Thread (5 messages) flat view 5 messages, 2 authors, 2023-11-29

Re: [PATCH net] net/netfilter: bpf: avoid leakage of skb

From: "D. Wythe" <alibuda@linux.alibaba.com>
Date: 2023-11-29 15:02:09
Also in: bpf, lkml, netfilter-devel


On 11/29/23 10:47 PM, Florian Westphal wrote:
D. Wythe [off-list ref] wrote:
quoted
And my origin intention was to allow ebpf progs to return NF_STOLEN, we are
trying to modify some netfilter modules via ebpf,
and some scenarios require the use of NF_STOLEN, but from your description,
NF_STOLEN can only be supported via a trusted helper, as least as far as
I understand.

Otherwise verifier would have to guarantee that any branch that returns
NF_STOLEN has released the skb, or passed it to a function that will
release the skb in the near future.
Thank you very much for your help. I now understand the difficulty here.
The verifier cannot determine whether the consume_skb() was executed or not,
when the return value  goes to NF_STOLEN.

We may use NF_DROP at first, it won't be make much difference for us now.

Also, do you have any plans to support this helper?

Best wishes,
D. Wythe
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help