From: sashiko-bot@kernel.org
To: "Kuniyuki Iwashima" <kuniyu@google.com>
Cc: bpf@vger.kernel.org
Subject: Re: [PATCH bpf-next 6/7] bpf: tcp: Add kfunc to adjust sk->sk_rcvlowat.
Date: Sun, 20 Sep 2026 20:13:33 +0000 [thread overview]
Message-ID: <20260920201333.A40C81F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260920195633.3033620-7-kuniyu@google.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] bpf: tcp: OOB access and type confusion in bpf_tcp_ops_set_rcvlowat()
--
commit c903e36ae4ed7b68c1aea9023743a57be672cd2a
Author: Kuniyuki Iwashima <kuniyu@google.com>
bpf: tcp: Add kfunc to adjust sk->sk_rcvlowat.
This commit adds a new BPF kfunc bpf_tcp_ops_set_rcvlowat() to dynamically
adjust the receive low watermark for TCP sockets. It clamps negative values
to INT_MAX and configures the wakeup flag appropriately depending on the
calling hook (enqueue vs dequeue).
> diff --git a/net/ipv4/bpf_tcp_ops.c b/net/ipv4/bpf_tcp_ops.c
> index b0e14b54917eb..3768b1440eb77 100644
> --- a/net/ipv4/bpf_tcp_ops.c
> +++ b/net/ipv4/bpf_tcp_ops.c
> @@ -359,8 +359,62 @@ static struct bpf_struct_ops bpf_tcp_ops = {
> .owner = THIS_MODULE,
> };
>
> +__bpf_kfunc_start_defs();
> +
> +__bpf_kfunc int bpf_tcp_ops_set_rcvlowat(struct sock *sk, int rcvlowat,
> + const struct bpf_prog_aux *aux)
> +{
> + u32 moff = aux->attach_st_ops_member_off;
> + bool wakeup = false;
> +
> + if (moff == offsetof(struct bpf_tcp_ops, dequeue_rcvq))
> + wakeup = true;
> +
> + if (rcvlowat < 0)
> + rcvlowat = INT_MAX;
> +
> + return __tcp_set_rcvlowat(sk, rcvlowat, wakeup);
[Severity: High]
Could this lead to an out-of-bounds slab memory access if a BPF program
passes a non-TCP socket?
Because the kfunc accepts a generic struct sock *sk parameter, the BPF
verifier allows passing any socket type. For example, a trusted UDP
socket could be obtained via bpf_sk_lookup_udp() and passed directly here.
However, __tcp_set_rcvlowat() blindly casts the socket to struct tcp_sock *:
net/ipv4/tcp.c:__tcp_set_rcvlowat() {
struct tcp_sock *tp = tcp_sk(sk);
...
if (tp->window_clamp && tp->window_clamp < val)
WRITE_ONCE(tp->window_clamp, val);
}
This writes to tp->window_clamp, which resides well beyond the bounds of a
UDP socket structure.
Additionally, does this permit concurrent modification of the socket state
since the looked-up socket isn't guaranteed to be locked?
> +}
> +
> +__bpf_kfunc_end_defs();
[ ... ]
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260920195633.3033620-1-kuniyu@google.com?part=6
next prev parent reply other threads:[~2026-09-20 20:13 UTC|newest]
Thread overview: 28+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-20 19:56 [PATCH bpf-next 0/7] bpf: Add bpf_tcp_ops hooks for TCP AutoLOWAT Kuniyuki Iwashima
2026-09-20 19:56 ` [PATCH bpf-next 1/7] selftest: bpf: Use BPF_SOCK_OPS_ALL_CB_FLAGS + 1 for bad_cb_test_rv Kuniyuki Iwashima
2026-09-21 20:48 ` Stanislav Fomichev
2026-09-20 19:56 ` [PATCH bpf-next 2/7] bpf: tcp: Introduce bpf_tcp_ops.{enqueue,dequeue}_rcvq() Kuniyuki Iwashima
2026-09-20 21:16 ` bot+bpf-ci
2026-09-21 20:48 ` Stanislav Fomichev
2026-09-20 19:56 ` [PATCH bpf-next 3/7] bpf: tcp: Support bpf_sock_ops_cb_flags_set() for bpf_tcp_ops Kuniyuki Iwashima
2026-09-20 20:11 ` sashiko-bot
2026-09-20 21:05 ` Kuniyuki Iwashima
2026-09-21 20:48 ` Stanislav Fomichev
2026-09-20 19:56 ` [PATCH bpf-next 4/7] tcp: Split out __tcp_set_rcvlowat() Kuniyuki Iwashima
2026-09-20 21:01 ` bot+bpf-ci
2026-09-20 21:12 ` Kuniyuki Iwashima
2026-09-21 20:48 ` Stanislav Fomichev
2026-09-20 19:56 ` [PATCH bpf-next 5/7] bpf: mptcp: Don't support BPF_SOCK_OPS_RCVQ_CB_FLAG Kuniyuki Iwashima
2026-09-20 20:05 ` sashiko-bot
2026-09-20 21:09 ` Kuniyuki Iwashima
2026-09-20 19:56 ` [PATCH bpf-next 6/7] bpf: tcp: Add kfunc to adjust sk->sk_rcvlowat Kuniyuki Iwashima
2026-09-20 20:13 ` sashiko-bot [this message]
2026-09-20 21:10 ` Kuniyuki Iwashima
2026-09-20 21:16 ` bot+bpf-ci
2026-09-21 20:49 ` Stanislav Fomichev
2026-09-21 21:36 ` Kuniyuki Iwashima
2026-09-22 7:29 ` Clément Léger
2026-09-20 19:56 ` [PATCH bpf-next 7/7] selftest: bpf: Add test for bpf_tcp_ops.{enqueue,dequeue}_rcvq() Kuniyuki Iwashima
2026-09-20 21:16 ` bot+bpf-ci
2026-09-21 20:50 ` Stanislav Fomichev
2026-09-22 23:14 ` Kuniyuki Iwashima
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260920201333.A40C81F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=kuniyu@google.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.