From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f174.google.com (mail-pf1-f174.google.com [209.85.210.174]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3FA2D414DCA for ; Mon, 14 Sep 2026 21:55:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.174 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789422932; cv=none; b=T2x3tLTGbu8L523T2rD+rf6f6k/sKIh1/sZB9LuPbzZ6w2NgH2rVB04uPpEgQEa9/c+OVe3GhPPaWIBPD6DptBBeLbkrxxaN3OFFZXgHPz9PaksH+BMfIAavjHNxJhtb04q6JO5uFwIC6Ar/fvZWJo0RlRPYUzQmo6oS8ITVXNc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789422932; c=relaxed/simple; bh=ZW24AzKibRmsChTIZFpOqpEWa8pPmQADDutsZs1I8K8=; h=Mime-Version:Content-Type:Date:Message-Id:From:To:Cc:Subject: References:In-Reply-To; b=AIZ9eeKLFklNWdiiiVx3fiMZanNThPfC7GuMOq0JM+pF6XpW/rr/R7HOLQV40Vlw/cy+spRUQA22+vXQHHdNJxB8KLP31+KgYEGicpkf/4Xhn1fv3igfrPbMHPzfasCovZQZ3Zvim51GuK7JQOTywmU6TrRBLNeXHrFrOtIHkrE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=etsalapatis.com; spf=pass smtp.mailfrom=etsalapatis.com; dkim=pass (2048-bit key) header.d=etsalapatis-com.20251104.gappssmtp.com header.i=@etsalapatis-com.20251104.gappssmtp.com header.b=N/h/zzjJ; arc=none smtp.client-ip=209.85.210.174 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=etsalapatis.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=etsalapatis.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=etsalapatis-com.20251104.gappssmtp.com header.i=@etsalapatis-com.20251104.gappssmtp.com header.b="N/h/zzjJ" Received: by mail-pf1-f174.google.com with SMTP id d2e1a72fcca58-86a25369f16so3000515b3a.3 for ; Mon, 14 Sep 2026 14:55:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=etsalapatis-com.20251104.gappssmtp.com; s=20251104; t=1789422929; x=1790027729; darn=vger.kernel.org; h=in-reply-to:references:subject:cc:to:from:message-id:date :content-type:content-transfer-encoding:mime-version:from:to:cc :subject:date:message-id:reply-to:content-type; bh=T/TGZ0NqpBEB9GgHRd+TQ3uXQZZ6N+mNyW4FV6tZL6I=; b=N/h/zzjJjRH0m+Oyfcj/xy5x9EtK3sUMWeVZlp5JgAojOOX004qchGrl2hB9yCEskF tJwf1R/NCSK9yAI+K4nYw3dVIudOhV5g9aeBCPASqZMgy1vJLiDiW+YYsKYeHQjUiEXX WJkoogutrbWSr3WelghTNQVTyoAK3SKRNPxhi5Uio4LpT8Dxv4zgHCcndxHMTeO4QquC +8Q9wHh2fHVVe/OlrMsy/QZgMofWG4QakSORIU+KfqEm/XBgAJXKDjAILL3xnGwgyzWA HzcYWoFoQ7Gks2H3rtkZ11YwZFRn1Vik6Af976XabKK3BSRh+7MQRaMqMl8vCAInNMf+ iDMA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789422929; x=1790027729; h=in-reply-to:references:subject:cc:to:from:message-id:date :content-type:content-transfer-encoding:mime-version:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=T/TGZ0NqpBEB9GgHRd+TQ3uXQZZ6N+mNyW4FV6tZL6I=; b=I70xNQpw1qByD//OOb4U/bYSXlT47B/+HRPjR/zPUktm2lsdDFWOXtZM1w79WEWhso WPoxjQYanmA7Govng26PA86Q7mP+JngxGqD4Fdw46G4SGJb8o57fs0goMhBjezxel5am Lh9o/vU76UIJcT1iVS8QdqNrl0pIwnKDDKI36EtCufqtbwNnhFjyhU2QV0Yc9KdsVMCG mrz4mHJCaibgkDOCgegQYRaBEwV88Sfds2BOtz4RIAn1MyLVm5/4S95qKytYgho+aZRU ZY7912dnh+iU2Lx7PkCVXO9kayzamt7DHqo9O0f06uLKBuP/xUge+wHiRL0sNpEME+hu Kd3g== X-Forwarded-Encrypted: i=1; AKwUvBw3JtEAszwY+SHI5QUXpOCKAPD5Kz5WPrmzZWNWgk5NCd2dBTRM1guvSqd6O/RzPQI6LMKKFEQVnkbJCMc=@vger.kernel.org