From: Alexei Starovoitov Date: Mon, 15 Sep 2025 17:53:15 +0000 (-0700) Subject: Merge branch 'remove-use-of-current-cgns-in-bpf_cgroup_from_id' X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=61ee2cce3fe4a006c600069c726dc36d54256765;p=thirdparty%2Fkernel%2Fstable.git Merge branch 'remove-use-of-current-cgns-in-bpf_cgroup_from_id' Kumar Kartikeya Dwivedi says: ==================== Remove use of current->cgns in bpf_cgroup_from_id bpf_cgroup_from_id currently ends up doing a check on whether the cgroup being looked up is a descendant of the root cgroup of the current task's cgroup namespace. This leads to unreliable results since this kfunc can be invoked from any arbitrary context, for any arbitrary value of current. Fix this by removing namespace-awarness in the kfunc, and include a test that detects such a case and fails without the fix. Changelog: ---------- v2 -> v3 v2: https://lore.kernel.org/bpf/20250811195901.1651800-1-memxor@gmail.com * Refactor cgroup_get_from_id into non-ns version. (Andrii) * Address nits from Eduard. v1 -> v2 v1: https://lore.kernel.org/bpf/20250811175045.1055202-1-memxor@gmail.com * Add Ack from Tejun. * Fix selftest to perform namespace migration and cgroup setup in a child process to avoid changing test_progs namespace. ==================== Link: https://patch.msgid.link/20250915032618.1551762-1-memxor@gmail.com Signed-off-by: Alexei Starovoitov --- 61ee2cce3fe4a006c600069c726dc36d54256765