Received: by 2002:a05:6a10:206:0:0:0:0 with SMTP id 6csp1495611pxj; Fri, 18 Jun 2021 08:21:28 -0700 (PDT) X-Google-Smtp-Source: ABdhPJzc/SE4XS0aAQ8toq/CyaVHl0lqEQobl2T1dpsESP+KxL1feNCc7HR7ZPuV3XtqOHmJVd5Z X-Received: by 2002:a02:914a:: with SMTP id b10mr3745817jag.59.1624029688092; Fri, 18 Jun 2021 08:21:28 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1624029688; cv=none; d=google.com; s=arc-20160816; b=ADN8TyDqd5UlEut1bZZzeQyDb71EJceVwBAjJCu13F1HUHb6LCTASbrB8oSQI/DfJt ko/nRd40meSafpcv9Ier7sui7Y8RbKV56GMJpMMoREqReKqG8ExeDX6nchhqrfk+ymuU r4fPgt6XrUIs5DpjE9r60RLLja25vTTCkQvV62ElMJhhBIbTQpYe68S0009BgrirejDi nHek54DekPGmnp44pe4LNH0LUC0ZhvaBs8MYnjqUztSi5gmeVUIQBFb0LNzsjcxX1d6G FvySaDsV4AN9jKhGQbGld1yu2i3qQKT4xzftl/Kl75EL8kZZw5eC7VGPlo4zYxVx86DX 7yrQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:cc:to:subject :message-id:date:from:in-reply-to:references:mime-version :dkim-signature; bh=fg1RaSfJDnm+oFtJenKoerkLiZFE4+FFve2MWRbIPq8=; b=CjKFnhzo8jsuDUSfeDcIdIxBNv6jwFX3RJVPcc4F7iUixdT6Q2uCPXNnRbotx7O/N3 iqTxP5BUKRS5Ypeg4pgY5oyCcG+wXyO/rpxIp991HhlI91lpKb8SvhIj+KqiSjGAzbRM Aw1se5ZwgObTiXYU1Vhx7hbbA0Vly4t5os5Rqjoee1OtTrLm1JJnVNxSy4RSJT6LtsGa vRjbWDUqiZMBP+CQrtwM4MwNQSoc4EhWMnRP9kI8sZ5kntw8HdD8AIKfLKQHJJtHjfN3 v8Xry5dshPUk7s1WO5t2DeBLIpKJz2g0B5R8B2axvpZsHutYAe3s3FZ8pz7133dpcqXh B9hg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@cloudflare.com header.s=google header.b=bGQXWrnH; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=cloudflare.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id i12si9824168jal.25.2021.06.18.08.21.14; Fri, 18 Jun 2021 08:21:28 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@cloudflare.com header.s=google header.b=bGQXWrnH; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=cloudflare.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S233917AbhFRL5i (ORCPT + 99 others); Fri, 18 Jun 2021 07:57:38 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:38698 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S231345AbhFRL5h (ORCPT ); Fri, 18 Jun 2021 07:57:37 -0400 Received: from mail-lf1-x134.google.com (mail-lf1-x134.google.com [IPv6:2a00:1450:4864:20::134]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id AB006C06175F for ; Fri, 18 Jun 2021 04:55:27 -0700 (PDT) Received: by mail-lf1-x134.google.com with SMTP id r5so16274052lfr.5 for ; Fri, 18 Jun 2021 04:55:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cloudflare.com; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc:content-transfer-encoding; bh=fg1RaSfJDnm+oFtJenKoerkLiZFE4+FFve2MWRbIPq8=; b=bGQXWrnHAw1dakSzFzG5w7YPvMRPK9n8R/oUJRdledAo8ktrfduPjgMISVi3LoBaeG +EueV/nflnH1P+4IwWVq9+ujSipihpmCmo0KDG21JEepFJEnobIaM6mx6BFrpSdlO41l jxhrvk8kcf+9SZMZ8H6gLUdi8XZxJnZXs8ajg= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc:content-transfer-encoding; bh=fg1RaSfJDnm+oFtJenKoerkLiZFE4+FFve2MWRbIPq8=; b=LaviOpsRfYtlbis5IygheFyUhUtvq688gzBpwVo1FtkbP4gRJ2MBxwYWODVIC3bscb B+IYbMPrk4U+jyejWVkNf7sAFvy7e+szUi9bSPiYOFUJp5oGTec5xUgDeVcQSRAB8OR6 4yHeVGBzOrwxeIjCTGptxOywbqFLUwULO13Yjbyr7JhItClVkKI8AfuiWSjUwqOSD+Zz Vrjigjj25sCXtjgjoTzzpX7hZ6Abc8qvxoKQWD/Qe6m6gdGxhNW5mu9hqxvKVfMSZF7u NkXYjdFUwDl/EZgzh1huUl9IJ9+In0s7kpwZIVm2F62zbjrxDmgfPDn0vaTjhjOcf1JO jHWQ== X-Gm-Message-State: AOAM531KMNKcZn49MxcyO7Mu5XAtJNznUC/6++vtwe6QDCfmgNnrtxhr SxrOABjY+/SRCRnLyBlovj25rLdbWyRjSZNFhg37/A== X-Received: by 2002:a05:6512:a84:: with SMTP id m4mr2849723lfu.451.1624017326050; Fri, 18 Jun 2021 04:55:26 -0700 (PDT) MIME-Version: 1.0 References: <20210618105526.265003-1-zenczykowski@gmail.com> In-Reply-To: <20210618105526.265003-1-zenczykowski@gmail.com> From: Lorenz Bauer Date: Fri, 18 Jun 2021 12:55:15 +0100 Message-ID: Subject: Re: [PATCH bpf] Revert "bpf: program: Refuse non-O_RDWR flags in BPF_OBJ_GET" To: =?UTF-8?Q?Maciej_=C5=BBenczykowski?= Cc: =?UTF-8?Q?Maciej_=C5=BBenczykowski?= , Alexei Starovoitov , Daniel Borkmann , Linux Network Development Mailing List , Linux Kernel Mailing List , BPF Mailing List , "David S . Miller" , Andrii Nakryiko , Greg Kroah-Hartman Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Fri, 18 Jun 2021 at 11:55, Maciej =C5=BBenczykowski wrote: > > This reverts commit d37300ed182131f1757895a62e556332857417e5. > > This breaks Android userspace which expects to be able to > fetch programs with just read permissions. Sorry about this! I'll defer to the maintainers what to do here. Reverting leaves us with a gaping hole for access control of pinned programs. --=20 Lorenz Bauer | Systems Engineer 6th Floor, County Hall/The Riverside Building, SE1 7PB, UK www.cloudflare.com