Thread (8 messages) 8 messages, 5 authors, 2026-08-13

Re: [PATCH net] net/sched: cls_bpf: reject dev-bound programs bound to a different device

flat view

From: Jamal Hadi Salim <jhs@mojatatu.com>
Date: 2026-08-11 11:35:54
Also in: bpf, stable

On Mon, Aug 10, 2026 at 8:05 PM Jakub Kicinski [off-list ref] wrote:
On Sun,  9 Aug 2026 05:44:18 -0400 Jamal Hadi Salim wrote:
quoted
cls_bpf_prog_from_efd() obtained a SCHED_CLS program via
bpf_prog_get_type_dev() but never verified that a device-bound (offloaded)
program's bound netdev matches the TC netdev the classifier is being
attached to. This let a program loaded with prog_ifindex for device A be
attached via cls_bpf + skip_sw to device B; deleting device A then
destroyed the program's offload state while it was still attached to
device B, triggering a netdevsim WARN (panic with panic_on_warn=1).
maybe netdevsim has a bug then.
Looking closely: You're right. nfp guards at the driver
(bpf_offload_dev_match() at
while netdevsim's cls_bpf path checks boundness, not the device match.
quoted
Mirror the XDP attach path (net/core/dev.c) and reject the attach with
-EINVAL when a dev-bound program's bound device does not match the
target device.

Fixes: 6c8dfe21c435 ("cls_bpf: allow attaching programs loaded for specific device")
This commit in itself is fine, nfp checks that the offload matches:
https://elixir.bootlin.com/linux/v7.2-rc5/source/drivers/net/ethernet/netronome/nfp/bpf/offload.c#L579

Maybe the bound-devs got extended for JIT / descriptor access, and
that added some extra risk here. So either this is netdevsim-only
(and not worth the Fixes tag), or the Fixes tag is wrong..
Fixes tag is definetely wrong. 6c8dfe21c435 was fine for nfp; the
semantic shift happened from Stan's fix in 2b3486bc2d23 (made
prog->aux->offload non-NULL for dev-bound progs). c0c6bde586c7 then
fixed netdevsim XDP but missed cls_bpf.

It seems a v2 may be worth it:
fix netdevsim's cls_bpf path (Fixes: 2b3486bc2d23), keep the core
check as defense-in-depth without the bogus Fixes:, and walk
block->ports for shared blocks (block->q is NULL there). Or drop the
core change and fix only netdevsim. What says you?

cheers,
jamal
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help