[Top] [All Lists]

[PATCH v8 0/9] seccomp: add thread sync ability

Subject: [PATCH v8 0/9] seccomp: add thread sync ability
From: Kees Cook <>
Date: Tue, 24 Jun 2014 13:48:04 -0700
Cc: Kees Cook <>, Oleg Nesterov <>, Andy Lutomirski <>, "Michael Kerrisk (man-pages)" <>, Alexei Starovoitov <>, Andrew Morton <>, Daniel Borkmann <>, Will Drewry <>, Julien Tinnes <>, David Drysdale <>,,,,,,
List-archive: <>
List-help: <>
List-id: linux-mips <>
List-owner: <>
List-post: <>
List-software: Ecartis version 1.0.0
List-subscribe: <>
List-unsubscribe: <>
Original-recipient: rfc822;
This adds the ability for threads to request seccomp filter
synchronization across their thread group (at filter attach time).
For example, for Chrome to make sure graphic driver threads are fully
confined after seccomp filters have been attached.

To support this, locking on seccomp changes via thread-group-shared
sighand lock is introduced, along with refactoring of no_new_privs. Races
with thread creation are handled via delayed duplication of the seccomp
task struct field.

This includes a new syscall (instead of adding a new prctl option),
as suggested by Andy Lutomirski and Michael Kerrisk.



 - drop use of tasklist_lock, appears redundant against sighand (oleg)
 - reduced use of smp_load_acquire to logical minimum (oleg)
 - change nnp to a task struct held atomic flags field (oleg, luto)
 - drop needless irqflags changes in fork.c for holding sighand lock (oleg)
 - cleaned up use of thread for-each loop (oleg)
 - rearranged patch order to keep syscall changes adjacent
 - added example code to manpage (mtk)
 - rebase on Linus's tree (merged with network bpf changes)
 - wrote manpage text documenting API (follows this series)
 - switch from seccomp-specific lock to thread-group lock to gain atomicity
 - implement seccomp syscall across all architectures with seccomp filter
 - clean up sparse warnings around locking
 - move includes around (drysdale)
 - drop set_nnp return value (luto)
 - use smp_load_acquire/store_release (luto)
 - merge nnp changes to seccomp always, fewer ifdef (luto)
 - cleaned up locking further, as noticed by David Drysdale
 - added SECCOMP_EXT_ACT_FILTER for new filter install options
 - reworked to avoid clone races

<Prev in Thread] Current Thread [Next in Thread>