Skip to content

Account for PacketStart offsets in packet guards - #47

Merged
arthurfabre merged 1 commit into
masterfrom
afabre/packetoffsets
Jul 28, 2026
Merged

Account for PacketStart offsets in packet guards#47
arthurfabre merged 1 commit into
masterfrom
afabre/packetoffsets

Conversation

@arthurfabre

Copy link
Copy Markdown
Collaborator

The verifier rejects any programs that accesses packets with offsets greater than 0xFFFF.

For absolute loads we can detect this statically, for indirect loads we insert a runtime check.

But our checks didn't account for any pre-existing offset to the packet pointer the caller passes in! (eg because the caller has parsed / skipped the ethernet header).

This must be accounted for in the maximum offset check.

Add an option to both EBPFOpts and COpts to allow users to specify the maximum offset the packet pointer may have, so it can be included in the static analysis for absolute loads, and the runtime checks for indirect loads.

Thank you to @Dhiver for figuring this out in #45.

The verifier rejects any programs that accesses packets with offsets
greater than 0xFFFF.

For absolute loads we can detect this statically, for indirect loads we
insert a runtime check.

But our checks didn't account for any pre-existing offset to the packet
pointer the caller passes in! (eg because the caller has parsed /
skipped the ethernet header).

This must be accounted for in the maximum offset check.

Add an option to both EBPFOpts and COpts to allow users to specify the
maximum offset the packet pointer may have, so it can be included in the
static analysis for absolute loads, and the runtime checks for indirect
loads.

Thank you to @Dhiver for figuring this out in #45.
@arthurfabre
arthurfabre merged commit ca2cb56 into master Jul 28, 2026
10 checks passed
@arthurfabre
arthurfabre deleted the afabre/packetoffsets branch July 28, 2026 13:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants