Re: [PATCH v2 2/4] net: filter: add sk_attach_filter_kern() function
From: Willem de Bruijn <willemdebruijn.kernel@gmail.com>
Date: 2026-09-30 02:43:10
Rongguang Wei wrote:
From: Rongguang Wei <redacted> sk_attach_filter() copies the program from user space and sk_attach_bpf() takes it from a user file descriptor, so a program that the kernel keeps in memory cannot be installed again later. sk_attach_filter_kern() builds the program from a sock_fprog_kern, so no user buffer is read, and attaches it like sk_attach_filter(). The caller must hold the socket lock. Failing the attach releases it; so does the socket when the filter is replaced, detached or the socket goes away. Signed-off-by: Rongguang Wei <redacted>
This should probably be squashed into the next commit, that first uses it.
quoted hunk ↗ jump to hunk
--- include/linux/filter.h | 1 + net/core/filter.c | 22 ++++++++++++++++++++++ 2 files changed, 23 insertions(+)diff --git a/include/linux/filter.h b/include/linux/filter.h index 39decde7fc73..0de5a738fb26 100644 --- a/include/linux/filter.h +++ b/include/linux/filter.h@@ -1218,6 +1218,7 @@ int bpf_prog_create_from_user(struct bpf_prog **pfp, struct sock_fprog *fprog, void bpf_prog_destroy(struct bpf_prog *fp); int sk_attach_filter(struct sock_fprog *fprog, struct sock *sk); +int sk_attach_filter_kern(struct sock_fprog_kern *fprog, struct sock *sk); int sk_attach_bpf(u32 ufd, struct sock *sk); int sk_reuseport_attach_filter(struct sock_fprog *fprog, struct sock *sk); int sk_reuseport_attach_bpf(u32 ufd, struct sock *sk);diff --git a/net/core/filter.c b/net/core/filter.c index 70dc621672f2..64d6505a4ef2 100644 --- a/net/core/filter.c +++ b/net/core/filter.c@@ -1567,6 +1567,28 @@ int sk_attach_filter(struct sock_fprog *fprog, struct sock *sk) } EXPORT_SYMBOL_GPL(sk_attach_filter); +int sk_attach_filter_kern(struct sock_fprog_kern *fprog, struct sock *sk) +{ + struct bpf_prog *prog; + int err; + + if (sock_flag(sk, SOCK_FILTER_LOCKED)) + return -EPERM; + + err = bpf_prog_create(&prog, fprog); + if (err) + return err; + + err = __sk_attach_prog(prog, sk); + if (err < 0) { + __bpf_prog_release(prog); + return err; + } + + return 0; +} +EXPORT_SYMBOL_GPL(sk_attach_filter_kern); + int sk_reuseport_attach_filter(struct sock_fprog *fprog, struct sock *sk) { struct bpf_prog *prog = __get_filter(fprog, sk);-- 2.25.1 No virus found Checked by Hillstone Network AntiVirus