From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f171.google.com (mail-pf1-f171.google.com [209.85.210.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5966641BA9B for ; Fri, 24 Jul 2026 22:02:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.171 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784930551; cv=none; b=bkvKitMSI5d1mtOzGQkSngmSmzy5aM2SlbLprGUUEevNASH5ql0+ihC123IdhN/PlT7LRftmJqm8ZzPI3vd2Vnb6nwzy1FI9stNy0J2cNlH3D6B1gbcpGvb847lsxNaJ7UMG/hgX6EOhVK0FK4BdX63p44VV99rWCDWwakTgjIk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784930551; c=relaxed/simple; bh=b9+clYgP6mL9bW6u2CvbC18jZah0tWLSqjNjkcpfOTw=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=XR7VySLZL+/5aSk0B0KLgHLD/vrrhmqnJSMqy2NU3ogqLzV3Eud3bpj0lxCU+Aqwav0NrGOpdGiQmXRkhSZMZ5+HGc4QkEJgZIfK7HI9WBucLINVPLXNv/b1LMn17mst8U86EfommVnrae20NFuzRyWZs4wBrqg0Skn/lAASYTc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=qWsxaAVq; arc=none smtp.client-ip=209.85.210.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="qWsxaAVq" Received: by mail-pf1-f171.google.com with SMTP id d2e1a72fcca58-845c92bc464so778343b3a.2 for ; Fri, 24 Jul 2026 15:02:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784930550; x=1785535350; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=PAzNTf9Ao1Jd+i4HQ1y+PwV6f9J/K6SmB5ui1Xz+21c=; b=qWsxaAVqtl+bmvXjs9/deQojKDEOV5XRxWkm8kBVnH5Js2P+rHcrdeMlbQ5RzFNwgs 5o1PqiJN8nUxmk2DehWbagYR2ua7oPlsGXneAINu8yLKnfVwJ8Lb+SScSQlEwSU2TgY2 OzT4XrYBsei2Uy9C+sTtB/P8kQz58fIKD70XVCZKMqiwQ4dv0eL20rN8G6nCvPejPF3j rr7KsiSYnM49u+PSAoqehxp+dkOxse7K9i0BPIfvUFBEMJ8Tv7+aPKl6SanXQ818R7f9 42B38reVq9kyGuHgvQ3u3A7dzpqPQCxxZ1yYfG/GT3sw0jDtBYVTya8SXB1GnZ/qlkll VKkA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784930550; x=1785535350; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=PAzNTf9Ao1Jd+i4HQ1y+PwV6f9J/K6SmB5ui1Xz+21c=; b=rDdrXOgCSZFjwu1wcnnifUjaxMrQVJDHQZU4VK2QrLdSm6vdm6JsaMDPMqFjvmne8F NvlSp9eeSUaHkQNWTONlTkrEQ6KsQmZwoDdd/g0FCpBKx5Pype0cbXsrcpvismJn1VeA nYymn5RrHj0RlIRdltA33JhrTgo6eEIZyZTTtsF2CoqCiKR9rhkM7g/3M4hGKgEMklPJ 2ZdWOlWddAr4xbN+AWKoSn8OXuwPvkNUAZf9H3q42RvOdH1J8JlznMG3uhfFnWkpJvsS XjdH49KSMRd230so+cjY7wxEZ7pOFQgZRb4+Ksb/4QiPnxzddxCPO6G41kxjbMRS55dw mS1w== X-Forwarded-Encrypted: i=1; AHgh+RqOMn7baxOa0lXSxkuZvMwHikZp8T+nZGj2DYBkuPrR/6rpxgiR1QI/kkXcRcMWtthdS0LIZHXibOwjVY0=@vger.kernel.org X-Gm-Message-State: AOJu0Yy6Fr5TWzauEzRz4u/yWucEUHzrkexdSh2XW/0Vi0gMTkFijj1g jJx7S6RCNhfHLo+ufRrCgyTsRc+Ry7T2rATi71zmwji/aq3kMX3w6KCR X-Gm-Gg: AR+sD13M6Ic1P3Pgd6BLey2mDFvl1l5Ij5kNoE5bkUJQWK5kumKo9iYpmAzUsJgMZ4P drey60CHBAjbvtP+jEAYcLCFhDUXTHIr+IaXF/I5lIxQcqQaetBVwwAVU2Pksmc2EqZt+uMBwvj EkU1oeOaYEUaElGFQmEX+kqGwF8NMIodt+f7I00EGFQGfrRCAMNji4z7Ass07O+2vRQiLz4xCHZ DFtcNqX8/cTo+694SK5BcI/7yjC7NvC71sGLW0DB2knQPUbUMEek/KljsebzpRhbeYMlKJf8rGZ LZoE0qIMpSMhDVior9Lknc/1LEnIW7p7Lqmap/R7/TKcAIf/cyFMPGLoSzZccHyJ2TScwpdRFLL WjyOGNztYHuRMeKwyJPmd/DyyMU9xHterGtfHAshb9WT0mhI0x6EMzzmsA2yKTlm7mXbTX0i/V7 u1wbcdHVKF2JBt9TmvqY+Z+iV8scUtOqBMaLpqQtrPiI2lO5u7RnQ65JVFU9IN X-Received: by 2002:a05:6a21:495:b0:39f:59c8:f302 with SMTP id adf61e73a8af0-3c67df10d07mr125091637.37.1784930549615; Fri, 24 Jul 2026 15:02:29 -0700 (PDT) Received: from pop-os.tail4adac7.ts.net ([2601:647:6802:dbc0:546a:e1b0:9574:3a29]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-314bc5a67f3sm2962631eec.29.2026.07.24.15.02.27 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 24 Jul 2026 15:02:28 -0700 (PDT) From: Cong Wang To: Andy Lutomirski Cc: Kees Cook , linux-kernel@vger.kernel.org, Will Drewry , Christian Brauner , Andrew Morton , linux-mm@kvack.org, Cong Wang Subject: [PATCH v7 6/8] seccomp: re-validate a redirected syscall against outer filters Date: Fri, 24 Jul 2026 15:01:45 -0700 Message-ID: <20260724220147.214396-7-xiyou.wangcong@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260724220147.214396-1-xiyou.wangcong@gmail.com> References: <20260724220147.214396-1-xiyou.wangcong@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit From: Cong Wang Stacked filters compose by taking the most restrictive verdict over one evaluation of a single seccomp_data, assuming the syscall they voted on is the syscall that runs. SECCOMP_IOCTL_NOTIF_SEND_REDIRECT breaks that: the supervisor rewrites the argument registers and the syscall resumes without the stack being re-consulted, so an inner, container-installed filter can redirect a syscall into a form an outer filter would have blocked. Close the hole with seccomp_redirect_revalidate(): after a redirect it walks from the notifier outward, judging the substituted syscall one filter at a time; the innermost filter that does not allow it decides. ALLOW and LOG fall through; ERRNO, TRAP and KILL are terminal; USER_NOTIF consults the outer supervisor, whose plain FLAG_CONTINUE keeps the walk going; TRACE fails closed with -ENOSYS, since a tracer rewrite cannot be soundly re-composed mid-walk. The walk is strictly outward, so the notifier is never reconsulted and no re-notify loop exists, so a deep chain cannot exhaust the kernel stack. A redirect never changes the syscall number, only the argument registers differ. Assisted-by: Claude:claude-opus-4.8 Signed-off-by: Cong Wang --- kernel/seccomp.c | 141 ++++++++++++++++++++++++++++++++++++++++++----- 1 file changed, 126 insertions(+), 15 deletions(-) diff --git a/kernel/seccomp.c b/kernel/seccomp.c index f23dbee12ab7..2475aff55ec2 100644 --- a/kernel/seccomp.c +++ b/kernel/seccomp.c @@ -93,6 +93,13 @@ struct seccomp_knotif { long val; u32 flags; + /* + * Set by SEND_REDIRECT: the reply rewrote the syscall's registers, + * so on resume the syscall must be re-evaluated against the filters + * outer to the one that notified (see __seccomp_filter()). + */ + bool redirect; + /* * Signals when this has changed states, such as the listener * dying, a new seccomp addfd message, or changing to REPLIED @@ -1183,10 +1190,12 @@ static bool should_sleep_killable(struct seccomp_filter *match, static int seccomp_do_user_notification(int this_syscall, struct seccomp_filter *match, - const struct seccomp_data *sd) + const struct seccomp_data *sd, + bool *redirected) { int err; u32 flags = 0; + bool redirect = false; long ret = 0; struct seccomp_knotif n = {}; struct seccomp_kaddfd *addfd, *tmp; @@ -1243,6 +1252,7 @@ static int seccomp_do_user_notification(int this_syscall, ret = n.val; err = n.error; flags = n.flags; + redirect = n.redirect; interrupted: /* If there were any pending addfd calls, clear them out */ @@ -1269,19 +1279,120 @@ static int seccomp_do_user_notification(int this_syscall, mutex_unlock(&match->notify_lock); /* Userspace requests to continue the syscall. */ - if (flags & SECCOMP_USER_NOTIF_FLAG_CONTINUE) + if (flags & SECCOMP_USER_NOTIF_FLAG_CONTINUE) { + *redirected = redirect; return 0; + } syscall_set_return_value(current, current_pt_regs(), err, ret); return -1; } +static void seccomp_kill_task(int this_syscall, u32 action, int data) +{ + current->seccomp.mode = SECCOMP_MODE_DEAD; + seccomp_log(this_syscall, SIGSYS, action, true); + /* Dump core only if this is the last remaining thread. */ + if (action != SECCOMP_RET_KILL_THREAD || + (atomic_read(¤t->signal->live) == 1)) { + /* Show the original registers in the dump. */ + syscall_rollback(current, current_pt_regs()); + /* Trigger a coredump with SIGSYS */ + force_sig_seccomp(this_syscall, data, true); + } else { + do_exit(SIGSYS); + } +} + +static int seccomp_redirect_revalidate(struct seccomp_filter *notifier) +{ + struct seccomp_filter *f; + struct seccomp_data