From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pg1-f171.google.com (mail-pg1-f171.google.com [209.85.215.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 887DB3FA5E7 for ; Fri, 24 Jul 2026 22:02:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.171 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784930546; cv=none; b=WeYPdn0+mlRsfRcj3OysxF9rl+30a6D3I7tiZlXnYsiNjsh3LZedKwejzcBaAGobMnTdSFsoJIlhLwE8SfGxYCDEPq6BMvcrnEB2H1HoytlqLQlSZOp8rYDTNIZhTMfvGb20sNYmdXCx1SvWCg18yEb7olsXzlgAi6VCDpGKWi8= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784930546; c=relaxed/simple; bh=l8LrloIzOK32CMuzElY05harW0usRO0LsWxE3MqYBd0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=B/fH5Xaub8Atw1KcaHDo8INdHrR9wXDH/cT+xGG/q42o8uGjnnZXtKwJlsLhERZAZVcgVqn911rDBifIf2dq7H+DDCrnVNnvojdVR3u3nbEbQtLouwqGpoDLVHSW71RDo3kPa4vHJAogRYaJuAfGBA1HSkeKSfIPox9GfEoodBI= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=mctNviMZ; arc=none smtp.client-ip=209.85.215.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="mctNviMZ" Received: by mail-pg1-f171.google.com with SMTP id 41be03b00d2f7-ca7bea5e5b3so707483a12.1 for ; Fri, 24 Jul 2026 15:02:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784930544; x=1785535344; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=6q5nQLizQGV2XlL8vTWKU8w6FEVGfMIRL5kdTFKa2t4=; b=mctNviMZ/WDakgjh1+XmbvqO0bqbQlL5USYYyrrA7e9zkOshlESagjYAAOFY0+fjHY /gkaAjaPQlJHcZZuqOltAw8i9RcN+xTlD8/O8tJfkumLDemUEwK8Ggfl7kn/g3PWFozT RaEFDZK9clKLBoze0wvqHjy7FVhQhon4o1ojEILdNE0ZRylyH1nP//UqHLBKkEB5olaC OL7vNQFhXanoo2cZTP5VCv0mdEPxnqnZJG04Dc6DKIYX8wlZL6IUEwWU3pUDOeYEro67 zoR+39zRmlUTKanhM/1V0LUMJNRVLlrbY/h+SCdgj7pZFjuscu001Sl7Du/httvgOXhr +2VQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784930544; x=1785535344; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=6q5nQLizQGV2XlL8vTWKU8w6FEVGfMIRL5kdTFKa2t4=; b=bvfM8j+PGDxnmZ0jgqrDE48rJvyPJp4TcFbc6MITqE6Z8GxdwW3f1/Elrt9stk0PHN xTlllpKS60XHgvqGaO+5sz+Zso3FjCfRvQrx16/RxVZgQfLWjRjFXLuwmoHeWYjOI6wx uy0J+LrqGMwnHQYRjWYbMEoOqUsgfto5Kk2lrHvh3sUDCGnvMH0wdImKTnGC/DMC5xaw ERcnwJLIpwdPNn9O+/I2OfI0Pv6qM6lI0aJJpo1fuivT9LVOvRb3UC6cBrY+4xd6hD9h s2f69OiDZfm89Tw6EaIltrTfMDvnYaGIu1p4qNxsTPywjqpwELg3Y86u7bpOndCOa0sn V3wQ== X-Forwarded-Encrypted: i=1; AHgh+RrCOfA1KfrCsDxYfkYD4alN1h6eVRyEl4qXMNwr7TTFKHcSr94tltT3Sjpe9m0YNkebH/xO6NGCvfOLAok=@vger.kernel.org X-Gm-Message-State: AOJu0YxKxTFK6VrOmpKfKlR9lAljZGngkdwOVm5KrBuqGQgFUv8LCBK5 fMaEfIGxAHFNN66qt0FJisBGlZnzBbXytV4G35lJBMIr5Zo9BFuVzhNw X-Gm-Gg: AR+sD1271McuNmzxFcWPrqtWZedKQXfBRIFVri3NtVNzYCK2zDjEhKNVHDFPB6ARtbo OpZPxLiKTvNW+VZhzIQd+nDbw7TJweuQHByPnEESbON4JiVZljldbe5egIJAIr6odoYIujabraw Eej3cc+OgyUQkqv6x1SBNHBjNAAXrKqYk12XmG2HuUBvBVoTPMMOtjjN/rq/GCyWb2EA/D5fIsr /ak4zCtpBNP+7lwuVI3qSFhOAttobBg9vUzhuwK6aP10Yos1IZVbVmBjKGLCHV/LEPdvuZ+a/Wa nQRoEu2n4OGdOxMQ1fCuzXP0YxLg/2sbM6swaYJJD5HhAP+ia89Ht525kCRWu8QQhEXt/gBvgBd KjHbMefFOaXqkNPRvNHv+zFNnzjOwBbQqT1qJ7yjhViXkGNZG6MUP+rWMPff6I6stxgSmn2DF5w sJiAbWLB3eWrBpkalvXef/jjr+f7ZTp3y7eAdc8GSw5pXWyQa0GrVfVpoD6hULzNtf3pwK1w8= X-Received: by 2002:a05:6a21:4a8c:b0:3c3:83e6:c6e2 with SMTP id adf61e73a8af0-3c67e0e101fmr109624637.50.1784930543994; Fri, 24 Jul 2026 15:02:23 -0700 (PDT) Received: from pop-os.tail4adac7.ts.net ([2601:647:6802:dbc0:546a:e1b0:9574:3a29]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-314bc5a67f3sm2962631eec.29.2026.07.24.15.02.21 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 24 Jul 2026 15:02:22 -0700 (PDT) From: Cong Wang To: Andy Lutomirski Cc: Kees Cook , linux-kernel@vger.kernel.org, Will Drewry , Christian Brauner , Andrew Morton , linux-mm@kvack.org, Cong Wang Subject: [PATCH v7 4/8] seccomp: add __NR_seccomp_* aliases for rt_sigreturn and clone/fork Date: Fri, 24 Jul 2026 15:01:43 -0700 Message-ID: <20260724220147.214396-5-xiyou.wangcong@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260724220147.214396-1-xiyou.wangcong@gmail.com> References: <20260724220147.214396-1-xiyou.wangcong@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit From: Cong Wang The existing __NR_seccomp_* aliases name only the strict-mode syscalls (read/write/exit/sigreturn). SEND_REDIRECT must also recognise rt_sigreturn and the clone/fork task-creation family, native and compat, so it can refuse to redirect them. Gate these behind a new SECCOMP_ARCH_REDIRECT opt-in, mirroring how SECCOMP_ARCH_NATIVE gates the bitmap cache: an arch declares it only once it supplies a complete, verified set of these numbers, and where it is undefined the feature is compiled out. This avoids a generic fallback silently handing an arch a wrong number that would drop a syscall from the deny list. x86_64 opts in and supplies the ia32 compat numbers. Assisted-by: Claude:claude-opus-4.8 Signed-off-by: Cong Wang --- arch/x86/include/asm/seccomp.h | 15 ++++++++++++++- include/asm-generic/seccomp.h | 30 ++++++++++++++++++++++++++++++ 2 files changed, 44 insertions(+), 1 deletion(-) diff --git a/arch/x86/include/asm/seccomp.h b/arch/x86/include/asm/seccomp.h index 42bcd42d70d1..a911fce504ac 100644 --- a/arch/x86/include/asm/seccomp.h +++ b/arch/x86/include/asm/seccomp.h @@ -6,6 +6,7 @@ #ifdef CONFIG_X86_32 #define __NR_seccomp_sigreturn __NR_sigreturn +#define __NR_seccomp_rt_sigreturn __NR_rt_sigreturn #endif #ifdef CONFIG_COMPAT @@ -14,12 +15,18 @@ #define __NR_seccomp_write_32 __NR_ia32_write #define __NR_seccomp_exit_32 __NR_ia32_exit #define __NR_seccomp_sigreturn_32 __NR_ia32_sigreturn +#define __NR_seccomp_rt_sigreturn_32 __NR_ia32_rt_sigreturn +#define __NR_seccomp_clone_32 __NR_ia32_clone +#define __NR_seccomp_clone3_32 __NR_ia32_clone3 +#define __NR_seccomp_fork_32 __NR_ia32_fork +#define __NR_seccomp_vfork_32 __NR_ia32_vfork #endif #ifdef CONFIG_X86_64 # define SECCOMP_ARCH_NATIVE AUDIT_ARCH_X86_64 # define SECCOMP_ARCH_NATIVE_NR NR_syscalls # define SECCOMP_ARCH_NATIVE_NAME "x86_64" +# define SECCOMP_ARCH_REDIRECT 1 # ifdef CONFIG_COMPAT # define SECCOMP_ARCH_COMPAT AUDIT_ARCH_I386 # define SECCOMP_ARCH_COMPAT_NR IA32_NR_syscalls @@ -28,8 +35,14 @@ /* * x32 will have __X32_SYSCALL_BIT set in syscall number. We don't support * caching them and they are treated as out of range syscalls, which will - * always pass through the BPF filter. + * always pass through the BPF filter. It shares AUDIT_ARCH_X86_64 with the + * native ABI, so refuse to redirect it: the generic denylist keys off plain + * syscall numbers and cannot name x32's sigreturn/clone. */ +static inline bool arch_seccomp_redirect_deny(const struct seccomp_data *sd) +{ + return sd->nr & __X32_SYSCALL_BIT; +} #else /* !CONFIG_X86_64 */ # define SECCOMP_ARCH_NATIVE AUDIT_ARCH_I386 # define SECCOMP_ARCH_NATIVE_NR NR_syscalls diff --git a/include/asm-generic/seccomp.h b/include/asm-generic/seccomp.h index 6b6f42bc58f9..42b1b9b79ddf 100644 --- a/include/asm-generic/seccomp.h +++ b/include/asm-generic/seccomp.h @@ -26,6 +26,36 @@ #define __NR_seccomp_sigreturn __NR_rt_sigreturn #endif +#ifdef SECCOMP_ARCH_REDIRECT +#ifndef __NR_seccomp_rt_sigreturn +#define __NR_seccomp_rt_sigreturn __NR_seccomp_sigreturn +#endif +#ifndef __NR_seccomp_clone +#define __NR_seccomp_clone __NR_clone +#endif +#ifndef __NR_seccomp_clone3 +#ifdef __NR_clone3 +#define __NR_seccomp_clone3 __NR_clone3 +#else +#define __NR_seccomp_clone3 (-1) +#endif +#endif +#ifndef __NR_seccomp_fork +#ifdef __NR_fork +#define __NR_seccomp_fork __NR_fork +#else +#define __NR_seccomp_fork (-1) +#endif +#endif +#ifndef __NR_seccomp_vfork +#ifdef __NR_vfork +#define __NR_seccomp_vfork __NR_vfork +#else +#define __NR_seccomp_vfork (-1) +#endif +#endif +#endif /* SECCOMP_ARCH_REDIRECT */ + #ifdef CONFIG_COMPAT #ifndef get_compat_mode1_syscalls static inline const int *get_compat_mode1_syscalls(void) -- 2.43.0