Received: by 2002:a05:6a11:4021:0:0:0:0 with SMTP id ky33csp369852pxb; Wed, 22 Sep 2021 04:13:20 -0700 (PDT) X-Google-Smtp-Source: ABdhPJxoJCvBnZzSE4cuDbFuLDx/evrivxJzOu/BNWfAR0IpNsHGEhjxUgam7uFlZUyK0hjSdYXH X-Received: by 2002:a05:6e02:1523:: with SMTP id i3mr21520553ilu.252.1632309200195; Wed, 22 Sep 2021 04:13:20 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1632309200; cv=none; d=google.com; s=arc-20160816; b=Fip3NtzUjtc2if6o97wg5HPfxExbsF6wmBcHijZFeo0u8s79LwisWfnSHhNfv8CSXd XLw+y5jrr8UbtixKf8BD4JIl7oKbcS87n8IvuYsBqD1j5JEJPhQDFrp03Z4gim2vxluO k4pmLtaX+ofHMPes6XEnhCxlC43BV9xgrluQrMDRazMNSK3mqr3oL/jGone86JZr4dkv 8a9XDHmW0NsdCLrG6tkVAXjhOUPsinzy8QvOQwC4d9A3vKgs8r5+XO0x19tmHxAaY6gy ScFXcpdUY3nDrc/cSvvM8rLfF4Tl80cZL9xpETAq8OShJ+aYaEVOcaTQCTtfhhTUewgf Arzw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :message-id:date:subject:cc:to:from:dkim-signature; bh=l4RZloahyjRG1N22DwCCx53LlP6k68dsBh8lyrVMOyo=; b=n5SyRLbFWlP67ttSjLICl9DBLdU7BarVEyalOULbe4uCQfFQfO4GPq17kbDAqGBA1t RKGH1mvpQbS2VZfJgrf7vZifuNpGXsHaOco6EELbCqD+nFXLIitc+2BbvmAk84WnY3du nUb7JmPXrgFUjv7fNaMVut3iOPgv/ErtiFHi0WsvsdRrMHEd8LyNIactY9qSaBf/ZVAO ybf/m6NeNmUE66ecPyrQ1UoPR1qYl3S3Vh/j9QLJjMxC5Wa0zUqeFE+Caj83LU+ZHPbx rH7F/ZTw3EkinD7mwBmwtEZiyh3dSWUtO3IQ0Ci1vNA9BO44y88l6BHiMoCP6XK3ekWx 8u7g== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@cloudflare.com header.s=google header.b=gbswmujy; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=cloudflare.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id s85si2559234ios.68.2021.09.22.04.13.06; Wed, 22 Sep 2021 04:13:20 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@cloudflare.com header.s=google header.b=gbswmujy; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=cloudflare.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S235460AbhIVLN1 (ORCPT + 99 others); Wed, 22 Sep 2021 07:13:27 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:38566 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S235424AbhIVLN1 (ORCPT ); Wed, 22 Sep 2021 07:13:27 -0400 Received: from mail-wr1-x42a.google.com (mail-wr1-x42a.google.com [IPv6:2a00:1450:4864:20::42a]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 45D73C061757 for ; Wed, 22 Sep 2021 04:11:57 -0700 (PDT) Received: by mail-wr1-x42a.google.com with SMTP id t18so5797481wrb.0 for ; Wed, 22 Sep 2021 04:11:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cloudflare.com; s=google; h=from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=l4RZloahyjRG1N22DwCCx53LlP6k68dsBh8lyrVMOyo=; b=gbswmujyBsd2CIJuI3gzzCLsbyFRnmyRBqDclILKZVritJh8jDMpBlnTOO0nocX0fp zovRbA0fyZmPgqOOQ0nsexInmOgyXqDrjcdUBsd2RXmZu7p3acio55fC35YScnlktUIm kHLMdb8Q4R0CA61qA3ED8wj5iB2eicH7aUeg0= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=l4RZloahyjRG1N22DwCCx53LlP6k68dsBh8lyrVMOyo=; b=ojRYI1see2z4/BcyKk/dB+SI9D//wY1kzHRBi9uqxhqAZDUEOyyRC9GpYYo5VWaJ3G 8L+cYbIvDlZ7dpXpm+Ka2sNuQfrmoNHDqh60JES6YdVifroZYLRT4ByPpQCTBZJB4mc7 IWYg5wjTCFinEe5X7ITSgzmEQQawOQBigW5fB5+Le3jhVP716x2yqx4HXhktNifvkXef Pz+7tLbFZoIp5cptdF0eV4Sj07wYMT+QAwhRkwgo7V5Xpehg0OSqYZAA6knqr9n5M4aS V4iJtrma0RCf8wPkgpQ8+fgf9TPvRRpgfDm/76QNVY1LSgn20tN90dy7duMsMU6RalAo 38DQ== X-Gm-Message-State: AOAM5307UUsIeZ+P92jFYu0Z4gv2LUlilbKJsQZyxBz0PZrC40wQqRpY 5gWWH/LQk4BWQZ2YX6qmfpz0eQ== X-Received: by 2002:a05:600c:3543:: with SMTP id i3mr9852341wmq.64.1632309115787; Wed, 22 Sep 2021 04:11:55 -0700 (PDT) Received: from antares.. (5.a.d.0.d.e.5.9.1.b.e.2.d.e.9.c.f.f.6.2.a.5.a.7.0.b.8.0.1.0.0.2.ip6.arpa. [2001:8b0:7a5a:26ff:c9ed:2eb1:95ed:da5]) by smtp.gmail.com with ESMTPSA id i9sm5966205wmi.44.2021.09.22.04.11.55 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 22 Sep 2021 04:11:55 -0700 (PDT) From: Lorenz Bauer To: Alexei Starovoitov , Daniel Borkmann Cc: kernel-team@cloudflare.com, Lorenz Bauer , netdev@vger.kernel.org, bpf@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH bpf] bpf: exempt CAP_BPF from checks against bpf_jit_limit Date: Wed, 22 Sep 2021 12:11:52 +0100 Message-Id: <20210922111153.19843-1-lmb@cloudflare.com> X-Mailer: git-send-email 2.30.2 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org When introducing CAP_BPF, bpf_jit_charge_modmem was not changed to treat programs with CAP_BPF as privileged for the purpose of JIT memory allocation. This means that a program without CAP_BPF can block a program with CAP_BPF from loading a program. Fix this by checking bpf_capable in bpf_jit_charge_modmem. Fixes: 2c78ee898d8f ("bpf: Implement CAP_BPF") Signed-off-by: Lorenz Bauer --- kernel/bpf/core.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/kernel/bpf/core.c b/kernel/bpf/core.c index 6fddc13fe67f..ea8a468dbded 100644 --- a/kernel/bpf/core.c +++ b/kernel/bpf/core.c @@ -827,7 +827,7 @@ int bpf_jit_charge_modmem(u32 pages) { if (atomic_long_add_return(pages, &bpf_jit_current) > (bpf_jit_limit >> PAGE_SHIFT)) { - if (!capable(CAP_SYS_ADMIN)) { + if (!bpf_capable()) { atomic_long_sub(pages, &bpf_jit_current); return -EPERM; } -- 2.30.2