mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Bobby Eshleman <bobbyeshleman@gmail.com>
To: Kaifeng Wang <kaifengw@google.com>
Cc: netdev@vger.kernel.org, almasrymina@google.com,
	edumazet@google.com, pabeni@redhat.com, willemb@google.com,
	davem@davemloft.net, kuba@kernel.org, horms@kernel.org,
	sdf@fomichev.me, bobbyeshleman@meta.com, kaiyuanz@google.com,
	linux-kernel@vger.kernel.org
Subject: Re: [PATCH net] net: devmem: check uid and netns in net_devmem_get_binding()
Date: Tue, 6 Oct 2026 09:19:49 -0700	[thread overview]
Message-ID: <asUfpfngzZGlpkaC@devvm29614.prn0.facebook.com> (raw)
In-Reply-To: <20261005210403.3206872-1-kaifengw@google.com>

On Mon, Oct 05, 2026 at 09:04:03PM +0000, Kaifeng Wang wrote:
> NETDEV_CMD_BIND_TX is unprivileged, and dmabuf binding IDs are allocated
> from a single global xarray. Currently net_devmem_get_binding() looks up
> the binding by ID without checking whether the sending socket belongs to
> the same user or network namespace that created the binding.
> 
> Record the creating netlink socket's network namespace and UID on the
> binding, and verify both in net_devmem_get_binding() before checking the
> route destination device. Return -EINVAL on mismatch so callers cannot
> distinguish non-existent IDs from bindings owned by other users.
> 
> Fixes: bd61848900bf ("net: devmem: Implement TX path")
> Signed-off-by: Kaifeng Wang <kaifengw@google.com>
> ---
>  net/core/devmem.c      | 7 ++++++-
>  net/core/devmem.h      | 5 +++++
>  net/core/netdev-genl.c | 5 +++--
>  3 files changed, 14 insertions(+), 3 deletions(-)
> 
> diff --git a/net/core/devmem.c b/net/core/devmem.c
> index f4d60654ce7f..9a773b1ce92d 100644
> --- a/net/core/devmem.c
> +++ b/net/core/devmem.c
> @@ -191,6 +191,7 @@ net_devmem_bind_dmabuf(struct net_device *dev, void *vdev,
>  		       enum dma_data_direction direction,
>  		       unsigned int dmabuf_fd, unsigned int niov_shift,
>  		       struct netdev_nl_sock *priv,
> +		       const struct sock *nl_sk,
>  		       struct netlink_ext_ack *extack)
>  {
>  	struct net_devmem_dmabuf_binding *binding;
> @@ -220,6 +221,8 @@ net_devmem_bind_dmabuf(struct net_device *dev, void *vdev,
>  
>  	binding->dev = dev;
>  	binding->vdev = vdev;
> +	write_pnet(&binding->net, sock_net(nl_sk));
> +	binding->uid = sk_uid(nl_sk);
>  	binding->niov_shift = niov_shift;
>  	xa_init_flags(&binding->bound_rxqs, XA_FLAGS_ALLOC);
>  
> @@ -390,7 +393,9 @@ struct net_devmem_dmabuf_binding *net_devmem_get_binding(struct sock *sk,
>  	int err = 0;
>  
>  	binding = net_devmem_lookup_dmabuf(dmabuf_id);
> -	if (!binding || !binding->tx_vec) {
> +	if (!binding || !binding->tx_vec ||
> +	    !net_eq(sock_net(sk), read_pnet(&binding->net)) ||
> +	    !uid_eq(sk_uid(sk), binding->uid)) {
>  		err = -EINVAL;
>  		goto out_err;
>  	}
> diff --git a/net/core/devmem.h b/net/core/devmem.h
> index 4a293a7d1149..7b9d3e04367c 100644
> --- a/net/core/devmem.h
> +++ b/net/core/devmem.h
> @@ -10,6 +10,7 @@
