Re: [PATCH net] net/sched: cls_bpf: reject dev-bound programs bound to a different device

Jamal Hadi Salim <[email protected]>
Newsgroups org.kernel.vger.netdev,org.kernel.vger.bpf,org.kernel.vger.stable
Message-ID <CAM0EoMke_qk2jJdWW0rHvZcwMNd7RCG4xGkpNYZpPtrSKg2Q3A@mail.gmail.com>
On Mon, Aug 10, 2026 at 8:05 PM Jakub Kicinski <[email protected]> wrote:
>
> On Sun,  9 Aug 2026 05:44:18 -0400 Jamal Hadi Salim wrote:
> > cls_bpf_prog_from_efd() obtained a SCHED_CLS program via
> > bpf_prog_get_type_dev() but never verified that a device-bound (offloaded)
> > program's bound netdev matches the TC netdev the classifier is being
> > attached to. This let a program loaded with prog_ifindex for device A be
> > attached via cls_bpf + skip_sw to device B; deleting device A then
> > destroyed the program's offload state while it was still attached to
> > device B, triggering a netdevsim WARN (panic with panic_on_warn=1).
>
> maybe netdevsim has a bug then.
>

Looking closely: You're right. nfp guards at the driver
(bpf_offload_dev_match() at
while netdevsim's cls_bpf path checks boundness, not the device match.

> > Mirror the XDP attach path (net/core/dev.c) and reject the attach with
> > -EINVAL when a dev-bound program's bound device does not match the
> > target device.
> >
> > Fixes: 6c8dfe21c435 ("cls_bpf: allow attaching programs loaded for specific device")
>
> This commit in itself is fine, nfp checks that the offload matches:
> https://elixir.bootlin.com/linux/v7.2-rc5/source/drivers/net/ethernet/netronome/nfp/bpf/offload.c#L579
>
> Maybe the bound-devs got extended for JIT / descriptor access, and
> that added some extra risk here. So either this is netdevsim-only
> (and not worth the Fixes tag), or the Fixes tag is wrong..

Fixes tag is definetely wrong. 6c8dfe21c435 was fine for nfp; the
semantic shift happened from Stan's fix in 2b3486bc2d23 (made
prog->aux->offload non-NULL for dev-bound progs). c0c6bde586c7 then
fixed netdevsim XDP but missed cls_bpf.

It seems a v2 may be worth it:
fix netdevsim's cls_bpf path (Fixes: 2b3486bc2d23), keep the core
check as defense-in-depth without the bogus Fixes:, and walk
block->ports for shared blocks (block->q is NULL there). Or drop the
core change and fix only netdevsim. What says you?

cheers,
jamal
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.