Jakub Sitnicki
71e96c3b40
UPSTREAM: inet: Run SK_LOOKUP BPF program on socket lookup
...
Run a BPF program before looking up a listening socket on the receive path.
Program selects a listening socket to yield as result of socket lookup by
calling bpf_sk_assign() helper and returning SK_PASS code. Program can
revert its decision by assigning a NULL socket with bpf_sk_assign().
Alternatively, BPF program can also fail the lookup by returning with
SK_DROP, or let the lookup continue as usual with SK_PASS on return, when
no socket has been selected with bpf_sk_assign().
This lets the user match packets with listening sockets freely at the last
possible point on the receive path, where we know that packets are destined
for local delivery after undergoing policing, filtering, and routing.
With BPF code selecting the socket, directing packets destined to an IP
range or to a port range to a single socket becomes possible.
In case multiple programs are attached, they are run in series in the order
in which they were attached. The end result is determined from return codes
of all the programs according to following rules:
1. If any program returned SK_PASS and selected a valid socket, the socket
is used as result of socket lookup.
2. If more than one program returned SK_PASS and selected a socket,
last selection takes effect.
3. If any program returned SK_DROP, and no program returned SK_PASS and
selected a socket, socket lookup fails with -ECONNREFUSED.
4. If all programs returned SK_PASS and none of them selected a socket,
socket lookup continues to htable-based lookup.
Suggested-by: Marek Majkowski <marek@cloudflare.com>
Change-Id: Ibc8c3ee012474990fe81f3baeb2234e19bc3a3ec
Signed-off-by: Jakub Sitnicki <jakub@cloudflare.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Link: https://lore.kernel.org/bpf/20200717103536.397595-5-jakub@cloudflare.com
2026-01-14 18:13:17 -08:00
..
bpfilter
UPSTREAM: umd: Track user space drivers with struct pid
2026-01-14 18:12:15 -08:00
netfilter
Revert "netfilter: Replace zero-length array with flexible-array member"
2025-01-14 17:17:17 +00:00
af_inet.c
UPSTREAM: bpf: Add BPF_CGROUP_INET_SOCK_RELEASE hook
2026-01-14 18:12:01 -08:00
ah4.c
arp.c
This is the 5.4.291 stable release
2025-03-13 14:53:52 +00:00
bpf_tcp_ca.c
UPSTREAM: bpf: Change bpf_sk_storage_*() to accept ARG_PTR_TO_BTF_ID_SOCK_COMMON
2026-01-14 18:12:34 -08:00
cipso_ipv4.c
cipso: fix total option length computation
2024-07-05 09:08:22 +02:00
datagram.c
devinet.c
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
esp4.c
net: ipv4: fix return value check in esp_remove_trailer
2023-10-25 11:53:21 +02:00
esp4_offload.c
fib_frontend.c
ipv4: Mask upper DSCP bits and ECN bits in NETLINK_FIB_LOOKUP family
2024-11-08 16:20:37 +01:00
fib_lookup.h
fib_notifier.c
fib_rules.c
ip: fib_rules: Fetch net from fib_rule in fib[46]_rule_configure().
2025-06-04 14:32:34 +02:00
fib_semantics.c
ipv4: fib: annotate races around nh->nh_saddr_genid and nh->nh_saddr
2023-10-25 11:53:21 +02:00
fib_trie.c
fou.c
gre_demux.c
gre_offload.c
icmp.c
icmp: fix icmp_ndo_send address translation for reply direction
2025-09-09 18:43:57 +02:00
igmp.c
UPSTREAM: ipv4: igmp: fix refcnt uaf issue when receiving igmp query packet
2023-12-21 11:28:11 +00:00
inet_connection_sock.c
Merge tag 'android11-5.4.293_r00' into android11-5.4
2025-05-26 03:40:18 -07:00
inet_diag.c
inet_diag: Initialize pad field in struct inet_diag_req_v2
2024-07-18 11:40:50 +02:00
inet_fragment.c
Revert "inet: inet_defrag: prevent sk release while still in use"
2024-11-09 14:30:42 +00:00
inet_hashtables.c
UPSTREAM: inet: Run SK_LOOKUP BPF program on socket lookup
2026-01-14 18:13:17 -08:00
inet_timewait_sock.c
tcp: Fix NEW_SYN_RECV handling in inet_twsk_purge()
2024-05-02 16:18:37 +02:00
inetpeer.c
ip_forward.c
ip_fragment.c
Revert "inet: inet_defrag: prevent sk release while still in use"
