|
@@ -2619,6 +2619,24 @@ static const struct bpf_func_proto bpf_get_socket_cookie_proto = {
|
|
.arg1_type = ARG_PTR_TO_CTX,
|
|
.arg1_type = ARG_PTR_TO_CTX,
|
|
};
|
|
};
|
|
|
|
|
|
|
|
+BPF_CALL_1(bpf_get_socket_uid, struct sk_buff *, skb)
|
|
|
|
+{
|
|
|
|
+ struct sock *sk = sk_to_full_sk(skb->sk);
|
|
|
|
+ kuid_t kuid;
|
|
|
|
+
|
|
|
|
+ if (!sk || !sk_fullsock(sk))
|
|
|
|
+ return overflowuid;
|
|
|
|
+ kuid = sock_net_uid(sock_net(sk), sk);
|
|
|
|
+ return from_kuid_munged(sock_net(sk)->user_ns, kuid);
|
|
|
|
+}
|
|
|
|
+
|
|
|
|
+static const struct bpf_func_proto bpf_get_socket_uid_proto = {
|
|
|
|
+ .func = bpf_get_socket_uid,
|
|
|
|
+ .gpl_only = false,
|
|
|
|
+ .ret_type = RET_INTEGER,
|
|
|
|
+ .arg1_type = ARG_PTR_TO_CTX,
|
|
|
|
+};
|
|
|
|
+
|
|
static const struct bpf_func_proto *
|
|
static const struct bpf_func_proto *
|
|
bpf_base_func_proto(enum bpf_func_id func_id)
|
|
bpf_base_func_proto(enum bpf_func_id func_id)
|
|
{
|
|
{
|
|
@@ -2655,6 +2673,8 @@ sk_filter_func_proto(enum bpf_func_id func_id)
|
|
return &bpf_skb_load_bytes_proto;
|
|
return &bpf_skb_load_bytes_proto;
|
|
case BPF_FUNC_get_socket_cookie:
|
|
case BPF_FUNC_get_socket_cookie:
|
|
return &bpf_get_socket_cookie_proto;
|
|
return &bpf_get_socket_cookie_proto;
|
|
|
|
+ case BPF_FUNC_get_socket_uid:
|
|
|
|
+ return &bpf_get_socket_uid_proto;
|
|
default:
|
|
default:
|
|
return bpf_base_func_proto(func_id);
|
|
return bpf_base_func_proto(func_id);
|
|
}
|
|
}
|
|
@@ -2716,6 +2736,8 @@ tc_cls_act_func_proto(enum bpf_func_id func_id)
|
|
return &bpf_skb_under_cgroup_proto;
|
|
return &bpf_skb_under_cgroup_proto;
|
|
case BPF_FUNC_get_socket_cookie:
|
|
case BPF_FUNC_get_socket_cookie:
|
|
return &bpf_get_socket_cookie_proto;
|
|
return &bpf_get_socket_cookie_proto;
|
|
|
|
+ case BPF_FUNC_get_socket_uid:
|
|
|
|
+ return &bpf_get_socket_uid_proto;
|
|
default:
|
|
default:
|
|
return bpf_base_func_proto(func_id);
|
|
return bpf_base_func_proto(func_id);
|
|
}
|
|
}
|