-
Notifications
You must be signed in to change notification settings - Fork 224
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[netebpfext] Add per-provider WFP handles to avoid improper use from parallel invocations #3866
base: main
Are you sure you want to change the base?
Conversation
@@ -539,6 +581,9 @@ _net_ebpf_ext_register_wfp_callout(_Inout_ net_ebpf_ext_wfp_callout_state_t* cal | |||
callout_register_state.flags = 0; | |||
|
|||
status = FwpsCalloutRegister(device_object, &callout_register_state, &callout_state->assigned_callout_id); | |||
if (WFP_ERROR(status, ALREADY_EXISTS)) { |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
nit: in what case can it already exist?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
reboot without driver being unloaded - such as kernel crash or power failure.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Come to think of it, since FWPM_*_FLAG_PERSISTENT
is not passed for any objects; none of these objects should remain after a reboot. You were likely hitting this during your intermediate testing. I think this check can be safely removed.
…ks with asserts, remove unneded helper function
Description
Issue:
Our KM stress tests revealed an issue in our netebpfext code. There is a single global WFP handle, but multiple threads could use this at the same time (such as two programs attaching in parallel), leading to errors in the WFP APIs.
Fix:
Closes #3607
Testing
Existing tests validate this functionality.
Documentation
None.
Installation
None.