From: Daniel Borkmann <daniel@iogearbox.net>
To: ast@kernel.org
Cc: memxor@gmail.com, eddyz87@gmail.com, info@starlabs.sg,
bpf@vger.kernel.org
Subject: [PATCH bpf v2 3/4] bpf: Require CAP_PERFMON for untrusted read-only memory reads
Date: Thu, 10 Sep 2026 23:35:09 +0200 [thread overview]
Message-ID: <20260910213510.49358-3-daniel@iogearbox.net> (raw)
In-Reply-To: <20260910213510.49358-1-daniel@iogearbox.net>
Marking bpf_rdonly_cast() KF_PERFMON CAP-limits one producer of PTR_TO_MEM |
MEM_RDONLY | PTR_UNTRUSTED, but not the type itself. A global subprogram
argument tagged __arg_untrusted results in the same register with no kfunc
call.
Reported-by: STAR Labs SG <info@starlabs.sg>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
---
v1 -> v2:
- Fixed formatting bpf_diag_policy (Alexei)
- Dropped Fixes tags (Alexei)
kernel/bpf/verifier.c | 9 +++++++++
1 file changed, 9 insertions(+)
diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c
index 939e535a3442..8058f684a9ea 100644
--- a/kernel/bpf/verifier.c
+++ b/kernel/bpf/verifier.c
@@ -6453,6 +6453,15 @@ static int check_mem_access(struct bpf_verifier_env *env, int insn_idx, struct b
return -EACCES;
}
+ if (rdonly_untrusted && !env->allow_ptr_leaks) {
+ verbose(env, "%s access is allowed only to CAP_PERFMON and CAP_SYS_ADMIN\n",
+ reg_type_str(env, reg->type));
+ bpf_diag_policy(env, insn_idx, "read from untrusted read-only memory",
+ "the access requires CAP_PERFMON",
+ "Load the program with CAP_PERFMON, or avoid dereferencing untrusted pointers.");
+ return -EPERM;
+ }
+
/*
* Accesses to untrusted PTR_TO_MEM are done through probe
* instructions, hence no need to check bounds in that case.
--
2.43.0
next prev parent reply other threads:[~2026-09-10 21:35 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-10 21:35 [PATCH bpf v2 1/4] bpf: Add KF_PERFMON kfunc flag Daniel Borkmann
2026-09-10 21:35 ` [PATCH bpf v2 2/4] bpf: Require CAP_PERFMON for kfuncs reading memory Daniel Borkmann
2026-09-10 21:45 ` sashiko-bot
2026-09-10 22:33 ` bot+bpf-ci
2026-09-10 21:35 ` Daniel Borkmann [this message]
2026-09-10 22:33 ` [PATCH bpf v2 3/4] bpf: Require CAP_PERFMON for untrusted read-only memory reads bot+bpf-ci
2026-09-10 21:35 ` [PATCH bpf v2 4/4] selftests/bpf: Add tests for the KF_PERFMON gates Daniel Borkmann
2026-09-10 22:33 ` bot+bpf-ci
2026-09-11 0:00 ` [PATCH bpf v2 1/4] bpf: Add KF_PERFMON kfunc flag patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260910213510.49358-3-daniel@iogearbox.net \
--to=daniel@iogearbox.net \
--cc=ast@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=eddyz87@gmail.com \
--cc=info@starlabs.sg \
--cc=memxor@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.