Re: [PATCH net] net/sched: cls_bpf: reject dev-bound programs bound to a different device
Jamal Hadi Salim <[email protected]>
| Newsgroups | org.kernel.vger.netdev,org.kernel.vger.bpf,org.kernel.vger.stable |
|---|---|
| Message-ID | <CAM0EoMke_qk2jJdWW0rHvZcwMNd7RCG4xGkpNYZpPtrSKg2Q3A@mail.gmail.com> |
On Mon, Aug 10, 2026 at 8:05 PM Jakub Kicinski <[email protected]> wrote: > > On Sun, 9 Aug 2026 05:44:18 -0400 Jamal Hadi Salim wrote: > > cls_bpf_prog_from_efd() obtained a SCHED_CLS program via > > bpf_prog_get_type_dev() but never verified that a device-bound (offloaded) > > program's bound netdev matches the TC netdev the classifier is being > > attached to. This let a program loaded with prog_ifindex for device A be > > attached via cls_bpf + skip_sw to device B; deleting device A then > > destroyed the program's offload state while it was still attached to > > device B, triggering a netdevsim WARN (panic with panic_on_warn=1). > > maybe netdevsim has a bug then. > Looking closely: You're right. nfp guards at the driver (bpf_offload_dev_match() at while netdevsim's cls_bpf path checks boundness, not the device match. > > Mirror the XDP attach path (net/core/dev.c) and reject the attach with > > -EINVAL when a dev-bound program's bound device does not match the > > target device. > > > > Fixes: 6c8dfe21c435 ("cls_bpf: allow attaching programs loaded for specific device") > > This commit in itself is fine, nfp checks that the offload matches: > https://elixir.bootlin.com/linux/v7.2-rc5/source/drivers/net/ethernet/netronome/nfp/bpf/offload.c#L579 > > Maybe the bound-devs got extended for JIT / descriptor access, and > that added some extra risk here. So either this is netdevsim-only > (and not worth the Fixes tag), or the Fixes tag is wrong.. Fixes tag is definetely wrong. 6c8dfe21c435 was fine for nfp; the semantic shift happened from Stan's fix in 2b3486bc2d23 (made prog->aux->offload non-NULL for dev-bound progs). c0c6bde586c7 then fixed netdevsim XDP but missed cls_bpf. It seems a v2 may be worth it: fix netdevsim's cls_bpf path (Fixes: 2b3486bc2d23), keep the core check as defense-in-depth without the bogus Fixes:, and walk block->ports for shared blocks (block->q is NULL there). Or drop the core change and fix only netdevsim. What says you? cheers, jamal