From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wr2-f1.google.com (mail-wr2-f1.google.com [74.125.225.65]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A8680363C53 for ; Mon, 3 Aug 2026 03:26:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.225.65 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785727595; cv=none; b=op+oBVby2badkEH/uGKzggvUBOrIcuRpXAPciwnQ274Sm/MciJtlHlVX2ulUyIvGbWyTsyrsxzsw99tyZYLxQosUCNyRWRkGE6fDT+SxZ8BL2GK1YI9q+L+skGSqSX4sXbc9tORjrJrgduLPqhU44jW9WZSeRVuhR4NC0xaS0zI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785727595; c=relaxed/simple; bh=q0Iq6ZtSP2Bo6Kr/xjePCnb4yWA7JsFK+cxdHKTVT1c=; h=Mime-Version:Content-Type:Date:Message-Id:To:Cc:Subject:From: References:In-Reply-To; b=m3jccJcBs+G+IYwAJrzwjxACekQkozUG1SHfDHZI3C8KM+2vgamEIgHerzsdO+TWqGaHh1exckVEbHjSng8zCIJgH3g4GuFAeVgcdBlVQubkQclCG1A3Uq3/O06TFr9eLo+e4cC9tWNfT7Va9R28UIB/F6borzZZxvNrxZiP2Nw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=LjhLtax5; arc=none smtp.client-ip=74.125.225.65 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="LjhLtax5" Received: by mail-wr2-f1.google.com with SMTP id ffacd0b85a97d-47fcb9d4b33so1462054f8f.0 for ; Sun, 02 Aug 2026 20:26:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785727592; x=1786332392; darn=vger.kernel.org; h=in-reply-to:references:from:subject:cc:to:message-id:date :content-type:content-transfer-encoding:mime-version:from:to:cc :subject:date:message-id:reply-to:content-type; bh=rW2m4UfJFTFczcwxnDcti6pYYCW920pNNinJvPy7q7A=; b=LjhLtax5AaA4c1bBb4namimn762R7jAK7CAGgejlmA68oQFADOuniBHNjWZJAtzKUr A+HXrP1pkfYfawcmps5wDkibEksc+OmA5uYyzhxTjgbZiaujjsbuexgtLNasSjtRVzEY 0jeuMjlJPxJnBHK2MogYYROF2kEH/1LsyYMI4WU+VTs5JjCKyQ0yvxrpjhvsGcf8fVuQ az0hLvGwdT6VU3hX3g0duZODuumaN8dL6elnuvPpwIYP0E1QUFmphH/YwbawF+XMdM/E yOVYio4hIYbNqJ55FiiaD1m/i8nH15eqNF80GCfML1m9WOiVIBpDu5tC+ANJMZm1qHIf I0qQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785727592; x=1786332392; h=in-reply-to:references:from:subject:cc:to:message-id:date :content-type:content-transfer-encoding:mime-version:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=rW2m4UfJFTFczcwxnDcti6pYYCW920pNNinJvPy7q7A=; b=Qpr/YDAWPpATIXOXlYtgNP5dcPW6bGJfsEAOzNM6GqRj4AXDCnpMLkCz6JXYZTSwrW vH7U4YIZ3bBJbsLY3xNB7s7rm2e0UPh+wZnpX7V6lmh3cfZNorTipLuAW4zNuLIb2INq aFD9HfhhEqTzfxkbVGmd6X3DNy+1X7sh0QEPQddmOIxDce/npaUEJkGeT2Uv7ISQmlBH xxauCU3vCm0lmcjdI+W22kgDKrtTDAKpbNIrQAE0DukrprzgNyQY3ZF3NgBik45hbzng uuzObr1x3/KFolE5sT6b3P/jToLkGIw+37urBGmAFfPiGrM5W7nzTPsM23O6oQQgfPsh vX4A== X-Forwarded-Encrypted: i=1; AHgh+RrDHxyDCXCLgiEUxf8oD14pv3VQRLRvRxdmqb/sFsa5SHT5Yp4AS9NpyS4VER8tf1KZL0ODokRhOmbtD/I=@vger.kernel.org X-Gm-Message-State: AOJu0Yx9q/YeFs5R0rWKxRpMsiiECxiT+QMFNv0C4CUvrSruiw5mZ6aO gLnZhQMkyXGAJeGXOYKEMOyfJJVpOYpdN3uqIlSm6kvPh2+RbQKNNLHq X-Gm-Gg: AR+sD130HAnYwlNxOdFwKp2ECYv3u+h1SF/W3u2ikmj3Jn2dkIjvaSWurCG19ru7cyl GGWx6TVHllDD9/iAf6CO9aOTYVsxSb4oGNl8AcTzym+UnKY534UjXn/uxOqCw14nk8EYbEiWGam R4rxzKH2dI+40BuDlXNZ3Mm+kW/KeceU0N+qICdwrtTK0q0qxGWXgD2gAxf1IONmVWmNPP73LNZ YDZuPQ4OSoknHrUBfGDnkm956JUb85aA7WuqLzHQKiGx55kf7TeQiTWGDvu0cGgyR4tK4Nb7t+H SbcmuKnBrErQssiisAb04oocPvD9VVhJyCnJu0uC2gEwheCKj+gHczqh/cVA3w+BCECEJdSngdF kskeZ21qDPE5IkUgoq3BHEqd8Dc63hjLxIyu6Sm742grmtxcyEA4qFlCmCbGokw8NZS60kK87Ju 6gCGnJgg9QcwZ7Jx0n27i/FlsxQqotJINHiBieqSgUd0uigga/tE7H5nGqFZ+jHUS2ta6DLmTNs kK+kCXl2H0c87YngpU+UDuS9LS4X9zh10mGOCgu2ytZY7YSNGBIsvF8+Z2XGDeoCUpGfHpSrQYV N1anUCQVsxzJVh4/Y6aS0ey2a+o= X-Received: by 2002:a05:600c:e548:10b0:498:943:ccc0 with SMTP id 5b1f17b1804b1-4980c649c63mr132917915e9.6.1785727591863; Sun, 02 Aug 2026 20:26:31 -0700 (PDT) Received: from localhost (nat-icclus-192-26-29-3.epfl.ch. [192.26.29.3]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49807ba8032sm156577785e9.15.2026.08.02.20.26.31 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 02 Aug 2026 20:26:31 -0700 (PDT) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=UTF-8 Date: Mon, 03 Aug 2026 05:26:31 +0200 Message-Id: To: "Ning Ding" Cc: , , , , , , , , , , , , , , Subject: Re: [PATCH bpf] bpf: Reject writes through untrusted allocated pointers From: "Kumar Kartikeya Dwivedi" X-Mailer: aerc 0.21.0 References: <20260726021304.97ED91F000E9@smtp.kernel.org> <20260728033837.1466123-1-dingning04@gmail.com> In-Reply-To: On Mon Aug 3, 2026 at 5:21 AM CEST, Ning Ding wrote: >> Second, I don't understand your explanation. WDYM by "after the access >> permission check"? It gets invoked for BPF_WRITE, so should be rejecting >> res->key =3D 42 if 'res' is a pointer with PTR_UNTRUSTED flag set. What = am I >> missing? > > The direct write will pass this earlier permission check since > type_is_ptr_alloc_obj does not check PTR_UNTRUSTED: > if (atype !=3D BPF_READ && !type_is_ptr_alloc_obj(reg->type)) > return -EACCES; > > The later PTR_UNTRUSTED branch is not a rejection check. It means when > accessing a pointer field through an untrusted parent pointer, > propagate PTR_UNTRUSTED to the child pointer. > > if (ret !=3D PTR_TO_BTF_ID) { > /* just mark; */ > > } else if (type_flag(reg->type) & PTR_UNTRUSTED) { > /* If this is an untrusted pointer, all pointers formed by walking it > * also inherit the untrusted flag. > */ > flag =3D PTR_UNTRUSTED; > > } > > For res->key =3D 42, key is a scalar, so ret !=3D PTR_TO_BTF_ID. Therefor= e > the second branch is skipped and has no effect. I am talking about this bit before all of that logic: if (atype !=3D BPF_READ && (type_flag(reg->type) & PTR_UNTRUSTED))= { verbose(env, "only read is supported\n"); return -EACCES; } Why is this not enough? 'key' is scalar, but 'res' which is being written t= o is still a PTR_TO_BTF_ID with PTR_UNTRUSTED.