Thread (7 messages) flat view 7 messages, 2 authors, 2019-08-21

Re: [PATCH bpf-next 2/2] tools: bpftool: add "bpftool map freeze" subcommand

From: Daniel Borkmann <daniel@iogearbox.net>
Date: 2019-08-21 11:40:45
Also in: bpf

On 8/21/19 10:52 AM, Quentin Monnet wrote:
quoted hunk ↗ jump to hunk
Add a new subcommand to freeze maps from user space.

Signed-off-by: Quentin Monnet <redacted>
Reviewed-by: Jakub Kicinski <redacted>
---
  .../bpf/bpftool/Documentation/bpftool-map.rst |  9 +++++
  tools/bpf/bpftool/bash-completion/bpftool     |  4 +--
  tools/bpf/bpftool/map.c                       | 34 ++++++++++++++++++-
  3 files changed, 44 insertions(+), 3 deletions(-)
diff --git a/tools/bpf/bpftool/Documentation/bpftool-map.rst b/tools/bpf/bpftool/Documentation/bpftool-map.rst
index 61d1d270eb5e..1c0f7146aab0 100644
--- a/tools/bpf/bpftool/Documentation/bpftool-map.rst
+++ b/tools/bpf/bpftool/Documentation/bpftool-map.rst
@@ -36,6 +36,7 @@ MAP COMMANDS
  |	**bpftool** **map pop**        *MAP*
  |	**bpftool** **map enqueue**    *MAP* **value** *VALUE*
  |	**bpftool** **map dequeue**    *MAP*
+|	**bpftool** **map freeze**     *MAP*
  |	**bpftool** **map help**
  |
  |	*MAP* := { **id** *MAP_ID* | **pinned** *FILE* }
@@ -127,6 +128,14 @@ DESCRIPTION
  	**bpftool map dequeue**  *MAP*
  		  Dequeue and print **value** from the queue.
  
+	**bpftool map freeze**  *MAP*
+		  Freeze the map as read-only from user space. Entries from a
+		  frozen map can not longer be updated or deleted with the
+		  **bpf\ ()** system call. This operation is not reversible,
+		  and the map remains immutable from user space until its
+		  destruction. However, read and write permissions for BPF
+		  programs to the map remain unchanged.
That is not correct, programs that are loaded into the system /after/ the map
has been frozen cannot modify values either, thus read-only from both sides.

Thanks,
Daniel
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help