Skip to content

Account for PacketStart offsets in packet guards - #47

Open
arthurfabre wants to merge 1 commit into
masterfrom
afabre/packetoffsets
Open

Account for PacketStart offsets in packet guards#47
arthurfabre wants to merge 1 commit into
masterfrom
afabre/packetoffsets

Conversation

@arthurfabre

Copy link
Copy Markdown
Collaborator

The verifier rejects any programs that accesses packets with offsets greater than 0xFFFF.

For absolute loads we can detect this statically, for indirect loads we insert a runtime check.

But our checks didn't account for any pre-existing offset to the packet pointer the caller passes in! (eg because the caller has parsed / skipped the ethernet header).

This must be accounted for in the maximum offset check.

Add an option to both EBPFOpts and COpts to allow users to specify the maximum offset the packet pointer may have, so it can be included in the static analysis for absolute loads, and the runtime checks for indirect loads.

Thank you to @Dhiver for figuring this out in #45.

The verifier rejects any programs that accesses packets with offsets
greater than 0xFFFF.

For absolute loads we can detect this statically, for indirect loads we
insert a runtime check.

But our checks didn't account for any pre-existing offset to the packet
pointer the caller passes in! (eg because the caller has parsed /
skipped the ethernet header).

This must be accounted for in the maximum offset check.

Add an option to both EBPFOpts and COpts to allow users to specify the
maximum offset the packet pointer may have, so it can be included in the
static analysis for absolute loads, and the runtime checks for indirect
loads.

Thank you to @Dhiver for figuring this out in #45.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant