Re: [PATCH net] net/sched: cls_bpf: reject dev-bound programs bound to a different device
Jakub Kicinski <[email protected]>
| Newsgroups | org.kernel.vger.netdev,org.kernel.vger.bpf,org.kernel.vger.stable |
|---|---|
| Message-ID | <[email protected]> |
On Sun, 9 Aug 2026 05:44:18 -0400 Jamal Hadi Salim wrote:
> cls_bpf_prog_from_efd() obtained a SCHED_CLS program via
> bpf_prog_get_type_dev() but never verified that a device-bound (offloaded)
> program's bound netdev matches the TC netdev the classifier is being
> attached to. This let a program loaded with prog_ifindex for device A be
> attached via cls_bpf + skip_sw to device B; deleting device A then
> destroyed the program's offload state while it was still attached to
> device B, triggering a netdevsim WARN (panic with panic_on_warn=1).
maybe netdevsim has a bug then.
> Mirror the XDP attach path (net/core/dev.c) and reject the attach with
> -EINVAL when a dev-bound program's bound device does not match the
> target device.
>
> Fixes: 6c8dfe21c435 ("cls_bpf: allow attaching programs loaded for specific device")
This commit in itself is fine, nfp checks that the offload matches:
https://elixir.bootlin.com/linux/v7.2-rc5/source/drivers/net/ethernet/netronome/nfp/bpf/offload.c#L579
Maybe the bound-devs got extended for JIT / descriptor access, and
that added some extra risk here. So either this is netdevsim-only
(and not worth the Fixes tag), or the Fixes tag is wrong..