From: Chenbo Feng <chenbofeng.kernel@gmail.com>
To: "David S . Miller" <davem@davemloft.net>,
Alexei Starovoitov <ast@fb.com>,
netdev@vger.kernel.org
Cc: Willem de Bruijn <willemb@google.com>,
Lorenzo Colitti <lorenzo@google.com>,
Chenbo Feng <fengc@google.com>,
Chenbo Feng <chenbofeng.kernel@gmail.com>
Subject: [PATCH net-next 2/2] Add a eBPF helper function to retrieve socket uid
Date: Thu, 2 Feb 2017 12:59:50 -0800 [thread overview]
Message-ID: <20170202205950.100334-3-chenbofeng.kernel@gmail.com> (raw)
In-Reply-To: <20170202205950.100334-1-chenbofeng.kernel@gmail.com>
From: Chenbo Feng <fengc@google.com>
Returns the owner uid of the socket inside a sk_buff. This is useful to
perform per-UID accounting of network traffic or per-UID packet
filtering.
Signed-off-by: Chenbo Feng <chenbofeng.kernel@gmail.com>
---
include/linux/bpf.h | 1 +
include/uapi/linux/bpf.h | 9 ++++++++-
net/core/filter.c | 19 +++++++++++++++++++
3 files changed, 28 insertions(+), 1 deletion(-)
diff --git a/include/linux/bpf.h b/include/linux/bpf.h
index 3f2e0af28c6e..c775ca4678b7 100644
--- a/include/linux/bpf.h
+++ b/include/linux/bpf.h
@@ -350,6 +350,7 @@ extern const struct bpf_func_proto bpf_skb_vlan_push_proto;
extern const struct bpf_func_proto bpf_skb_vlan_pop_proto;
extern const struct bpf_func_proto bpf_get_stackid_proto;
extern const struct bpf_func_proto bpf_get_socket_cookie_proto;
+extern const struct bpf_func_proto bpf_get_socket_uid_proto;
/* Shared helpers among cBPF and eBPF. */
void bpf_user_rnd_init_once(void);
diff --git a/include/uapi/linux/bpf.h b/include/uapi/linux/bpf.h
index 62ee5fab08e5..dad4dc7aca49 100644
--- a/include/uapi/linux/bpf.h
+++ b/include/uapi/linux/bpf.h
@@ -436,6 +436,12 @@ union bpf_attr {
* @skb: pointer to skb
* Return: 8 Bytes non-decreasing number on success or 0 if the socket
* field is missing inside sk_buff
+ *
+ * u32 bpf_get_socket_uid(skb)
+ * Get the owner uid of the socket stored inside sk_buff.
+ * @skb: pointer to skb
+ * Return: uid of the socket owner on success or 0 if the socket pointer
+ * inside sk_buff is NULL
*/
#define __BPF_FUNC_MAPPER(FN) \
FN(unspec), \
@@ -483,7 +489,8 @@ union bpf_attr {
FN(get_numa_node_id), \
FN(skb_change_head), \
FN(xdp_adjust_head), \
- FN(get_socket_cookie),
+ FN(get_socket_cookie), \
+ FN(get_socket_uid),
/* integer value in 'imm' field of BPF_CALL instruction selects which helper
* function eBPF program intends to call
diff --git a/net/core/filter.c b/net/core/filter.c
index 913b14d3b484..bc36ed72551f 100644
--- a/net/core/filter.c
+++ b/net/core/filter.c
@@ -2610,6 +2610,23 @@ const struct bpf_func_proto bpf_get_socket_cookie_proto = {
.arg1_type = ARG_PTR_TO_CTX,
};
+BPF_CALL_1(bpf_get_socket_uid, struct sk_buff *, skb)
+{
+ struct sock *sk;
+ kuid_t kuid;
+
+ sk = skb->sk;
+ kuid = sock_net_uid(dev_net(skb->dev), sk);
+ return (u32)kuid.val;
+}
+
+const struct bpf_func_proto bpf_get_socket_uid_proto = {
+ .func = bpf_get_socket_uid,
+ .gpl_only = false,
+ .ret_type = RET_INTEGER,
+ .arg1_type = ARG_PTR_TO_CTX,
+};
+
static const struct bpf_func_proto *
sk_filter_func_proto(enum bpf_func_id func_id)
{
@@ -2635,6 +2652,8 @@ sk_filter_func_proto(enum bpf_func_id func_id)
return bpf_get_trace_printk_proto();
case BPF_FUNC_get_socket_cookie:
return &bpf_get_socket_cookie_proto;
+ case BPF_FUNC_get_socket_uid:
+ return &bpf_get_socket_uid_proto;
default:
return NULL;
}
--
2.11.0.483.g087da7b7c-goog
next prev parent reply other threads:[~2017-02-02 21:00 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-02-02 20:59 [PATCH net-next 0/2] net: core: Two Helper function about socket information Chenbo Feng
2017-02-02 20:59 ` [PATCH net-next 1/2] Add a helper function to get socket cookie in eBPF Chenbo Feng
2017-02-02 21:23 ` Daniel Borkmann
2017-02-02 20:59 ` Chenbo Feng [this message]
2017-02-02 21:32 ` [PATCH net-next 2/2] Add a eBPF helper function to retrieve socket uid Daniel Borkmann
2017-02-03 0:00 ` Lorenzo Colitti
2017-02-03 0:28 ` Daniel Borkmann
2017-02-03 0:31 ` Eric Dumazet
2017-02-03 1:18 ` Lorenzo Colitti
2017-02-03 1:51 ` Eric Dumazet
2017-02-03 8:25 ` Daniel Borkmann
2017-02-06 3:25 ` Lorenzo Colitti
2017-02-03 0:13 ` [PATCH net-next 0/2] net: core: Two Helper function about socket information Alexei Starovoitov
2017-02-03 16:19 ` Lorenzo Colitti
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20170202205950.100334-3-chenbofeng.kernel@gmail.com \
--to=chenbofeng.kernel@gmail.com \
--cc=ast@fb.com \
--cc=davem@davemloft.net \
--cc=fengc@google.com \
--cc=lorenzo@google.com \
--cc=netdev@vger.kernel.org \
--cc=willemb@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.