android_kernel_motorola_sm6375/net
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Willem de Bruijn 8ed702674d bpf: support SKF_NET_OFF and SKF_LL_OFF on skb frags
[ Upstream commit d4bac0288a2b444e468e6df9cb4ed69479ddf14a ]

Classic BPF socket filters with SKB_NET_OFF and SKB_LL_OFF fail to
read when these offsets extend into frags.

This has been observed with iwlwifi and reproduced with tun with
IFF_NAPI_FRAGS. The below straightforward socket filter on UDP port,
applied to a RAW socket, will silently miss matching packets.

    const int offset_proto = offsetof(struct ip6_hdr, ip6_nxt);
    const int offset_dport = sizeof(struct ip6_hdr) + offsetof(struct udphdr, dest);
    struct sock_filter filter_code[] = {
            BPF_STMT(BPF_LD  + BPF_B   + BPF_ABS, SKF_AD_OFF + SKF_AD_PKTTYPE),
            BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, PACKET_HOST, 0, 4),
            BPF_STMT(BPF_LD  + BPF_B   + BPF_ABS, SKF_NET_OFF + offset_proto),
            BPF_JUMP(BPF_JMP + BPF_JEQ + BPF_K, IPPROTO_UDP, 0, 2),
            BPF_STMT(BPF_LD  + BPF_H   + BPF_ABS, SKF_NET_OFF + offset_dport),

This is unexpected behavior. Socket filter programs should be
consistent regardless of environment. Silent misses are
particularly concerning as hard to detect.

Use skb_copy_bits for offsets outside linear, same as done for
non-SKF_(LL|NET) offsets.

Offset is always positive after subtracting the reference threshold
SKB_(LL|NET)_OFF, so is always >= skb_(mac|network)_offset. The sum of
the two is an offset against skb->data, and may be negative, but it
cannot point before skb->head, as skb_(mac|network)_offset would too.

This appears to go back to when frag support was introduced to
sk_run_filter in linux-2.4.4, before the introduction of git.

The amount of code change and 8/16/32 bit duplication are unfortunate.
But any attempt I made to be smarter saved very few LoC while
complicating the code.

Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Link: https://lore.kernel.org/netdev/20250122200402.3461154-1-maze@google.com/
Link: https://elixir.bootlin.com/linux/2.4.4/source/net/core/filter.c#L244
Reported-by: Matt Moeller <moeller.matt@gmail.com>
Co-developed-by: Maciej Żenczykowski <maze@google.com>
Signed-off-by: Maciej Żenczykowski <maze@google.com>
Signed-off-by: Willem de Bruijn <willemb@google.com>
Acked-by: Stanislav Fomichev <sdf@fomichev.me>
Link: https://lore.kernel.org/r/20250408132833.195491-2-willemdebruijn.kernel@gmail.com
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-05-02 07:39:13 +02:00
..
6lowpan
9p 9p/xen: fix release of IRQ 2024-12-14 19:44:41 +01:00
802 net: 802: LLC+SNAP OID:PID lookup on start of skb data 2025-02-01 18:18:45 +01:00
8021q net: vlan: don't propagate flags on open 2025-05-02 07:39:11 +02:00
appletalk
atm atm: Fix NULL pointer dereference 2025-04-10 14:29:38 +02:00
ax25
batman-adv batman-adv: Ignore own maximum aggregation size during RX 2025-04-10 14:29:38 +02:00
bluetooth Bluetooth: Fix error code in chan_alloc_skb_cb() 2025-04-10 14:29:38 +02:00
bpf
bpfilter
bridge netfilter: Replace zero-length array with flexible-array member 2025-01-09 13:23:35 +01:00
caif
can can: statistics: use atomic access in hot path 2025-04-10 14:29:42 +02:00
ceph
core bpf: support SKF_NET_OFF and SKF_LL_OFF on skb frags 2025-05-02 07:39:13 +02:00
dcb
dccp net: fix data-races around sk->sk_forward_alloc 2025-02-01 18:18:52 +01:00
decnet
dns_resolver
dsa
ethernet
hsr
ieee802154 net: ieee802154: do not leave a dangling sk pointer in ieee802154_create() 2024-12-14 19:44:51 +01:00
ife
ipv4 net-timestamp: support TCP GSO case for a few missing flags 2025-03-13 12:43:30 +01:00
ipv6 ipv6: fix omitted netlink attributes when using RTEXT_FILTER_SKIP_STATS 2025-04-10 14:29:43 +02:00
iucv
kcm
key
l2tp
l3mdev
lapb
llc llc: do not use skb_get() before dev_queue_xmit() 2025-03-13 12:43:29 +01:00
mac80211 wifi: mac80211: wake the queues in case of failure in resume 2025-01-09 13:23:35 +01:00
mac802154 mac802154: check local interfaces before deleting sdata list 2025-02-01 18:18:50 +01:00
mpls
ncsi net/ncsi: wait for the last response to Deselect Package before configuring channel 2025-03-13 12:43:11 +01:00
netfilter netfilter: nft_exthdr: fix offset with ipv4_find_option() 2025-04-10 14:29:35 +02:00
netlabel
netlink
netrom netrom: check buffer length before accessing it 2025-01-09 13:23:35 +01:00
nfc NFC: nci: Add bounds checking in nci_hci_create_pipe() 2025-03-13 12:43:11 +01:00
nsh
openvswitch openvswitch: use RCU protection in ovs_vport_cmd_fill_info() 2025-03-13 12:43:18 +01:00
packet af_packet: fix vlan_get_protocol_dgram() vs MSG_PEEK 2025-01-09 13:23:35 +01:00
phonet
psample
qrtr
rds
rfkill
rose net: rose: lock the socket in rose_bind() 2025-03-13 12:43:06 +01:00
rxrpc
sched net_sched: skbprio: Remove overly strict queue assertions 2025-04-10 14:29:43 +02:00
sctp sctp: Fix undefined behavior in left shift operation 2025-04-10 14:29:36 +02:00
smc net/smc: check sndbuf_space again after NOSPACE flag is set in smc_poll 2025-01-09 13:23:27 +01:00
strparser
sunrpc sunrpc: suppress warnings for unused procfs functions 2025-03-13 12:43:24 +01:00
switchdev
tipc tipc: fix memory leak in tipc_link_xmit 2025-05-02 07:39:08 +02:00
tls tls: Fix tls_sw_sendmsg error handling 2025-02-01 18:18:45 +01:00
unix
vmw_vsock vsock: avoid timeout during connect() if the socket is closing 2025-04-10 14:29:43 +02:00
wimax
wireless wifi: nl80211: reject cooked mode if it is set along with other flags 2025-03-13 12:43:28 +01:00
x25
xdp
xfrm xfrm_output: Force software GSO only in tunnel mode 2025-04-10 14:29:37 +02:00
compat.c
Kconfig
Makefile
socket.c
sysctl_net.c