mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH v2] seccomp: avoid the lock trip seccomp_filter_release in common case
@ 2025-02-13 17:09 Mateusz Guzik
  2025-02-24 19:18 ` Kees Cook
  0 siblings, 1 reply; 2+ messages in thread
From: Mateusz Guzik @ 2025-02-13 17:09 UTC (permalink / raw)
  To: kees, luto, wad; +Cc: linux-kernel, Mateusz Guzik

Vast majority of threads don't have any seccomp filters, all while the
lock taken here is shared between all threads in given process and
frequently used.

Safety of the check relies on the following:
- seccomp_filter_release is only legally called for PF_EXITING threads
- SIGNAL_GROUP_EXIT is only ever set with the sighand lock held
- PF_EXITING is only ever set with the sighand lock held *or* after
  SIGNAL_GROUP_EXIT is set *or* the process is single-threaded
- seccomp_sync_threads holds the sighand lock and skips all threads if
  SIGNAL_GROUP_EXIT is set, PF_EXITING threads if not

Resulting reduction of contention gives me a 5% boost in a
microbenchmark spawning and killing threads within the same process.

Signed-off-by: Mateusz Guzik <mjguzik@gmail.com>
---

So I slept on it and did an actual analysis instead of a lazy skim,
benchmarked as well. :)

 kernel/seccomp.c | 10 ++++++++++
 1 file changed, 10 insertions(+)

diff --git a/kernel/seccomp.c b/kernel/seccomp.c
index 0ce17c616150..41aa761c7738 100644
--- a/kernel/seccomp.c
+++ b/kernel/seccomp.c
@@ -574,6 +574,9 @@ void seccomp_filter_release(struct task_struct *tsk)
 	if (WARN_ON((tsk->flags & PF_EXITING) == 0))
 		return;
 
+	if (READ_ONCE(tsk->seccomp.filter) == NULL)
+		return;
+
 	spin_lock_irq(&tsk->sighand->siglock);
 	orig = tsk->seccomp.filter;
 	/* Detach task from its filter tree. */
@@ -599,6 +602,13 @@ static inline void seccomp_sync_threads(unsigned long flags)
 	BUG_ON(!mutex_is_locked(&current->signal->cred_guard_mutex));
 	assert_spin_locked(&current->sighand->siglock);
 
+	/*
+	 * Don't touch any of the threads if the process is being killed.
+	 * This allows for a lockless check in seccomp_filter_release.
+	 */
+	if (current->signal->flags & SIGNAL_GROUP_EXIT)
+		return;
+
 	/* Synchronize all threads. */
 	caller = current;
 	for_each_thread(caller, thread) {
-- 
2.43.0


^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH v2] seccomp: avoid the lock trip seccomp_filter_release in common case
  2025-02-13 17:09 [PATCH v2] seccomp: avoid the lock trip seccomp_filter_release in common case Mateusz Guzik
@ 2025-02-24 19:18 ` Kees Cook
  0 siblings, 0 replies; 2+ messages in thread
From: Kees Cook @ 2025-02-24 19:18 UTC (permalink / raw)
  To: luto, wad, Mateusz Guzik; +Cc: Kees Cook, linux-kernel

On Thu, 13 Feb 2025 18:09:10 +0100, Mateusz Guzik wrote:
> Vast majority of threads don't have any seccomp filters, all while the
> lock taken here is shared between all threads in given process and
> frequently used.
> 
> Safety of the check relies on the following:
> - seccomp_filter_release is only legally called for PF_EXITING threads
> - SIGNAL_GROUP_EXIT is only ever set with the sighand lock held
> - PF_EXITING is only ever set with the sighand lock held *or* after
>   SIGNAL_GROUP_EXIT is set *or* the process is single-threaded
> - seccomp_sync_threads holds the sighand lock and skips all threads if
>   SIGNAL_GROUP_EXIT is set, PF_EXITING threads if not
> 
> [...]

Applied to for-next/seccomp, thanks!

[1/1] seccomp: avoid the lock trip seccomp_filter_release in common case
      https://git.kernel.org/kees/c/8f19331384e6

Take care,

-- 
Kees Cook


^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2025-02-24 19:18 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-02-13 17:09 [PATCH v2] seccomp: avoid the lock trip seccomp_filter_release in common case Mateusz Guzik
2025-02-24 19:18 ` Kees Cook

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®