Commit 73e4f9e6 authored by Kui-Feng Lee's avatar Kui-Feng Lee Committed by Martin KaFai Lau
Browse files

bpf, net: validate struct_ops when updating value.



Perform all validations when updating values of struct_ops maps. Doing
validation in st_ops->reg() and st_ops->update() is not necessary anymore.
However, tcp_register_congestion_control() has been called in various
places. It still needs to do validations.

Cc: netdev@vger.kernel.org
Signed-off-by: default avatarKui-Feng Lee <thinker.li@gmail.com>
Link: https://lore.kernel.org/r/20240224223418.526631-2-thinker.li@gmail.com


Signed-off-by: default avatarMartin KaFai Lau <martin.lau@kernel.org>
parent 01031fd4
Loading
Loading
Loading
Loading
+6 −5
Original line number Diff line number Diff line
@@ -672,13 +672,14 @@ static long bpf_struct_ops_map_update_elem(struct bpf_map *map, void *key,
		*(unsigned long *)(udata + moff) = prog->aux->id;
	}

	if (st_map->map.map_flags & BPF_F_LINK) {
		err = 0;
	if (st_ops->validate) {
		err = st_ops->validate(kdata);
		if (err)
			goto reset_unlock;
	}

	if (st_map->map.map_flags & BPF_F_LINK) {
		err = 0;
		arch_protect_bpf_trampoline(st_map->image, PAGE_SIZE);
		/* Let bpf_link handle registration & unregistration.
		 *
+1 −5
Original line number Diff line number Diff line
@@ -146,11 +146,7 @@ EXPORT_SYMBOL_GPL(tcp_unregister_congestion_control);
int tcp_update_congestion_control(struct tcp_congestion_ops *ca, struct tcp_congestion_ops *old_ca)
{
	struct tcp_congestion_ops *existing;
	int ret;

	ret = tcp_validate_congestion_control(ca);
	if (ret)
		return ret;
	int ret = 0;

	ca->key = jhash(ca->name, sizeof(ca->name), strlen(ca->name));