>  #ifndef _NET_DEVMEM_H
>  #define _NET_DEVMEM_H
>  
> +#include <net/net_namespace.h>
>  #include <net/netmem.h>
>  #include <net/netdev_netlink.h>
>  
> @@ -26,6 +27,8 @@ struct net_devmem_dmabuf_binding {
>  	 * dereferenced.
>  	 */
>  	void *vdev;
> +	possible_net_t net;
> +	kuid_t uid;
>  	struct gen_pool *chunk_pool;
>  	/* Protect dev */
>  	struct mutex lock;
> @@ -97,6 +100,7 @@ net_devmem_bind_dmabuf(struct net_device *dev, void *vdev,
>  		       enum dma_data_direction direction,
>  		       unsigned int dmabuf_fd, unsigned int niov_shift,
>  		       struct netdev_nl_sock *priv,
> +		       const struct sock *nl_sk,
>  		       struct netlink_ext_ack *extack);
>  struct net_devmem_dmabuf_binding *net_devmem_lookup_dmabuf(u32 id);
>  void net_devmem_unbind_dmabuf(struct net_devmem_dmabuf_binding *binding);
> @@ -181,6 +185,7 @@ net_devmem_bind_dmabuf(struct net_device *dev, void *vdev,
>  		       unsigned int dmabuf_fd,
>  		       unsigned int niov_shift,
>  		       struct netdev_nl_sock *priv,
> +		       const struct sock *nl_sk,
>  		       struct netlink_ext_ack *extack)
>  {
>  	return ERR_PTR(-EOPNOTSUPP);
> diff --git a/net/core/netdev-genl.c b/net/core/netdev-genl.c
> index 33b9f4eb9565..847814e3df3f 100644
> --- a/net/core/netdev-genl.c
> +++ b/net/core/netdev-genl.c
> @@ -1094,7 +1094,7 @@ int netdev_nl_bind_rx_doit(struct sk_buff *skb, struct genl_info *info)
>  
>  	binding = net_devmem_bind_dmabuf(netdev, NULL, dma_dev, DMA_FROM_DEVICE,
>  					 dmabuf_fd, niov_shift, priv,
> -					 info->extack);
> +					 NETLINK_CB(skb).sk, info->extack);
>  	if (IS_ERR(binding)) {
>  		err = PTR_ERR(binding);
>  		goto err_rxq_bitmap;
> @@ -1243,7 +1243,8 @@ int netdev_nl_bind_tx_doit(struct sk_buff *skb, struct genl_info *info)
>  	binding = net_devmem_bind_dmabuf(bind_dev,
>  					 bind_dev != netdev ? netdev : NULL,
>  					 dma_dev, DMA_TO_DEVICE, dmabuf_fd,
> -					 PAGE_SHIFT, priv, info->extack);
> +					 PAGE_SHIFT, priv, NETLINK_CB(skb).sk,
> +					 info->extack);
>  	if (IS_ERR(binding)) {
>  		err = PTR_ERR(binding);
>  		goto err_unlock_bind_dev;
> -- 
> 2.56.0.rc1.315.gc6ed9934b7-goog
> 

Reviewed-by: Bobby Eshleman <bobbyeshleman@meta.com>

      parent reply	other threads:[~2026-10-06 16:19 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-05 21:04 Kaifeng Wang
2026-10-05 21:09 ` netdev-bot+sinfo
2026-10-05 21:22   ` Kaifeng Wang
2026-10-05 22:24 ` Stanislav Fomichev
2026-10-06 16:19 ` Bobby Eshleman [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=asUfpfngzZGlpkaC@devvm29614.prn0.facebook.com \
    --to=bobbyeshleman@gmail.com \
    --cc=almasrymina@google.com \
    --cc=bobbyeshleman@meta.com \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=horms@kernel.org \
    --cc=kaifengw@google.com \
    --cc=kaiyuanz@google.com \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=sdf@fomichev.me \
    --cc=willemb@google.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®