From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f174.google.com (mail-pl1-f174.google.com [209.85.214.174]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0012942A176 for ; Wed, 29 Jul 2026 21:36:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.174 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785360997; cv=none; b=KubFTwjibcfMchq9F7m1jy+/fmBNOzwktsEreAoStJVi+5jEiQmbvqyRpvRaWXjnKznIo2ZS6S/rZXhgNuAPj99DJdRLzmzvJRMBLC8FumaorOPSm1ajCxxFgQhPyXm6l0BLUJc8emsEKz04q7/wiaAPq83gI4FDqR8l4ol1UE0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785360997; c=relaxed/simple; bh=yR5fKIYVJcWc/ZaDA+dXlb0F+aNrx3vc41X3bspmR9U=; h=Mime-Version:Content-Type:Date:Message-Id:Cc:Subject:From:To: References:In-Reply-To; b=hrt4mTD0YWfoco+xSaOzzE44cpyDPG9UwI3TfRks1XDFvbGyThTzAPcN0uQ4a/umFwOWwCjvNDpl870qwRI9arSAw1JyiCPFr0AE2ZF168unZmoaZBFBS6GMeeG/lOyMdgyWkHcBVI6tTMJPK1O4gKofxGNRfAx88poIUESusyQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=etsalapatis.com; spf=pass smtp.mailfrom=etsalapatis.com; dkim=pass (2048-bit key) header.d=etsalapatis-com.20251104.gappssmtp.com header.i=@etsalapatis-com.20251104.gappssmtp.com header.b=bGt/iEjc; arc=none smtp.client-ip=209.85.214.174 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=etsalapatis.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=etsalapatis.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=etsalapatis-com.20251104.gappssmtp.com header.i=@etsalapatis-com.20251104.gappssmtp.com header.b="bGt/iEjc" Received: by mail-pl1-f174.google.com with SMTP id d9443c01a7336-2cc73e322dbso17041185ad.1 for ; Wed, 29 Jul 2026 14:36:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=etsalapatis-com.20251104.gappssmtp.com; s=20251104; t=1785360991; x=1785965791; darn=vger.kernel.org; h=in-reply-to:references:to:from:subject:cc:message-id:date :content-type:content-transfer-encoding:mime-version:from:to:cc :subject:date:message-id:reply-to:content-type; bh=eZQ8VR07pXx0Bw0kE02/jttQnE1Ukn2+Gh6NYsBKzlI=; b=bGt/iEjczv8UstgvnwKYm+qjRwidQ4ojoCXXt2X9+G2W8W31JplSMyMR+TLM/KmRjJ Z7CBoDen2B3CaMCa1IHusGns0SZpeSXXluocFwvHCNKRL6A8akxPudwzcvZR+DIYAUU9 1lG4P5YebaXISi5m/j6jxK2MaBG2mY0lrnSFY6fybil3PxNYv9tCgQK2uykudgEk1b30 p74u31S0H96Ry+VC4A+CEkDPN5RLDefDfsO7oGVSn1J34jrsXbsXCuseEvw4LaXKsbFS seJgdO3usKU/i0TTQSADESZSo6Q2RVP2hhP4la1zODvYZ2h2sYAB2IyOy7fClGxkizMK Mihw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785360991; x=1785965791; h=in-reply-to:references:to:from:subject:cc:message-id:date :content-type:content-transfer-encoding:mime-version:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=eZQ8VR07pXx0Bw0kE02/jttQnE1Ukn2+Gh6NYsBKzlI=; b=mG4BXGWrAnGR/LZ9HLhmg+4etIHEU4x6RcPbNV/oiJBzbNQtf2oUGOdJWEDLQREFhh 09hrf9D4sur8byX/8GCJ5u3UC/47nRjq2D0NgJ5vKiVAQKRsczwXPUlch4BLMTVnx6lV EuNwEg9sirfJNUBvyvkuIoVeK2zzEIGbH5xau2mKcG4ZqHD/ffoF9XBtDoURLT0Goi/D 8W4unFLt/grm2OkNYcfx5hDKPfixkerIeV1+SpJl452pz1XirOkTuQ+q/oT2EwmXoy4P Xc1iEOmg7zfdpazZyOwxpM3w+iPHhtvGnqyTvgWikhb1O+K6csv3EOTsY/cuHScDp5Ds Gyrw== X-Forwarded-Encrypted: i=1; AHgh+Rq/EHD+C3V1XWhYVeLhzNJ8N5ZvsMx38FeyPN5GSRrDGQS164augc+ex26xOmY8wCOaBnzxwPNPazrJbxk=@vger.kernel.org X-Gm-Message-State: AOJu0YyKJ67wWW2F75n0GQI8CH2WIdx1OD+2FBQk6qgqxBqU3OielvCW