• Martin KaFai Lau's avatar
    bpf: Check sk_fullsock() before returning from bpf_sk_lookup() · f7355a6c
    Martin KaFai Lau authored
    The BPF_FUNC_sk_lookup_xxx helpers return RET_PTR_TO_SOCKET_OR_NULL.
    Meaning a fullsock ptr and its fullsock's fields in bpf_sock can be
    accessed, e.g. type, protocol, mark and priority.
    Some new helper, like bpf_sk_storage_get(), also expects
    ARG_PTR_TO_SOCKET is a fullsock.
    
    bpf_sk_lookup() currently calls sk_to_full_sk() before returning.
    However, the ptr returned from sk_to_full_sk() is not guaranteed
    to be a fullsock.  For example, it cannot get a fullsock if sk
    is in TCP_TIME_WAIT.
    
    This patch checks for sk_fullsock() before returning. If it is not
    a fullsock, sock_gen_put() is called if needed and then returns NULL.
    
    Fixes: 6acc9b43 ("bpf: Add helper to retrieve socket in BPF")
    Cc: Joe Stringer <joe@isovalent.com>
    Signed-off-by: default avatarMartin KaFai Lau <kafai@fb.com>
    Acked-by: default avatarJoe Stringer <joe@isovalent.com>
    Signed-off-by: default avatarDaniel Borkmann <daniel@iogearbox.net>
    f7355a6c
filter.c 229 KB