X-Gm-Message-State: AFuF++m9A4dyvwAhBrzBBDOmPcflThBm1rPXQwrAoS0aU12dQpGQw7mP HIZTFhjCv6eWOxzxrLxbhpeOOaP3N6wr+MA9fPUdJQqWwuekwXmQPugv1wDqnrYANEo= X-Gm-Gg: AYBFou2MTUInZUq80H7ArTiiKA/5X5PxZMjokqae22JuPtU+VMnMLztIj14qKHO5Bxk 6qBo7F3oIygN5aJpZ5TUPX0meevnR9m4mk2zeuOk8KBw5SjplGuGHxNL0cn3A8poFivgadqPRK7 TY43XChTdeOFc4Xhx9J6MoXq7SRqqcS/U2j4/6/twVq8F4zNbuOhmgo6R6tFxGzJacnIozJBZ8B kOELNyD1UH/mhvS1QWP5IAAP8cjhMriKxu+Zi+xD3BMi/NVAF5Z1Cuh9hEdz+YGb6Q/c7x9u/8c dmMo9pomNqlHLRHQU0stRI5tOF3qOR4CzneEKChYM5Ov66CJJ5UeUU+WEzXIRrLgYsLxcWpeO7l MoLsBRmSYRSRapJiRf4UpUJRY96zIshayFw7exOX7+9FlhW8RgKyJuO1RN+1Kz60q5or+YpMlkk MIzkQdPkqal4r00yXXFIbBD+LhWCEo4xpXXZnsPJEkHCjJQhxP3H7dgiylFjGIvQeXmpoDIHtKc hjb+NJ/TBWbX4BXp82o4xgyW9t4 X-Received: by 2002:a05:6a00:2403:b0:864:cbc5:b8c1 with SMTP id d2e1a72fcca58-86f83344128mr8757554b3a.2.1789422929402; Mon, 14 Sep 2026 14:55:29 -0700 (PDT) Received: from localhost (107-190-31-17.cpe.teksavvy.com. [107.190.31.17]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-86b29dc09d4sm5106016b3a.47.2026.09.14.14.55.26 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 14 Sep 2026 14:55:27 -0700 (PDT) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=UTF-8 Date: Mon, 14 Sep 2026 21:55:26 +0000 Message-Id: From: "Emil Tsalapatis" To: "Shihuang Liu" , Cc: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , Subject: Re: [PATCH bpf v2 1/2] bpf: reject incompatible socket assignments X-Mailer: aerc 0.21.0 References: <20260911172313.64009-1-shlomojune6@gmail.com> In-Reply-To: <20260911172313.64009-1-shlomojune6@gmail.com> On Fri Sep 11, 2026 at 5:23 PM UTC, Shihuang Liu wrote: > bpf_sk_assign() permits TC ingress programs to associate an IPv6 packet > with an AF_INET socket. The receive path can then interpret IPv6 skb > control data as IPv4 metadata. When IP_RETOPTS is enabled, this can cause > __ip_options_echo() to copy beyond its stack buffer. > > Reject incompatible packet and socket families in bpf_sk_assign() and > bpf_sk_assign_tcp_reqsk(). Continue to allow IPv4 packets to use > dual-stack AF_INET6 sockets. > > Check request sockets against rsk_ops->family, since their sk_family is > inherited from the listener and sk_ipv6only is not initialized. > > Fixes: cf7fbe660f2d ("bpf: Add socket assign support") > Assisted-by: LLM > Signed-off-by: Shihuang Liu > --- > Changes since v1: > - Move family validation out of the IPv6 receive fast path and into > bpf_sk_assign() and bpf_sk_assign_tcp_reqsk(). > - Preserve IPv4 assignments to dual-stack AF_INET6 sockets. > - Check request sockets using rsk_ops->family. > - Split the fix into two patches and target the BPF fixes tree. > > v1: > https://lore.kernel.org/netdev/20260823101809.26802-1-shlomojune6@gmail.c= om/ > > include/uapi/linux/bpf.h | 4 ++++ > net/core/filter.c | 31 +++++++++++++++++++++++++++++++ > tools/include/uapi/linux/bpf.h | 4 ++++ > 3 files changed, 39 insertions(+) > > diff --git a/include/uapi/linux/bpf.h b/include/uapi/linux/bpf.h > index 732b35cc08d1c..5d8f5e2c8db38 100644 > --- a/include/uapi/linux/bpf.h > +++ b/include/uapi/linux/bpf.h > @@ -4568,6 +4568,10 @@ union bpf_attr { > * **-EOPNOTSUPP** if the operation is not supported, for example > * a call from outside of TC ingress. > * > + * **-EAFNOSUPPORT** if the socket family is not compatible with > + * the network layer of the packet, for example an **AF_INET** > + * socket and an IPv6 packet. > + * > * long bpf_sk_assign(struct bpf_sk_lookup *ctx, struct bpf_sock *sk, u6= 4 flags) > * Description > * Helper is overloaded depending on BPF program type. This > diff --git a/net/core/filter.c b/net/core/filter.c > index 61940e7535523..e9cc76b775c0c 100644 > --- a/net/core/filter.c > +++ b/net/core/filter.c > @@ -3491,6 +3491,32 @@ static int bpf_skb_proto_xlat(struct sk_buff *skb,= __be16 to_proto) > return -ENOTSUPP; > } > =20 > +static bool bpf_sk_assign_family_ok(const struct sk_buff *skb, > + const struct sock *sk) This should also be used in bpf_skb_adjust_room that can also change the address family of the skb after it has been checked against that of the sk. > +{ > + unsigned short family; > + > + switch (skb->protocol) { > + case htons(ETH_P_IP): > + family =3D AF_INET; > + break; > + case htons(ETH_P_IPV6): > + family =3D AF_INET6; > + break; What about VLAN? pw-bot: cr > + default: > + return true; > + } > + > + /* Requests inherit the listener family, but have family-specific ops. = */ > + if (sk->sk_state =3D=3D TCP_NEW_SYN_RECV) > + return inet_reqsk(sk)->rsk_ops->family =3D=3D family; > + > + return sk->sk_family =3D=3D family || > + (family =3D=3D AF_INET && > + sk->sk_family =3D=3D AF_INET6 && > + !ipv6_only_sock(sk)); > +} > + > BPF_CALL_3(bpf_skb_change_proto, struct sk_buff *, skb, __be16, proto, > u64, flags) > { > @@ -7989,6 +8015,8 @@ BPF_CALL_3(bpf_sk_assign, struct sk_buff *, skb, st= ruct sock *, sk, u64, flags) > return -ENETUNREACH; > if (sk_unhashed(sk)) > return -EOPNOTSUPP; > + if (!bpf_sk_assign_family_ok(skb, sk)) > + return -EAFNOSUPPORT; > if (sk_is_refcounted(sk) && > unlikely(!refcount_inc_not_zero(&sk->sk_refcnt))) > return -ENOENT; > @@ -12526,6 +12554,9 @@ __bpf_kfunc int bpf_sk_assign_tcp_reqsk(struct __= sk_buff *s, struct sock *sk, > if (net !=3D sock_net(sk)) > return -ENETUNREACH; > =20 > + if (!bpf_sk_assign_family_ok(skb, sk)) > + return -EAFNOSUPPORT; > + > switch (skb->protocol) { > case htons(ETH_P_IP): > ops =3D &tcp_request_sock_ops; > diff --git a/tools/include/uapi/linux/bpf.h b/tools/include/uapi/linux/bp= f.h > index 732b35cc08d1c..5d8f5e2c8db38 100644 > --- a/tools/include/uapi/linux/bpf.h > +++ b/tools/include/uapi/linux/bpf.h > @@ -4568,6 +4568,10 @@ union bpf_attr { > * **-EOPNOTSUPP** if the operation is not supported, for example > * a call from outside of TC ingress. > * > + * **-EAFNOSUPPORT** if the socket family is not compatible with > + * the network layer of the packet, for example an **AF_INET** > + * socket and an IPv6 packet. > + * > * long bpf_sk_assign(struct bpf_sk_lookup *ctx, struct bpf_sock *sk, u6= 4 flags) > * Description > * Helper is overloaded depending on BPF program type. This