JwU5dO0m674JTxnB8CMs7EV6UqTDzgnMajqQGqpQDlI/HRr9fnKNpFas1gMk/DtpNYPRwpZcH8j aNyzfmjrtzw== X-Gm-Gg: AR+sD12ZYDmJPd/DgrNW71t2KAgLCLgsGfSzA42MEXtJPYgkoI4OiPWvcE6/XSIOFvv GOALdaUYenJlOsZ76x86KJoVoYs0pi7Yxgi+rRb5LvKCJq6GaZ03AlWUoql6I/BdW+GzqSFJ225 3TcpJ4cZxV+SL3R6wseHPBUdDgANVLoKBjmDCVf+YOqS4uZCz6ndO1kJ+q+WyOrjf2FveGqAETN WQlZdsYjvijvJHhhH2wrVQ7ryYLscnvNCa9jF43qdzTEZGkf6J7cIuWThisN/zrGJEfIy4feGOL H0H1ra7lDV4DkvP379dwxU/gFNImaZNfi96MXQ8ER9xux9pfU4lXGp2j+nfG9mnSK/J+2Q5WY3W boWsXD+QYADQhW5JGjHFw4IQkI/NthJimxsOy14P81pqChAEK5X1L9jDymkFu9p5IxAxFBPjuaX 60nJR+uMdfv1+NcIAfpNxD4LfSvKPk7hD7I420ubXDsIlj X-Received: by 2002:a17:902:e5c3:b0:2c9:b8b7:5d27 with SMTP id d9443c01a7336-2d035c1c5f7mr398675ad.1.1785360991192; Wed, 29 Jul 2026 14:36:31 -0700 (PDT) Received: from localhost ([2620:10d:c090:600::1:d447]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-31504dab154sm14771138eec.26.2026.07.29.14.36.29 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Wed, 29 Jul 2026 14:36:30 -0700 (PDT) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=UTF-8 Date: Wed, 29 Jul 2026 17:36:28 -0400 Message-Id: Cc: "Stanislav Fomichev" , "Song Liu" , "Yonghong Song" , "Jiri Olsa" , "Emil Tsalapatis" , , , "Sechang Lim" Subject: Re: [PATCH bpf] bpf: Reject negative optlen in cgroup getsockopt hook From: "Emil Tsalapatis" To: "Junseo Lim" , "Alexei Starovoitov" , "Daniel Borkmann" , "Andrii Nakryiko" , "Eduard Zingerman" , "Kumar Kartikeya Dwivedi" , "Martin KaFai Lau" X-Mailer: aerc 0.21.0-0-g5549850facc2 References: <20260726070122.2407344-1-zirajs7@gmail.com> In-Reply-To: <20260726070122.2407344-1-zirajs7@gmail.com> On Sun Jul 26, 2026 at 3:01 AM EDT, Junseo Lim wrote: > A cgroup getsockopt BPF program can shrink ctx->optlen after the > kernel getsockopt handler has run. The kernel-buffer variant, used by > TCP_ZEROCOPY_RECEIVE, only rejects values larger than the original > length. > > If BPF writes a negative optlen, that value is accepted and propagated > back to the TCP getsockopt code. It can then be passed to > copy_to_sockptr() as a size_t and trigger the hardened usercopy > bytes > INT_MAX warning. > > Reject negative ctx.optlen in __cgroup_bpf_run_filter_getsockopt_kern(), > matching the lower-bound validation already present in the sockptr-based > getsockopt hook. > > Fixes: 9cacf81f8161 ("bpf: Remove extra lock_sock for TCP_ZEROCOPY_RECEIV= E") > Signed-off-by: Junseo Lim Reviewed-by: Emil Tsalapatis It'd be worth resending with a reproducer setting optlen to negative. > --- > Reproducer and warning:=20 > https://gist.github.com/ZirAjs/a177ec6d8f2c8ed7d93edca6313a9255 > > Tested by building and booting the patched kernel. The reproducer=20 > returns -EFAULT and no longer triggers the hardened usercopy warning. > > kernel/bpf/cgroup.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/kernel/bpf/cgroup.c b/kernel/bpf/cgroup.c > index 4355ccb78a9c..c04a244fe2e6 100644 > --- a/kernel/bpf/cgroup.c > +++ b/kernel/bpf/cgroup.c > @@ -2235,7 +2235,7 @@ int __cgroup_bpf_run_filter_getsockopt_kern(struct = sock *sk, int level, > if (ret < 0) > return ret; > =20 > - if (ctx.optlen > *optlen) > + if (ctx.optlen > *optlen || ctx.optlen < 0) > return -EFAULT; > =20 > /* BPF programs can shrink the buffer, export the modifications.