Re: [PATCH net] net/netfilter: bpf: avoid leakage of skb

From: Florian Westphal
Date: Wed Nov 29 2023 - 09:47:45 EST


D. Wythe <alibuda@xxxxxxxxxxxxxxxxx> wrote:
> And my origin intention was to allow ebpf progs to return NF_STOLEN, we are
> trying to modify some netfilter modules via ebpf,
> and some scenarios require the use of NF_STOLEN, but from your description,

NF_STOLEN can only be supported via a trusted helper, as least as far as
I understand.

Otherwise verifier would have to guarantee that any branch that returns
NF_STOLEN has released the skb, or passed it to a function that will
release the skb in the near future.