sd; + bool redirected = false; + int this_syscall; + u32 action; + int data; + + populate_seccomp_data(&sd); + this_syscall = sd.nr; + + for (f = notifier->prev; f; f = f->prev) { + u32 cur_ret = bpf_prog_run_pin_on_cpu(f->prog, &sd); + + data = cur_ret & SECCOMP_RET_DATA; + action = cur_ret & SECCOMP_RET_ACTION_FULL; + + switch (action) { + case SECCOMP_RET_ALLOW: + continue; + + case SECCOMP_RET_LOG: + seccomp_log(this_syscall, 0, action, true); + continue; + + case SECCOMP_RET_ERRNO: + /* Set low-order bits as an errno, capped at MAX_ERRNO. */ + if (data > MAX_ERRNO) + data = MAX_ERRNO; + syscall_set_return_value(current, current_pt_regs(), + -data, 0); + goto skip; + + case SECCOMP_RET_TRAP: + /* Show the handler the original registers. */ + syscall_rollback(current, current_pt_regs()); + /* Let the filter pass back 16 bits of data. */ + force_sig_seccomp(this_syscall, data, false); + goto skip; + + case SECCOMP_RET_USER_NOTIF: + /* + * The outer supervisor judges the substituted call: + * an error reply skips it, a plain FLAG_CONTINUE + * keeps the walk going, or this reply would slip the + * call past a stricter filter further out. It cannot + * redirect again: at most one redirect-capable + * listener exists in a chain, and the walk starts + * outside it. + */ + if (seccomp_do_user_notification(this_syscall, f, &sd, + &redirected)) + goto skip; + continue; + + case SECCOMP_RET_TRACE: + /* + * A tracer may rewrite the syscall, and there is no + * defensible way to restart composition mid-walk. + * Fail closed exactly like TRACE with no tracer + * attached: skip with -ENOSYS. + */ + syscall_set_return_value(current, current_pt_regs(), + -ENOSYS, 0); + goto skip; + + case SECCOMP_RET_KILL_THREAD: + case SECCOMP_RET_KILL_PROCESS: + default: + seccomp_kill_task(this_syscall, action, data); + return -1; + } + } + + return 0; + +skip: + seccomp_log(this_syscall, 0, action, f->log); + return -1; +} + static int __seccomp_filter(int this_syscall, const bool recheck_after_trace) { u32 filter_ret, action; struct seccomp_data sd; struct seccomp_filter *match = NULL; + bool redirected = false; int data; /* @@ -1356,9 +1467,19 @@ static int __seccomp_filter(int this_syscall, const bool recheck_after_trace) return 0; case SECCOMP_RET_USER_NOTIF: - if (seccomp_do_user_notification(this_syscall, match, &sd)) + if (seccomp_do_user_notification(this_syscall, match, &sd, + &redirected)) goto skip; + /* + * A redirect rewrote the argument registers; every filter + * outer to the notifier must judge the substituted syscall + * before it runs. A redirect from the outermost filter has + * no outer filter left to judge it. + */ + if (redirected && match->prev) + return seccomp_redirect_revalidate(match); + return 0; case SECCOMP_RET_LOG: @@ -1376,18 +1497,7 @@ static int __seccomp_filter(int this_syscall, const bool recheck_after_trace) case SECCOMP_RET_KILL_THREAD: case SECCOMP_RET_KILL_PROCESS: default: - current->seccomp.mode = SECCOMP_MODE_DEAD; - seccomp_log(this_syscall, SIGSYS, action, true); - /* Dump core only if this is the last remaining thread. */ - if (action != SECCOMP_RET_KILL_THREAD || - (atomic_read(¤t->signal->live) == 1)) { - /* Show the original registers in the dump. */ - syscall_rollback(current, current_pt_regs()); - /* Trigger a coredump with SIGSYS */ - force_sig_seccomp(this_syscall, data, true); - } else { - do_exit(SIGSYS); - } + seccomp_kill_task(this_syscall, action, data); return -1; /* skip the syscall go directly to signal handling */ } @@ -2223,6 +2333,7 @@ static long seccomp_notify_send_redirect(struct seccomp_filter *filter, goto out_unlock_free; } + knotif->redirect = true; knotif->state = SECCOMP_NOTIFY_REPLIED; knotif->error = 0; knotif->val = 0; -- 2.43.0