2024-11-09 14:30:42 +00:00
ip_gre.c
BACKPORT: net: add a new ndo_tunnel_ioctl method
2026-01-14 18:12:44 -08:00
ip_input.c
BACKPORT: bpf: Add socket assign support
2025-12-23 13:36:11 -08:00
ip_options.c
ip_output.c
net: ipv4: fix a memleak in ip_setup_cork
2024-02-23 08:25:05 +01:00
ip_sockglue.c
ip_tunnel.c
BACKPORT: net: add a new ndo_tunnel_ioctl method
2026-01-14 18:12:44 -08:00
ip_tunnel_core.c
UPSTREAM: net: ip_tunnel: add header_ops for layer 3 devices
2025-09-24 12:16:37 +02:00
ip_vti.c
BACKPORT: net: add a new ndo_tunnel_ioctl method
2026-01-14 18:12:44 -08:00
ipcomp.c
ipconfig.c
ipip.c
BACKPORT: net: add a new ndo_tunnel_ioctl method
2026-01-14 18:12:44 -08:00
ipmr.c
ipmr: fix tables suspicious RCU usage
2024-12-14 19:44:34 +01:00
ipmr_base.c
ipmr: do not call mr_mfc_uses_dev() for unres entries
2025-03-13 12:42:59 +01:00
Kconfig
Makefile
BACKPORT: udp_tunnel: add central NIC RX port offload infrastructure
2026-01-14 18:12:10 -08:00
metrics.c
netfilter.c
netlink.c
nexthop.c
This is the 5.4.302 stable release
2025-12-03 14:36:44 +00:00
ping.c
proc.c
protocol.c
raw.c
raw_diag.c
route.c
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
syncookies.c
tcp: fix cookie_init_timestamp() overflows
2023-11-20 10:30:10 +01:00
sysctl_net_ipv4.c
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
tcp.c
UPSTREAM: tcp: simplify tcp_set_congestion_control(): Always reinitialize
2026-01-14 18:12:28 -08:00
tcp_bbr.c
tcp_bic.c
tcp_bpf.c
BACKPORT: bpf, sockmap: Fix sk->sk_forward_alloc warn_on in sk_stream_kill_queues
2026-01-14 18:13:10 -08:00
tcp_cdg.c
tcp_cong.c
UPSTREAM: tcp: simplify tcp_set_congestion_control(): Always reinitialize
2026-01-14 18:12:28 -08:00
tcp_cubic.c
tcp_dctcp.c
tcp: Fix shift-out-of-bounds in dctcp_update_alpha().
2024-06-16 13:28:45 +02:00
tcp_dctcp.h
tcp_diag.c
net: annotate lockless accesses to sk->sk_max_ack_backlog
2024-11-08 16:20:46 +01:00
tcp_fastopen.c
UPSTREAM: bpf: tcp: Add bpf_skops_established()
2026-01-14 18:12:17 -08:00
tcp_highspeed.c
tcp_htcp.c
tcp_hybla.c
tcp_illinois.c
tcp_input.c
BACKPORT: tcp: bpf: Optionally store mac header in TCP_SAVE_SYN
2026-01-14 18:12:18 -08:00
tcp_ipv4.c
BACKPORT: bpf: tcp: Add bpf_skops_hdr_opt_len() and bpf_skops_write_hdr_opt()
2026-01-14 18:12:18 -08:00
tcp_lp.c
tcp_metrics.c
tcp_metrics: validate source addr length
2024-07-18 11:40:50 +02:00
tcp_minisocks.c
UPSTREAM: bpf: tcp: Allow bpf prog to write and parse TCP header option
2026-01-14 18:12:18 -08:00
tcp_nv.c
tcp_offload.c
net-timestamp: support TCP GSO case for a few missing flags
2025-03-13 12:43:30 +01:00
tcp_output.c
UPSTREAM: bpf: tcp: Allow bpf prog to write and parse TCP header option
2026-01-14 18:12:18 -08:00
tcp_rate.c
tcp_recovery.c
tcp: fix excessive TLP and RACK timeouts from HZ rounding
2023-10-25 11:53:21 +02:00
tcp_scalable.c
tcp_timer.c
Merge branch 'android11-5.4-lts' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
2024-08-05 21:50:23 +03:00
tcp_ulp.c
UPSTREAM: net, sk_msg: Annotate lockless access to sk_prot on clone
2025-12-23 13:36:03 -08:00
tcp_vegas.c
tcp_vegas.h
tcp_veno.c
tcp_westwood.c
tcp_yeah.c
tunnel4.c
udp.c
BACKPORT: inet: Extract helper for selecting socket from reuseport group
2026-01-14 18:13:17 -08:00
udp_diag.c
udp_impl.h
udp_offload.c
This is the 5.4.297 stable release
2025-09-02 10:52:40 +00:00
udp_tunnel_core.c
BACKPORT: udp_tunnel: add central NIC RX port offload infrastructure
2026-01-14 18:12:10 -08:00
udp_tunnel_nic.c
BACKPORT: udp_tunnel: add central NIC RX port offload infrastructure
2026-01-14 18:12:10 -08:00
udp_tunnel_stub.c
BACKPORT: udp_tunnel: add central NIC RX port offload infrastructure
2026-01-14 18:12:10 -08:00
udplite.c
xfrm4_input.c
xfrm: Preserve vlan tags for transport mode software GRO
2024-05-17 11:43:53 +02:00
xfrm4_output.c
xfrm4_policy.c
xfrm4_protocol.c
xfrm4_state.c
xfrm4_tunnel.c