[Top] [All Lists]

[PATCH v6 0/9] seccomp: add thread sync ability

Subject: [PATCH v6 0/9] seccomp: add thread sync ability
From: Kees Cook <>
Date: Tue, 10 Jun 2014 16:01:45 -0700
Cc: Kees Cook <>, Andy Lutomirski <>, Oleg Nesterov <>, Will Drewry <>, Julien Tinnes <>, David Drysdale <>, Alexei Starovoitov <>, John Johansen <>, Russell King <>, Ralf Baechle <>, Thomas Gleixner <>, Ingo Molnar <>, "H. Peter Anvin" <>, Alexander Viro <>, Peter Zijlstra <>, Arnd Bergmann <>, James Morris <>, Andrew Morton <>, Frederic Weisbecker <>, "David A. Long" <>, Heiko Carstens <>, Kevin Hilman <>, Christoph Hellwig <>, Michal Simek <>, Juri Lelli <>, Miklos Szeredi <>, Dario Faggioli <>, Markos Chandras <>, James Hogan <>, Huacai Chen <>, Paul Burton <>, Viresh Kumar <>, "J. Bruce Fields" <>, Mike Frysinger <>, "David S. Miller" <>, Daniel Borkmann <>, Steven Rostedt <>, Rasmus Villemoes <>, Tom Zanussi <>, Andi Kleen <>, Mathieu Desnoyers <>, Rik van Riel <>, Daeseok Youn <>, David Rientjes <>, Eric Paris <>, Fabian Frederick <>, Robin Holt <>, Dongsheng Yang <>, liguang <>, Geert Uytterhoeven <>, Alex Thorlton <>, "Eric W. Biederman" <>, Josh Triplett <>,,,,,,,
List-archive: <>
List-help: <>
List-id: linux-mips <>
List-owner: <>
List-post: <>
List-software: Ecartis version 1.0.0
List-subscribe: <>
List-unsubscribe: <>
Original-recipient: rfc822;
This adds the ability for threads to request seccomp filter
synchronization across their thread group (at filter attach time).
For example, for Chrome to make sure graphic driver threads are fully
confined after seccomp filters have been attached.

To support this, locking on seccomp changes is introduced, along with
refactoring of no_new_privs. Races with thread creation/death are handled
via tasklist_lock.

This includes a new syscall (instead of adding a new prctl option),
as suggested by Andy Lutomirski and Michael Kerrisk.



 - switch from seccomp-specific lock to thread-group lock to gain atomicity
 - implement seccomp syscall across all architectures with seccomp filter
 - clean up sparse warnings around locking
 - move includes around (drysdale)
 - drop set_nnp return value (luto)
 - use smp_load_acquire/store_release (luto)
 - merge nnp changes to seccomp always, fewer ifdef (luto)
 - cleaned up locking further, as noticed by David Drysdale
 - added SECCOMP_EXT_ACT_FILTER for new filter install options
 - reworked to avoid clone races

<Prev in Thread] Current Thread [Next in Thread>