From: Daniel Borkmann <daniel@iogearbox.net>
To: Johannes Berg <johannes@sipsolutions.net>,
Alexei Starovoitov <ast@kernel.org>
Cc: netdev <netdev@vger.kernel.org>
Subject: Re: __sk_buff.data_end
Date: Thu, 20 Apr 2017 16:10:40 +0200 [thread overview]
Message-ID: <58F8C160.6010905@iogearbox.net> (raw)
In-Reply-To: <1492668065.3109.1.camel@sipsolutions.net>
On 04/20/2017 08:01 AM, Johannes Berg wrote:
> On Thu, 2017-04-20 at 02:01 +0200, Daniel Borkmann wrote:
>>
>> Yeah, should work as well for the 32 bit archs, on 64 bit we
>> have this effectively already:
>
> Right.
>
> [...]
>
>> Can you elaborate on why this works for mac80211? It uses cb
>> only up to that point from where you invoke the prog?
>
> No, it works because then I can move a u64 field to the same offset,
> and save/restore it across the BPF call :)
Right.
> But I don't have a *pointer* field to move there, and no space for the
> alignment anyway (already using all 48 bytes).
>
> Come to think of it - somebody had proposed extensions to this by
> passing an on-stack pointer in addition to the data in the cb.
>
> Perhaps we can extend BPF to have an optional second argument, and
> track a second context around the verifier, if applicable? Then we can
> solve all of this really easily, because it means we don't always have
> to go from the SKB context but could go from the other one (which could
> be that on-stack buffer).
I think this would be a rather more complex operation on the BPF side,
it would need changes from LLVM (which assumes initial ctx sits in r1),
verifier for tracking this ctx2, all the way down to JITs plus some way
to handle 1 and 2 argument program calls generically. Much easier to
pass additional meta data for the program via cb[], for example.
> Alternatively I can clear another pointer (u64) in the CB, store a
> pointer there, and always emit code following that pointer - should be
> possible right?
What kind of pointer? If it's something like data_end as read-only, then
this needs to be tracked in the verifier in addition, of course. Other
option you could do (depending on what you want to achieve) is to have
a bpf_probe_read() version as a helper for your prog type that would
further walk that pointer/struct (similar to tracing) where this comes
w/o any backward compat guarantees, though.
next prev parent reply other threads:[~2017-04-20 14:11 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-04-19 21:31 __sk_buff.data_end Johannes Berg
2017-04-19 22:20 ` __sk_buff.data_end Johannes Berg
2017-04-20 0:01 ` __sk_buff.data_end Daniel Borkmann
2017-04-20 0:12 ` __sk_buff.data_end Alexei Starovoitov
2017-04-20 0:38 ` __sk_buff.data_end Daniel Borkmann
2017-04-20 6:07 ` __sk_buff.data_end Johannes Berg
2017-04-20 6:06 ` __sk_buff.data_end Johannes Berg
2017-04-20 6:01 ` __sk_buff.data_end Johannes Berg
2017-04-20 14:10 ` Daniel Borkmann [this message]
2017-04-20 14:17 ` __sk_buff.data_end Johannes Berg
2017-04-20 14:28 ` __sk_buff.data_end Daniel Borkmann
2017-04-20 14:32 ` __sk_buff.data_end Johannes Berg
2017-04-20 14:46 ` __sk_buff.data_end Daniel Borkmann
2017-04-20 14:48 ` __sk_buff.data_end Johannes Berg
2017-04-19 23:51 ` __sk_buff.data_end Daniel Borkmann
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=58F8C160.6010905@iogearbox.net \
--to=daniel@iogearbox.net \
--cc=ast@kernel.org \
--cc=johannes@sipsolutions.net \
--cc=netdev@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.