Thread (62 messages) read the whole thread 62 messages, 8 authors, 2014-07-05

Re: [PATCH RFC net-next 03/14] bpf: introduce syscall(BPF, ...) and BPF maps

From: Alexei Starovoitov <hidden>
Date: 2014-06-28 05:55:20
Also in: linux-api, lkml

On Fri, Jun 27, 2014 at 5:16 PM, Andy Lutomirski [off-list ref] wrote:
On Fri, Jun 27, 2014 at 5:05 PM, Alexei Starovoitov [off-list ref] wrote:
quoted
BPF syscall is a demux for different BPF releated commands.

'maps' is a generic storage of different types for sharing data between kernel
and userspace.

The maps can be created/deleted from user space via BPF syscall:
- create a map with given id, type and attributes
  map_id = bpf_map_create(int map_id, map_type, struct nlattr *attr, int len)
  returns positive map id or negative error

- delete map with given map id
  err = bpf_map_delete(int map_id)
  returns zero or negative error
What's the scope of "id"?  How is it secured?
the map and program id space is global and it's cap_sys_admin only.
There is no pressing need to do it with per-user limits.
So the whole thing is root only for now.

Since I got your attention please review the most interesting
verifier bits (patch 08/14) ;)
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help