Thread (8 messages) flat view 8 messages, 5 authors, 8d ago

Re: [PATCH net] net/sched: cls_bpf: reject dev-bound programs bound to a different device

From: Jakub Kicinski <kuba@kernel.org>
Date: 2026-08-11 00:05:36
Also in: bpf, stable

On Sun,  9 Aug 2026 05:44:18 -0400 Jamal Hadi Salim wrote:
cls_bpf_prog_from_efd() obtained a SCHED_CLS program via
bpf_prog_get_type_dev() but never verified that a device-bound (offloaded)
program's bound netdev matches the TC netdev the classifier is being
attached to. This let a program loaded with prog_ifindex for device A be
attached via cls_bpf + skip_sw to device B; deleting device A then
destroyed the program's offload state while it was still attached to
device B, triggering a netdevsim WARN (panic with panic_on_warn=1).
maybe netdevsim has a bug then. 
Mirror the XDP attach path (net/core/dev.c) and reject the attach with
-EINVAL when a dev-bound program's bound device does not match the
target device.

Fixes: 6c8dfe21c435 ("cls_bpf: allow attaching programs loaded for specific device")
This commit in itself is fine, nfp checks that the offload matches:
https://elixir.bootlin.com/linux/v7.2-rc5/source/drivers/net/ethernet/netronome/nfp/bpf/offload.c#L579

Maybe the bound-devs got extended for JIT / descriptor access, and
that added some extra risk here. So either this is netdevsim-only
(and not worth the Fixes tag), or the Fixes tag is wrong..
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help