mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Andreas Larsson <andreas@gaisler.com>
To: Stian Halseth <stian@itx.no>,
	"David S . Miller" <davem@davemloft.net>,
	Kees Cook <kees@kernel.org>,
	sparclinux@vger.kernel.org
Cc: Andy Lutomirski <luto@amacapital.net>,
	Will Drewry <wad@chromium.org>, Oleg Nesterov <oleg@redhat.com>,
	Shuah Khan <shuah@kernel.org>,
	linux-kselftest@vger.kernel.org, linux-kernel@vger.kernel.org,
	John Paul Adrian Glaubitz <glaubitz@physik.fu-berlin.de>
Subject: Re: [PATCH v2 0/2] sparc64: add seccomp filter support
Date: Wed, 7 Oct 2026 08:14:02 +0200	[thread overview]
Message-ID: <f32e114c-718f-46d7-9388-fdc5c382ddaa@gaisler.com> (raw)
In-Reply-To: <20260902072745.3412940-1-stian@itx.no>

On 2026-09-02 09:27, Stian Halseth wrote:
> This adds SECCOMP_FILTER support for sparc64.
> 
> The arch prerequisites have been in place for years, so patch 1 is
> mostly about the missing piece: letting seccomp veto a syscall, and
> returning to user space with the return value the seccomp core set in
> pt_regs rather than the -ENOSYS the assembler stubs used to force on
> any denied syscall.  Patch 2 teaches the seccomp_bpf selftest to
> drive sparc64's registers.
> 
> Tested on an UltraSPARC T4-1 (sun4v):
> 
>   - tools/testing/selftests/seccomp/seccomp_bpf: 95 passed, 0 failed,
>     16 skipped (uprobes and other optional features)
>   - libseccomp with its pending SPARC support (libseccomp PR #471)
>     passes its full suite, 5190 of 5190, including the live tests
>     that require kernel SECCOMP_FILTER
>   - docker containers run confined by the default profile, and a
>     custom SCMP_ACT_ERRNO profile denies as expected
> 
> The libseccomp side is https://github.com/seccomp/libseccomp/pull/471,
> and the tracking issue is https://github.com/sparclinux/issues/issues/11.
> 
> v2: drop the local regs-struct definition in the selftest in favour of
>     PTRACE_GETREGS64/PTRACE_SETREGS64 and the uapi struct pt_regs
>     (Kees Cook); patch 1 unchanged.
> 
> Stian Halseth (2):
>   sparc64: add seccomp filter support
>   selftests/seccomp: add sparc64 support
> 
>  arch/sparc/Kconfig                            |  2 +-
>  arch/sparc/include/asm/seccomp.h              | 15 ++++++++
>  arch/sparc/include/asm/syscall.h              | 11 +++---
>  arch/sparc/kernel/entry.h                     |  2 +-
>  arch/sparc/kernel/ptrace_64.c                 | 28 ++++++++++-----
>  arch/sparc/kernel/syscalls.S                  | 28 +++++++++++----
>  tools/testing/selftests/seccomp/seccomp_bpf.c | 36 ++++++++++++++++++++
>  7 files changed, 99 insertions(+), 23 deletions(-)
> 

Looks good to me, and selftests runs fine for me as well. Thanks! We have a soon
incoming patch set adding support for sparc32 as well on top of this.

Kees, are you ok with the selftest changes being taken through my tree?

Cheers,
Andreas


  parent reply	other threads:[~2026-10-07  6:14 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-02  7:27 Stian Halseth
2026-09-02  7:27 ` [PATCH v2 1/2] " Stian Halseth
2026-09-02  7:27 ` [PATCH v2 2/2] selftests/seccomp: add sparc64 support Stian Halseth
2026-10-09  7:35   ` Kees Cook
2026-10-07  6:14 ` Andreas Larsson [this message]
2026-10-09  6:55   ` [PATCH v2 0/2] sparc64: add seccomp filter support John Paul Adrian Glaubitz
2026-10-09 14:32 ` Andreas Larsson

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=f32e114c-718f-46d7-9388-fdc5c382ddaa@gaisler.com \
    --to=andreas@gaisler.com \
    --cc=davem@davemloft.net \
    --cc=glaubitz@physik.fu-berlin.de \
    --cc=kees@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-kselftest@vger.kernel.org \
    --cc=luto@amacapital.net \
    --cc=oleg@redhat.com \
    --cc=shuah@kernel.org \
    --cc=sparclinux@vger.kernel.org \
    --cc=stian@itx.no \
    --cc=wad@chromium.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®