Thread (5 messages) read the whole thread 5 messages, 2 authors, 2023-11-29

Re: [PATCH net] net/netfilter: bpf: avoid leakage of skb

From: Florian Westphal <fw@strlen.de>
Date: 2023-11-29 14:47:45
Also in: bpf, lkml, netfilter-devel

D. Wythe [off-list ref] wrote:
And my origin intention was to allow ebpf progs to return NF_STOLEN, we are
trying to modify some netfilter modules via ebpf,
and some scenarios require the use of NF_STOLEN, but from your description,
NF_STOLEN can only be supported via a trusted helper, as least as far as
I understand.

Otherwise verifier would have to guarantee that any branch that returns
NF_STOLEN has released the skb, or passed it to a function that will
release the skb in the near future.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help