[PATCH mptcp-next v2 0/7] mptcp: add bpf_setsockopt support

Gang Yan posted 7 patches 4 days, 4 hours ago
Patches applied successfully (tree, apply log)
git fetch https://github.com/multipath-tcp/mptcp_net-next tags/patchew/cover.1784601268.git.yangang@kylinos.cn
include/net/mptcp.h                           |   9 ++
net/core/filter.c                             |  10 ++
net/ipv4/tcp.c                                |   1 +
net/mptcp/protocol.c                          |   6 +
net/mptcp/protocol.h                          |  29 ++++
net/mptcp/sockopt.c                           | 149 +++++++++---------
.../testing/selftests/bpf/prog_tests/mptcp.c  |  61 +++++++
.../selftests/bpf/progs/mptcp_setsockopt.c    |  32 ++++
8 files changed, 223 insertions(+), 74 deletions(-)
create mode 100644 tools/testing/selftests/bpf/progs/mptcp_setsockopt.c
[PATCH mptcp-next v2 0/7] mptcp: add bpf_setsockopt support
Posted by Gang Yan 4 days, 4 hours ago
From: Gang Yan <yangang@kylinos.cn>

Changelog:
v2:
  - Patches 1 and 2 are new in this series; they address TCP_MAXSEG
    handling in the bpf_setsockopt() path [1].
  - Patch 4 adds an early return to fix msk->sk_rcvlowat being
    unexpectedly modified, an issue seen in v1.
  - Patch 5 makes the hook safe for the non-tcp master socket: it guards
    bpf_sock_ops_cb_flags_set() with sk_is_tcp() to prevent out-of-bounds
    heap reads/writes through tcp_sk(sk)->bpf_sock_ops_cb_flags, and does
    not set is_locked_tcp_sock for the msk (unlike tcp_call_bpf()). That
    flag authorizes the verifier's direct tcp_sock-offset field accesses;
    since the msk is not a tcp_sock, leaving it at the default 0 is safe.

v1:
  Link: https://patchwork.kernel.org/project/mptcp/cover/20260713095735.1222033-1-gang.yan@linux.dev/

Gang Yan (7):
  mptcp: drop unused @max arg of __mptcp_setsockopt_set_val
  mptcp: take TCP_MAXSEG handling into __mptcp_setsockopt_set_val
  mptcp: use sockopt_lock/release_sock in sockopt
  mptcp: reject sockopt requiring ssks' lock in BPF context
  mptcp: enable bpf_setsockopt on the master socket
  mptcp: add TCP_CONNECT_CB sock_ops hook
  selftests: bpf: verify mptcp bpf_setsockopt from TCP_CONNECT_CB

 include/net/mptcp.h                           |   9 ++
 net/core/filter.c                             |  10 ++
 net/ipv4/tcp.c                                |   1 +
 net/mptcp/protocol.c                          |   6 +
 net/mptcp/protocol.h                          |  29 ++++
 net/mptcp/sockopt.c                           | 149 +++++++++---------
 .../testing/selftests/bpf/prog_tests/mptcp.c  |  61 +++++++
 .../selftests/bpf/progs/mptcp_setsockopt.c    |  32 ++++
 8 files changed, 223 insertions(+), 74 deletions(-)
 create mode 100644 tools/testing/selftests/bpf/progs/mptcp_setsockopt.c

-- 
2.43.0
Re: [PATCH mptcp-next v2 0/7] mptcp: add bpf_setsockopt support
Posted by MPTCP CI 4 days, 3 hours ago
Hi Gang,

Thank you for your modifications, that's great!

Our CI did some validations and here is its report:

- KVM Validation: normal (except selftest_mptcp_join): Success! ✅
- KVM Validation: normal (only selftest_mptcp_join): Success! ✅
- KVM Validation: debug (except selftest_mptcp_join): Success! ✅
- KVM Validation: debug (only selftest_mptcp_join): Success! ✅
- KVM Validation: btf-normal (only bpftest_all): Success! ✅
- KVM Validation: btf-debug (only bpftest_all): Success! ✅
- Task: https://github.com/multipath-tcp/mptcp_net-next/actions/runs/29797149050

Initiator: Patchew Applier
Commits: https://github.com/multipath-tcp/mptcp_net-next/commits/6e51b04fa682
Patchwork: https://patchwork.kernel.org/project/mptcp/list/?series=1131261


If there are some issues, you can reproduce them using the same environment as
the one used by the CI thanks to a docker image, e.g.:

    $ cd [kernel source code]
    $ docker run -v "${PWD}:${PWD}:rw" -w "${PWD}" --privileged --rm -it \
        --pull always mptcp/mptcp-upstream-virtme-docker:latest \
        auto-normal

For more details:

    https://github.com/multipath-tcp/mptcp-upstream-virtme-docker


Please note that despite all the efforts that have been already done to have a
stable tests suite when executed on a public CI like here, it is possible some
reported issues are not due to your modifications. Still, do not hesitate to
help us improve that ;-)

Cheers,
MPTCP GH Action bot
Bot operated by Matthieu Baerts (NGI0 Core)