Re: [PATCH bpf 2/2] bpf: reject any prog that failed read-only lock

2018-06-15 Thread Martin KaFai Lau
On Fri, Jun 15, 2018 at 02:30:48AM +0200, Daniel Borkmann wrote: > We currently lock any JITed image as read-only via bpf_jit_binary_lock_ro() > as well as the BPF image as read-only through bpf_prog_lock_ro(). In > the case any of these would fail we throw a WARN_ON_ONCE() in order to > yell loudl

[PATCH bpf 2/2] bpf: reject any prog that failed read-only lock

2018-06-14 Thread Daniel Borkmann
We currently lock any JITed image as read-only via bpf_jit_binary_lock_ro() as well as the BPF image as read-only through bpf_prog_lock_ro(). In the case any of these would fail we throw a WARN_ON_ONCE() in order to yell loudly to the log. Perhaps, to some extend, this may be comparable to an alloc