From mboxrd@z Thu Jan 1 00:00:00 1970 From: Alexei Starovoitov Subject: Re: [RFC PATCH bpf-next v4 5/7] bpf: restrict use of peek/push/pop Date: Thu, 4 Oct 2018 16:57:55 -0700 Message-ID: <20181004235754.2c6trhnddmkmptiv@ast-mbp.dhcp.thefacebook.com> References: <153867314370.10087.2202062772042248653.stgit@kernel> <153867316984.10087.3212168623519526172.stgit@kernel> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Cc: Alexei Starovoitov , Daniel Borkmann , netdev@vger.kernel.org To: Mauricio Vasquez B Return-path: Received: from mail-pf1-f196.google.com ([209.85.210.196]:46686 "EHLO mail-pf1-f196.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1725998AbeJEGxy (ORCPT ); Fri, 5 Oct 2018 02:53:54 -0400 Received: by mail-pf1-f196.google.com with SMTP id r64-v6so4136732pfb.13 for ; Thu, 04 Oct 2018 16:57:59 -0700 (PDT) Content-Disposition: inline In-Reply-To: <153867316984.10087.3212168623519526172.stgit@kernel> Sender: netdev-owner@vger.kernel.org List-ID: On Thu, Oct 04, 2018 at 07:12:49PM +0200, Mauricio Vasquez B wrote: > Restrict the use of peek, push and pop helpers only to queue and stack > maps. > > Signed-off-by: Mauricio Vasquez B > --- > kernel/bpf/verifier.c | 14 ++++++++++++++ > 1 file changed, 14 insertions(+) > > diff --git a/kernel/bpf/verifier.c b/kernel/bpf/verifier.c > index 489667f93061..8b1f1b348782 100644 > --- a/kernel/bpf/verifier.c > +++ b/kernel/bpf/verifier.c > @@ -2328,6 +2328,13 @@ static int check_map_func_compatibility(struct bpf_verifier_env *env, > if (func_id != BPF_FUNC_sk_select_reuseport) > goto error; > break; > + case BPF_MAP_TYPE_QUEUE: > + case BPF_MAP_TYPE_STACK: > + if (func_id != BPF_FUNC_map_peek_elem && > + func_id != BPF_FUNC_map_pop_elem && > + func_id != BPF_FUNC_map_push_elem) > + goto error; why this is separate patch? I think it should be part of previous patch. > + break; > default: > break; > } > @@ -2384,6 +2391,13 @@ static int check_map_func_compatibility(struct bpf_verifier_env *env, > if (map->map_type != BPF_MAP_TYPE_REUSEPORT_SOCKARRAY) > goto error; > break; > + case BPF_FUNC_map_peek_elem: > + case BPF_FUNC_map_pop_elem: > + case BPF_FUNC_map_push_elem: > + if (map->map_type != BPF_MAP_TYPE_QUEUE && > + map->map_type != BPF_MAP_TYPE_STACK) > + goto error; > + break; > default: > break; > } >