22cb/0x3530
  ip_finish_output2+0x621/0x1a60
  ip_output+0x170/0x2e0
  ip_send_skb+0x129/0x180
  udp_send_skb+0x65d/0x1300
  udp_sendmsg+0x13bf/0x2000
  __sys_sendto+0x396/0x470
  __x64_sys_sendto+0xdc/0x1b0
  do_syscall_64+0x76/0x10a0
  entry_SYSCALL_64_after_hwframe+0x76/0x7e
 ---[ end trace 0000000000000000 ]---

v3 -> v4:
  - patch 2: also move the two device-bound checks, not just the offload
    one, so the link update path can't skip them (from the AI review on v3).
  - add patch 3, a selftest for the link update path.
v3: https://lore.kernel.org/bpf/[email protected]/

v2 -> v3:
  - Alexei said to do the check in one place instead of spreading it
    across attach paths. Put it in bpf_mprog_attach() for tcx/netkit and
    move the XDP check into dev_xdp_install(). Three patches became two.
v2: https://lore.kernel.org/bpf/[email protected]/

v1 -> v2:
  - tcx/netkit: also reject offloaded progs in the link update callback,
    not just attach (from the AI review on v1).
  - add a patch for the same hole in bpf_xdp_link_update().
v1: https://lore.kernel.org/bpf/[email protected]/

Jiayuan Chen (3):
  bpf, tcx, netkit: reject offloaded programs
  bpf, xdp: move offload check into dev_xdp_install()
  selftests/bpf: xdp: test dev_xdp_install() rejects device-bound
    program

 kernel/bpf/mprog.c                            | 11 +++++
 net/core/dev.c                                | 27 +++++-----
 .../bpf/prog_tests/xdp_dev_bound_only.c       | 49 +++++++++++++++++++
 3 files changed, 75 insertions(+), 12 deletions(-)

-- 
2.43.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.