TencentOS-kernel/kernel/bpf
Alexei Starovoitov aa5943127e bpf: Implement CAP_BPF
[upstream commit 2c78ee898d8f10ae6fb2fa23a3fbaec96b1b7366]

Implement permissions as stated in uapi/linux/capability.h
In order to do that the verifier allow_ptr_leaks flag is split
into four flags and they are set as:
  env->allow_ptr_leaks = bpf_allow_ptr_leaks();
  env->bypass_spec_v1 = bpf_bypass_spec_v1();
  env->bypass_spec_v4 = bpf_bypass_spec_v4();
  env->bpf_capable = bpf_capable();

The first three currently equivalent to perfmon_capable(), since leaking kernel
pointers and reading kernel memory via side channel attacks is roughly
equivalent to reading kernel memory with cap_perfmon.

'bpf_capable' enables bounded loops, precision tracking, bpf to bpf calls and
other verifier features. 'allow_ptr_leaks' enable ptr leaks, ptr conversions,
subtraction of pointers. 'bypass_spec_v1' disables speculative analysis in the
verifier, run time mitigations in bpf array, and enables indirect variable
access in bpf programs. 'bypass_spec_v4' disables emission of sanitation code
by the verifier.

That means that the networking BPF program loaded with CAP_BPF + CAP_NET_ADMIN
will have speculative checks done by the verifier and other spectre mitigation
applied. Such networking BPF program will not be able to leak kernel pointers
and will not be able to access arbitrary kernel memory.

Signed-off-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: Daniel Borkmann <daniel@iogearbox.net>
Link: https://lore.kernel.org/bpf/20200513230355.7858-3-alexei.starovoitov@gmail.com
2022-08-30 11:33:26 +08:00
..
Makefile bpf: Add task and task/file iterator targets 2022-08-30 11:33:25 +08:00
arraymap.c bpf: Implement CAP_BPF 2022-08-30 11:33:26 +08:00
bpf_iter.c bpf: Enable bpf_iter targets registering ctx argument types 2022-08-30 11:33:25 +08:00
bpf_lru_list.c bpf_lru_list: Read double-checked variable once without lock 2021-04-12 12:52:15 +08:00
bpf_lru_list.h Init Repo base on linux 5.4.32 long term, and add base tlinux kernel interfaces. 2021-03-16 11:01:34 +08:00
bpf_lsm.c bpf: lsm: Implement attach, detach and execution 2022-08-30 11:33:21 +08:00
bpf_struct_ops.c bpf: Implement CAP_BPF 2022-08-30 11:33:26 +08:00
bpf_struct_ops_types.h bpf: tcp: Support tcp_congestion_ops in bpf 2022-08-30 11:33:19 +08:00
btf.c bpf: Enable bpf_iter targets registering ctx argument types 2022-08-30 11:33:25 +08:00
cgroup.c bpf, cgroup: Return ENOLINK for auto-detached links on update 2022-08-30 11:33:23 +08:00
core.c bpf: Implement CAP_BPF 2022-08-30 11:33:26 +08:00
cpumap.c bpf: Implement CAP_BPF 2022-08-30 11:33:26 +08:00
devmap.c devmap: Use bpf_map_area_alloc() for allocating hash buckets 2021-03-16 16:30:57 +08:00
disasm.c bpf: Introduce BPF nospec instruction for mitigating Spectre v4 2022-08-30 11:33:16 +08:00
disasm.h Init Repo base on linux 5.4.32 long term, and add base tlinux kernel interfaces. 2021-03-16 11:01:34 +08:00
dispatcher.c bpf: Introduce BPF dispatcher 2022-08-30 11:33:19 +08:00
hashtab.c bpf: Implement CAP_BPF 2022-08-30 11:33:26 +08:00
helpers.c bpf: Fix helper bpf_map_peek_elem_proto pointing to wrong callback 2021-03-16 16:44:00 +08:00
inode.c bpf: Create file bpf iterator 2022-08-30 11:33:25 +08:00
local_storage.c Init Repo base on linux 5.4.32 long term, and add base tlinux kernel interfaces. 2021-03-16 11:01:34 +08:00
lpm_trie.c bpf: Implement CAP_BPF 2022-08-30 11:33:26 +08:00
map_in_map.c bpf: Implement CAP_BPF 2022-08-30 11:33:26 +08:00
map_in_map.h Init Repo base on linux 5.4.32 long term, and add base tlinux kernel interfaces. 2021-03-16 11:01:34 +08:00
map_iter.c bpf: Enable bpf_iter targets registering ctx argument types 2022-08-30 11:33:25 +08:00
net_namespace.c inet: Run SK_LOOKUP BPF program on socket lookup 2022-08-30 11:33:24 +08:00
offload.c Init Repo base on linux 5.4.32 long term, and add base tlinux kernel interfaces. 2021-03-16 11:01:34 +08:00
percpu_freelist.c Init Repo base on linux 5.4.32 long term, and add base tlinux kernel interfaces. 2021-03-16 11:01:34 +08:00
percpu_freelist.h Init Repo base on linux 5.4.32 long term, and add base tlinux kernel interfaces. 2021-03-16 11:01:34 +08:00
queue_stack_maps.c bpf: Implement CAP_BPF 2022-08-30 11:33:26 +08:00
reuseport_array.c bpf: Implement CAP_BPF 2022-08-30 11:33:26 +08:00
stackmap.c bpf: Implement CAP_BPF 2022-08-30 11:33:26 +08:00
syscall.c bpf: Implement CAP_BPF 2022-08-30 11:33:26 +08:00
sysfs_btf.c bpf: Fix sysfs export of empty BTF section 2021-03-16 16:37:55 +08:00
task_iter.c bpf: Enable bpf_iter targets registering ctx argument types 2022-08-30 11:33:25 +08:00
tnum.c Init Repo base on linux 5.4.32 long term, and add base tlinux kernel interfaces. 2021-03-16 11:01:34 +08:00
trampoline.c bpf: lsm: Implement attach, detach and execution 2022-08-30 11:33:21 +08:00
verifier.c bpf: Implement CAP_BPF 2022-08-30 11:33:26 +08:00
xskmap.c bpf: Implement map_gen_lookup() callback for XSKMAP 2022-08-30 11:33:17 +08:00