Commit ba62d611 authored by Lorenz Bauer's avatar Lorenz Bauer Committed by Martin KaFai Lau

bpf: Refuse unused attributes in bpf_prog_{attach,detach}

The recently added tcx attachment extended the BPF UAPI for attaching and
detaching by a couple of fields. Those fields are currently only supported
for tcx, other types like cgroups and flow dissector silently ignore the
new fields except for the new flags.

This is problematic once we extend bpf_mprog to older attachment types, since
it's hard to figure out whether the syscall really was successful if the
kernel silently ignores non-zero values.

Explicitly reject non-zero fields relevant to bpf_mprog for attachment types
which don't use the latter yet.

Fixes: e420bed0 ("bpf: Add fd-based tcx multi-prog infra with link support")
Signed-off-by: default avatarLorenz Bauer <lmb@isovalent.com>
Co-developed-by: default avatarDaniel Borkmann <daniel@iogearbox.net>
Signed-off-by: default avatarDaniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/r/20231006220655.1653-3-daniel@iogearbox.netSigned-off-by: default avatarMartin KaFai Lau <martin.lau@kernel.org>
parent edfa9af0
...@@ -3796,7 +3796,6 @@ static int bpf_prog_attach(const union bpf_attr *attr) ...@@ -3796,7 +3796,6 @@ static int bpf_prog_attach(const union bpf_attr *attr)
{ {
enum bpf_prog_type ptype; enum bpf_prog_type ptype;
struct bpf_prog *prog; struct bpf_prog *prog;
u32 mask;
int ret; int ret;
if (CHECK_ATTR(BPF_PROG_ATTACH)) if (CHECK_ATTR(BPF_PROG_ATTACH))
...@@ -3805,10 +3804,16 @@ static int bpf_prog_attach(const union bpf_attr *attr) ...@@ -3805,10 +3804,16 @@ static int bpf_prog_attach(const union bpf_attr *attr)
ptype = attach_type_to_prog_type(attr->attach_type); ptype = attach_type_to_prog_type(attr->attach_type);
if (ptype == BPF_PROG_TYPE_UNSPEC) if (ptype == BPF_PROG_TYPE_UNSPEC)
return -EINVAL; return -EINVAL;
mask = bpf_mprog_supported(ptype) ? if (bpf_mprog_supported(ptype)) {
BPF_F_ATTACH_MASK_MPROG : BPF_F_ATTACH_MASK_BASE; if (attr->attach_flags & ~BPF_F_ATTACH_MASK_MPROG)
if (attr->attach_flags & ~mask) return -EINVAL;
return -EINVAL; } else {
if (attr->attach_flags & ~BPF_F_ATTACH_MASK_BASE)
return -EINVAL;
if (attr->relative_fd ||
attr->expected_revision)
return -EINVAL;
}
prog = bpf_prog_get_type(attr->attach_bpf_fd, ptype); prog = bpf_prog_get_type(attr->attach_bpf_fd, ptype);
if (IS_ERR(prog)) if (IS_ERR(prog))
...@@ -3878,6 +3883,10 @@ static int bpf_prog_detach(const union bpf_attr *attr) ...@@ -3878,6 +3883,10 @@ static int bpf_prog_detach(const union bpf_attr *attr)
if (IS_ERR(prog)) if (IS_ERR(prog))
return PTR_ERR(prog); return PTR_ERR(prog);
} }
} else if (attr->attach_flags ||
attr->relative_fd ||
attr->expected_revision) {
return -EINVAL;
} }
switch (ptype) { switch (ptype) {
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment