From: sdf@google.com
To: Martin KaFai Lau <kafai@fb.com>
Cc: bpf@vger.kernel.org, netdev@vger.kernel.org,
Alexei Starovoitov <ast@kernel.org>,
Andrii Nakryiko <andrii@kernel.org>,
Daniel Borkmann <daniel@iogearbox.net>,
David Miller <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>,
kernel-team@fb.com, Paolo Abeni <pabeni@redhat.com>
Subject: Re: [PATCH v2 bpf-next 02/15] bpf: net: Avoid sk_setsockopt() taking sk lock when called from bpf
Date: Wed, 3 Aug 2022 15:59:26 -0700 [thread overview]
Message-ID: <Yur9zosqo4zpVBx5@google.com> (raw)
In-Reply-To: <20220803204614.3077284-1-kafai@fb.com>
On 08/03, Martin KaFai Lau wrote:
> Most of the code in bpf_setsockopt(SOL_SOCKET) are duplicated from
> the sk_setsockopt(). The number of supported optnames are
> increasing ever and so as the duplicated code.
> One issue in reusing sk_setsockopt() is that the bpf prog
> has already acquired the sk lock. This patch adds a in_bpf()
> to tell if the sk_setsockopt() is called from a bpf prog.
> The bpf prog calling bpf_setsockopt() is either running in_task()
> or in_serving_softirq(). Both cases have the current->bpf_ctx
> initialized. Thus, the in_bpf() only needs to test !!current->bpf_ctx.
> This patch also adds sockopt_{lock,release}_sock() helpers
> for sk_setsockopt() to use. These helpers will test in_bpf()
> before acquiring/releasing the lock. They are in EXPORT_SYMBOL
> for the ipv6 module to use in a latter patch.
> Note on the change in sock_setbindtodevice(). sockopt_lock_sock()
> is done in sock_setbindtodevice() instead of doing the lock_sock
> in sock_bindtoindex(..., lock_sk = true).
> Signed-off-by: Martin KaFai Lau <kafai@fb.com>
> ---
> include/linux/bpf.h | 8 ++++++++
> include/net/sock.h | 3 +++
> net/core/sock.c | 26 +++++++++++++++++++++++---
> 3 files changed, 34 insertions(+), 3 deletions(-)
> diff --git a/include/linux/bpf.h b/include/linux/bpf.h
> index 20c26aed7896..b905b1b34fe4 100644
> --- a/include/linux/bpf.h
> +++ b/include/linux/bpf.h
> @@ -1966,6 +1966,10 @@ static inline bool unprivileged_ebpf_enabled(void)
> return !sysctl_unprivileged_bpf_disabled;
> }
> +static inline bool in_bpf(void)
> +{
> + return !!current->bpf_ctx;
> +}
Good point on not needing to care about softirq!
That actually turned even nicer :-)
QQ: do we need to add a comment here about potential false-negatives?
I see you're adding ctx to the iter, but there is still a bunch of places
that don't use it.
next prev parent reply other threads:[~2022-08-03 22:59 UTC|newest]
Thread overview: 29+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-08-03 20:46 [PATCH v2 bpf-next 00/15] bpf: net: Remove duplicated code from bpf_setsockopt() Martin KaFai Lau
2022-08-03 20:46 ` [PATCH v2 bpf-next 01/15] net: Add sk_setsockopt() to take the sk ptr instead of the sock ptr Martin KaFai Lau
2022-08-03 20:46 ` [PATCH v2 bpf-next 02/15] bpf: net: Avoid sk_setsockopt() taking sk lock when called from bpf Martin KaFai Lau
2022-08-03 22:59 ` sdf [this message]
2022-08-03 23:19 ` Martin KaFai Lau
2022-08-03 23:24 ` Stanislav Fomichev
2022-08-03 23:35 ` Martin KaFai Lau
2022-08-04 19:03 ` Andrii Nakryiko
2022-08-04 19:29 ` Martin KaFai Lau
2022-08-04 20:51 ` Universally available bpf_ctx WAS: " Andrii Nakryiko
2022-08-04 21:43 ` Stanislav Fomichev
2022-08-05 0:29 ` Martin KaFai Lau
2022-08-03 20:46 ` [PATCH v2 bpf-next 03/15] bpf: net: Consider in_bpf() when testing capable() in sk_setsockopt() Martin KaFai Lau
2022-08-03 20:46 ` [PATCH v2 bpf-next 04/15] bpf: net: Change do_tcp_setsockopt() to use the sockopt's lock_sock() and capable() Martin KaFai Lau
2022-08-03 20:46 ` [PATCH v2 bpf-next 05/15] bpf: net: Change do_ip_setsockopt() " Martin KaFai Lau
2022-08-03 20:46 ` [PATCH v2 bpf-next 06/15] bpf: net: Change do_ipv6_setsockopt() " Martin KaFai Lau
2022-08-03 20:46 ` [PATCH v2 bpf-next 07/15] bpf: Initialize the bpf_run_ctx in bpf_iter_run_prog() Martin KaFai Lau
2022-08-03 20:46 ` [PATCH v2 bpf-next 08/15] bpf: Embed kernel CONFIG check into the if statement in bpf_setsockopt Martin KaFai Lau
2022-08-03 20:46 ` [PATCH v2 bpf-next 09/15] bpf: Change bpf_setsockopt(SOL_SOCKET) to reuse sk_setsockopt() Martin KaFai Lau
2022-08-03 20:47 ` [PATCH v2 bpf-next 10/15] bpf: Refactor bpf specific tcp optnames to a new function Martin KaFai Lau
2022-08-03 20:47 ` [PATCH v2 bpf-next 11/15] bpf: Change bpf_setsockopt(SOL_TCP) to reuse do_tcp_setsockopt() Martin KaFai Lau
2022-08-03 20:47 ` [PATCH v2 bpf-next 12/15] bpf: Change bpf_setsockopt(SOL_IP) to reuse do_ip_setsockopt() Martin KaFai Lau
2022-08-03 20:47 ` [PATCH v2 bpf-next 13/15] bpf: Change bpf_setsockopt(SOL_IPV6) to reuse do_ipv6_setsockopt() Martin KaFai Lau
2022-08-03 20:47 ` [PATCH v2 bpf-next 14/15] bpf: Add a few optnames to bpf_setsockopt Martin KaFai Lau
2022-08-03 20:47 ` [PATCH v2 bpf-next 15/15] selftests/bpf: bpf_setsockopt tests Martin KaFai Lau
2022-08-03 23:30 ` sdf
2022-08-04 0:04 ` Martin KaFai Lau
2022-08-04 17:03 ` Stanislav Fomichev
2022-08-04 19:17 ` Martin KaFai Lau
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=Yur9zosqo4zpVBx5@google.com \
--to=sdf@google.com \
--cc=andrii@kernel.org \
--cc=ast@kernel.org \
--cc=bpf@vger.kernel.org \
--cc=daniel@iogearbox.net \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=kafai@fb.com \
--cc=kernel-team@fb.com \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.