]> www.infradead.org Git - users/hch/misc.git/commit
bpf: BPF token support for BPF_BTF_GET_FD_BY_ID
authorMykyta Yatsenko <yatsenko@meta.com>
Mon, 17 Mar 2025 17:40:36 +0000 (17:40 +0000)
committerAndrii Nakryiko <andrii@kernel.org>
Mon, 17 Mar 2025 20:45:11 +0000 (13:45 -0700)
commit0de445d18e36ca5914337217c118016ba5db574d
treee4524bbe1683861784add30e3447b4a53c7f69fb
parent812f7702d83d84cdf776d75e2ba5386de9e8acc0
bpf: BPF token support for BPF_BTF_GET_FD_BY_ID

Currently BPF_BTF_GET_FD_BY_ID requires CAP_SYS_ADMIN, which does not
allow running it from user namespace. This creates a problem when
freplace program running from user namespace needs to query target
program BTF.
This patch relaxes capable check from CAP_SYS_ADMIN to CAP_BPF and adds
support for BPF token that can be passed in attributes to syscall.

Signed-off-by: Mykyta Yatsenko <yatsenko@meta.com>
Signed-off-by: Andrii Nakryiko <andrii@kernel.org>
Link: https://lore.kernel.org/bpf/20250317174039.161275-2-mykyta.yatsenko5@gmail.com
include/uapi/linux/bpf.h
kernel/bpf/syscall.c
tools/include/uapi/linux/bpf.h