Maciej Żenczykowski
aec8ee63c7
BACKPORT: bpf: Restore behaviour of CAP_SYS_ADMIN allowing the loading of networking bpf programs
...
This is a fix for a regression in commit 2c78ee898d8f ("bpf: Implement CAP_BPF").
Before the above commit it was possible to load network bpf programs
with just the CAP_SYS_ADMIN privilege.
The Android bpfloader happens to run in such a configuration (it has
SYS_ADMIN but not NET_ADMIN) and creates maps and loads bpf programs
for later use by Android's netd (which has NET_ADMIN but not SYS_ADMIN).
Fixes: 2c78ee898d8f ("bpf: Implement CAP_BPF")
Reported-by: John Stultz <john.stultz@linaro.org>
Change-Id: I14b6ebf1244d7fe5c8d2296f19bd71f2b638e4a7
Signed-off-by: Maciej Żenczykowski <maze@google.com>
Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Tested-by: John Stultz <john.stultz@linaro.org>
Link: https://lore.kernel.org/bpf/20200620212616.93894-1-zenczykowski@gmail.com
2026-01-14 17:50:46 -08:00
..
arraymap.c
UPSTREAM: bpf: Set map_btf_{name, id} for all map types
2026-01-14 17:50:46 -08:00
bpf_iter.c
UPSTREAM: bpf: Enable bpf_iter targets registering ctx argument types
2026-01-14 17:41:40 -08:00
bpf_lru_list.c
bpf_lru_list.h
UPSTREAM: bpf: Fix a typo "inacitve" -> "inactive"
2025-12-23 13:36:12 -08:00
bpf_lsm.c
UPSTREAM: bpf: Use tracing helpers for lsm programs
2026-01-14 17:48:07 -08:00
bpf_struct_ops.c
UPSTREAM: bpf: Set map_btf_{name, id} for all map types
2026-01-14 17:50:46 -08:00
bpf_struct_ops_types.h
btf.c
UPSTREAM: bpf: Support access to bpf map fields
2026-01-14 17:50:46 -08:00
cgroup.c
BACKPORT: bpf: cgroup: Allow multi-attach program to replace itself
2026-01-14 17:50:26 -08:00
core.c
BACKPORT: mm: remove the pgprot argument to __vmalloc
2026-01-14 17:48:09 -08:00
cpumap.c
UPSTREAM: bpf: Set map_btf_{name, id} for all map types
2026-01-14 17:50:46 -08:00
devmap.c
UPSTREAM: bpf: Set map_btf_{name, id} for all map types
2026-01-14 17:50:46 -08:00
disasm.c
disasm.h
dispatcher.c
UPSTREAM: bpf: Remove bpf_image tree
2025-12-23 13:36:07 -08:00
hashtab.c
UPSTREAM: bpf: Set map_btf_{name, id} for all map types
2026-01-14 17:50:46 -08:00
helpers.c
UPSTREAM: bpf: Implement BPF ring buffer and verifier support for it
2026-01-14 17:48:05 -08:00
inode.c
UPSTREAM: bpf: Create file bpf iterator
2025-12-23 13:36:19 -08:00
local_storage.c
UPSTREAM: bpf: Set map_btf_{name, id} for all map types
2026-01-14 17:50:46 -08:00
lpm_trie.c
UPSTREAM: bpf: Set map_btf_{name, id} for all map types
2026-01-14 17:50:46 -08:00
Makefile
BACKPORT: flow_dissector: Move out netns_bpf prog callbacks
2026-01-14 17:48:08 -08:00
map_in_map.c
BACKPORT: bpf: Implement CAP_BPF
2026-01-14 17:44:17 -08:00
map_in_map.h
map_iter.c
UPSTREAM: bpf: Enable bpf_iter targets registering ctx argument types
2026-01-14 17:41:40 -08:00
net_namespace.c
UPSTREAM: bpf: Add link-based BPF program attachment to network namespace
2026-01-14 17:48:09 -08:00
offload.c
percpu_freelist.c
percpu_freelist.h
queue_stack_maps.c
UPSTREAM: bpf: Set map_btf_{name, id} for all map types
2026-01-14 17:50:46 -08:00
reuseport_array.c
UPSTREAM: bpf: Set map_btf_{name, id} for all map types
2026-01-14 17:50:46 -08:00
ringbuf.c
UPSTREAM: bpf: Set map_btf_{name, id} for all map types
2026-01-14 17:50:46 -08:00
stackmap.c
UPSTREAM: bpf: Set map_btf_{name, id} for all map types
2026-01-14 17:50:46 -08:00
syscall.c
BACKPORT: bpf: Restore behaviour of CAP_SYS_ADMIN allowing the loading of networking bpf programs
2026-01-14 17:50:46 -08:00
sysfs_btf.c
task_iter.c
UPSTREAM: bpf: Fix bpf_iter's task iterator logic
2026-01-14 17:44:15 -08:00
tnum.c
BACKPORT: bpf: Verifier, do explicit ALU32 bounds tracking
2025-12-23 13:36:11 -08:00
trampoline.c
UPSTREAM: bpf: lsm: Implement attach, detach and execution
2025-12-23 13:36:10 -08:00
verifier.c
UPSTREAM: bpf: Set the number of exception entries properly for subprograms
2026-01-14 17:50:46 -08:00