From: Bobby Eshleman <bobbyeshleman@gmail.com>
To: Kaifeng Wang <kaifengw@google.com>
Cc: netdev@vger.kernel.org, almasrymina@google.com,
edumazet@google.com, pabeni@redhat.com, willemb@google.com,
davem@davemloft.net, kuba@kernel.org, horms@kernel.org,
sdf@fomichev.me, bobbyeshleman@meta.com, kaiyuanz@google.com,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH net] net: devmem: check uid and netns in net_devmem_get_binding()
Date: Tue, 6 Oct 2026 09:19:49 -0700 [thread overview]
Message-ID: <asUfpfngzZGlpkaC@devvm29614.prn0.facebook.com> (raw)
In-Reply-To: <20261005210403.3206872-1-kaifengw@google.com>
On Mon, Oct 05, 2026 at 09:04:03PM +0000, Kaifeng Wang wrote:
> NETDEV_CMD_BIND_TX is unprivileged, and dmabuf binding IDs are allocated
> from a single global xarray. Currently net_devmem_get_binding() looks up
> the binding by ID without checking whether the sending socket belongs to
> the same user or network namespace that created the binding.
>
> Record the creating netlink socket's network namespace and UID on the
> binding, and verify both in net_devmem_get_binding() before checking the
> route destination device. Return -EINVAL on mismatch so callers cannot
> distinguish non-existent IDs from bindings owned by other users.
>
> Fixes: bd61848900bf ("net: devmem: Implement TX path")
> Signed-off-by: Kaifeng Wang <kaifengw@google.com>
> ---
> net/core/devmem.c | 7 ++++++-
> net/core/devmem.h | 5 +++++
> net/core/netdev-genl.c | 5 +++--
> 3 files changed, 14 insertions(+), 3 deletions(-)
>
> diff --git a/net/core/devmem.c b/net/core/devmem.c
> index f4d60654ce7f..9a773b1ce92d 100644
> --- a/net/core/devmem.c
> +++ b/net/core/devmem.c
> @@ -191,6 +191,7 @@ net_devmem_bind_dmabuf(struct net_device *dev, void *vdev,
> enum dma_data_direction direction,
> unsigned int dmabuf_fd, unsigned int niov_shift,
> struct netdev_nl_sock *priv,
> + const struct sock *nl_sk,
> struct netlink_ext_ack *extack)
> {
> struct net_devmem_dmabuf_binding *binding;
> @@ -220,6 +221,8 @@ net_devmem_bind_dmabuf(struct net_device *dev, void *vdev,
>
> binding->dev = dev;
> binding->vdev = vdev;
> + write_pnet(&binding->net, sock_net(nl_sk));
> + binding->uid = sk_uid(nl_sk);
> binding->niov_shift = niov_shift;
> xa_init_flags(&binding->bound_rxqs, XA_FLAGS_ALLOC);
>
> @@ -390,7 +393,9 @@ struct net_devmem_dmabuf_binding *net_devmem_get_binding(struct sock *sk,
> int err = 0;
>
> binding = net_devmem_lookup_dmabuf(dmabuf_id);
> - if (!binding || !binding->tx_vec) {
> + if (!binding || !binding->tx_vec ||
> + !net_eq(sock_net(sk), read_pnet(&binding->net)) ||
> + !uid_eq(sk_uid(sk), binding->uid)) {
> err = -EINVAL;
> goto out_err;
> }
> diff --git a/net/core/devmem.h b/net/core/devmem.h
> index 4a293a7d1149..7b9d3e04367c 100644
> --- a/net/core/devmem.h
> +++ b/net/core/devmem.h
> @@ -10,6 +10,7 @@
> #ifndef _NET_DEVMEM_H
> #define _NET_DEVMEM_H
>
> +#include <net/net_namespace.h>
> #include <net/netmem.h>
> #include <net/netdev_netlink.h>
>
> @@ -26,6 +27,8 @@ struct net_devmem_dmabuf_binding {
> * dereferenced.
> */
> void *vdev;
> + possible_net_t net;
> + kuid_t uid;
> struct gen_pool *chunk_pool;
> /* Protect dev */
> struct mutex lock;
> @@ -97,6 +100,7 @@ net_devmem_bind_dmabuf(struct net_device *dev, void *vdev,
> enum dma_data_direction direction,
> unsigned int dmabuf_fd, unsigned int niov_shift,
> struct netdev_nl_sock *priv,
> + const struct sock *nl_sk,
> struct netlink_ext_ack *extack);
> struct net_devmem_dmabuf_binding *net_devmem_lookup_dmabuf(u32 id);
> void net_devmem_unbind_dmabuf(struct net_devmem_dmabuf_binding *binding);
> @@ -181,6 +185,7 @@ net_devmem_bind_dmabuf(struct net_device *dev, void *vdev,
> unsigned int dmabuf_fd,
> unsigned int niov_shift,
> struct netdev_nl_sock *priv,
> + const struct sock *nl_sk,
> struct netlink_ext_ack *extack)
> {
> return ERR_PTR(-EOPNOTSUPP);
> diff --git a/net/core/netdev-genl.c b/net/core/netdev-genl.c
> index 33b9f4eb9565..847814e3df3f 100644
> --- a/net/core/netdev-genl.c
> +++ b/net/core/netdev-genl.c
> @@ -1094,7 +1094,7 @@ int netdev_nl_bind_rx_doit(struct sk_buff *skb, struct genl_info *info)
>
> binding = net_devmem_bind_dmabuf(netdev, NULL, dma_dev, DMA_FROM_DEVICE,
> dmabuf_fd, niov_shift, priv,
> - info->extack);
> + NETLINK_CB(skb).sk, info->extack);
> if (IS_ERR(binding)) {
> err = PTR_ERR(binding);
> goto err_rxq_bitmap;
> @@ -1243,7 +1243,8 @@ int netdev_nl_bind_tx_doit(struct sk_buff *skb, struct genl_info *info)
> binding = net_devmem_bind_dmabuf(bind_dev,
> bind_dev != netdev ? netdev : NULL,
> dma_dev, DMA_TO_DEVICE, dmabuf_fd,
> - PAGE_SHIFT, priv, info->extack);
> + PAGE_SHIFT, priv, NETLINK_CB(skb).sk,
> + info->extack);
> if (IS_ERR(binding)) {
> err = PTR_ERR(binding);
> goto err_unlock_bind_dev;
> --
> 2.56.0.rc1.315.gc6ed9934b7-goog
>
Reviewed-by: Bobby Eshleman <bobbyeshleman@meta.com>
prev parent reply other threads:[~2026-10-06 16:19 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-05 21:04 Kaifeng Wang
2026-10-05 21:09 ` netdev-bot+sinfo
2026-10-05 21:22 ` Kaifeng Wang
2026-10-05 22:24 ` Stanislav Fomichev
2026-10-06 16:19 ` Bobby Eshleman [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=asUfpfngzZGlpkaC@devvm29614.prn0.facebook.com \
--to=bobbyeshleman@gmail.com \
--cc=almasrymina@google.com \
--cc=bobbyeshleman@meta.com \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=kaifengw@google.com \
--cc=kaiyuanz@google.com \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=sdf@fomichev.me \
--cc=willemb@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®