From: Shihuang Liu <shlomojune6@gmail.com>
To: netdev@vger.kernel.org
Cc: bpf@vger.kernel.org, linux-kernel@vger.kernel.org,
ast@kernel.org, daniel@iogearbox.net, andrii@kernel.org,
eddyz87@gmail.com, memxor@gmail.com, martin.lau@linux.dev,
song@kernel.org, yonghong.song@linux.dev, jolsa@kernel.org,
emil@etsalapatis.com, ihor.solodrai@linux.dev,
john.fastabend@gmail.com, sdf@fomichev.me, davem@davemloft.net,
edumazet@google.com, kuba@kernel.org, pabeni@redhat.com,
horms@kernel.org, akpm@linux-foundation.org,
leon.hwang@linux.dev, yatsenko@meta.com, kpsingh@kernel.org,
dmitry.baryshkov@oss.qualcomm.com, jordan@jrife.io,
nhudson@akamai.com, avinash.duduskar@gmail.com, rongtao@cestc.cn,
joe@wand.net.nz, Shihuang Liu <shlomojune6@gmail.com>
Subject: [PATCH bpf v2 2/2] bpf: revalidate assigned sockets after protocol change
Date: Sat, 12 Sep 2026 01:23:13 +0800 [thread overview]
Message-ID: <20260911172313.64009-2-shlomojune6@gmail.com> (raw)
In-Reply-To: <20260911172313.64009-1-shlomojune6@gmail.com>
An IPv4 packet can be assigned to an AF_INET socket and then translated
to IPv6 by bpf_skb_change_proto(). Since the translation preserves the
socket assignment, the IPv6 packet can still be delivered to the IPv4
socket, bypassing the family check in bpf_sk_assign().
After a successful protocol change, recheck any prefetched socket
against the new protocol and call skb_orphan() if its address family
is incompatible. This releases the assignment through the existing
skb destructor, allowing normal socket lookup or a new assignment
by the BPF program.
Fixes: cf7fbe660f2d ("bpf: Add socket assign support")
Assisted-by: LLM
Signed-off-by: Shihuang Liu <shlomojune6@gmail.com>
---
Changes since v1:
- Revalidate prefetched sockets after bpf_skb_change_proto() changes the
packet protocol, closing a bypass of assignment-time validation.
- Preserve compatible dual-stack assignments and release incompatible
assignments through their existing skb destructor.
- Split the fix into two patches and target the BPF fixes tree.
v1:
https://lore.kernel.org/netdev/20260823101809.26802-1-shlomojune6@gmail.com/
include/uapi/linux/bpf.h | 4 ++++
net/core/filter.c | 5 +++++
tools/include/uapi/linux/bpf.h | 4 ++++
3 files changed, 13 insertions(+)
diff --git a/include/uapi/linux/bpf.h b/include/uapi/linux/bpf.h
index 5d8f5e2c8db38..0de7967077a2e 100644
--- a/include/uapi/linux/bpf.h
+++ b/include/uapi/linux/bpf.h
@@ -2659,6 +2659,10 @@ union bpf_attr {
* checked and segments are recalculated by the GSO/GRO engine.
* The size for GSO target is adapted as well.
*
+ * On success, an assigned socket is released if its address
+ * family is incompatible with the new protocol. Assign a
+ * compatible socket after translation if required.
+ *
* All values for *flags* are reserved for future usage, and must
* be left at zero.
*
diff --git a/net/core/filter.c b/net/core/filter.c
index e9cc76b775c0c..79a0e484d9dd4 100644
--- a/net/core/filter.c
+++ b/net/core/filter.c
@@ -3547,6 +3547,11 @@ BPF_CALL_3(bpf_skb_change_proto, struct sk_buff *, skb, __be16, proto,
if (ret)
return ret;
+ /* Protocol translation can invalidate an earlier socket assignment. */
+ if (skb_sk_is_prefetched(skb) &&
+ !bpf_sk_assign_family_ok(skb, skb->sk))
+ skb_orphan(skb);
+
if (skb_valid_dst(skb))
skb_dst_drop(skb);
diff --git a/tools/include/uapi/linux/bpf.h b/tools/include/uapi/linux/bpf.h
index 5d8f5e2c8db38..0de7967077a2e 100644
--- a/tools/include/uapi/linux/bpf.h
+++ b/tools/include/uapi/linux/bpf.h
@@ -2659,6 +2659,10 @@ union bpf_attr {
* checked and segments are recalculated by the GSO/GRO engine.
* The size for GSO target is adapted as well.
*
+ * On success, an assigned socket is released if its address
+ * family is incompatible with the new protocol. Assign a
+ * compatible socket after translation if required.
+ *
* All values for *flags* are reserved for future usage, and must
* be left at zero.
*
--
2.43.0
next prev parent reply other threads:[~2026-09-11 17:24 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-11 17:23 [PATCH bpf v2 1/2] bpf: reject incompatible socket assignments Shihuang Liu
2026-09-11 17:23 ` Shihuang Liu [this message]
2026-09-11 17:46 ` [PATCH bpf v2 2/2] bpf: revalidate assigned sockets after protocol change sashiko-bot
2026-09-11 17:42 ` [PATCH bpf v2 1/2] bpf: reject incompatible socket assignments sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260911172313.64009-2-shlomojune6@gmail.com \
--to=shlomojune6@gmail.com \
--cc=akpm@linux-foundation.org \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=avinash.duduskar@gmail.com \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=davem@davemloft.net \
--cc=dmitry.baryshkov@oss.qualcomm.com \
--cc=eddyz87@gmail.com \
--cc=edumazet@google.com \
--cc=emil@etsalapatis.com \
--cc=horms@kernel.org \
--cc=ihor.solodrai@linux.dev \
--cc=joe@wand.net.nz \
--cc=john.fastabend@gmail.com \
--cc=jolsa@kernel.org \
--cc=jordan@jrife.io \
--cc=kpsingh@kernel.org \
--cc=kuba@kernel.org \
--cc=leon.hwang@linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=martin.lau@linux.dev \
--cc=memxor@gmail.com \
--cc=netdev@vger.kernel.org \
--cc=nhudson@akamai.com \
--cc=pabeni@redhat.com \
--cc=rongtao@cestc.cn \
--cc=sdf@fomichev.me \
--cc=song@kernel.org \
--cc=yatsenko@meta.com \
--cc=yonghong.song@linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.