Thread (4 messages) flat view 4 messages, 3 authors, 2017-10-18

Re: using verifier to ensure a BPF program uses certain metadata?

From: Alexei Starovoitov <hidden>
Date: 2017-10-18 17:42:58
Also in: linux-wireless

On Wed, Oct 18, 2017 at 08:56:31AM +0200, Johannes Berg wrote:
quoted
quoted
Now, I realize that people could trivially just work around this in
their program if they wanted, but I think most will take the
reminder
and just implement

    if (ctx->is_data_ethernet)
        return DROP_FRAME;

instead, since mostly data frames will not be very relevant to
them.

What do you think?
sounds fine and considering new verifier ops after Jakub refactoring
a check that is_data_ethernet was accessed would fit nicely.
Without void** hack.
Ok, thanks! I'll have to check what Jakub is doing there, do you have a
pointer to that refactoring?
something similar to
commit 4f9218aaf8a4 ("bpf: move knowledge about post-translation offsets out of verifier")
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help