Received: by 2002:ad5:474a:0:0:0:0:0 with SMTP id i10csp6481034imu; Sun, 2 Dec 2018 19:31:00 -0800 (PST) X-Google-Smtp-Source: AFSGD/UAUdGBY8s1Db+mgfEayUA/TQtYxOvGC1MEh/4H8Pq9mOAGxe7r0DRw8y3KuE600lIm4gKF X-Received: by 2002:a17:902:784d:: with SMTP id e13mr14619353pln.188.1543807860486; Sun, 02 Dec 2018 19:31:00 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1543807860; cv=none; d=google.com; s=arc-20160816; b=tOkkRTibN9N6dIgFkphKjE4Botq3P5g64zu0qhSGU2YPzSGfTd8k73rylC4LapgTRn Pm6fZ0OSLGXSrpJHboM12vr4kVHJjR3mixd5jIHAc99m3KAlcqa2kmjmouap63edt7NB RK+5fQAtpv4xytZ89K28o76pUd4TqRlZu3cnJbEaPtFa9C29XQ9DY3wE8tWsFZanaha9 XYR4eGTC35NlRwjG7h4XE9oo1ou9w4GT52z6V75Nsi9izhyh7/cHPfU7L5jmR9G7Z4XP M+I26mwlJ9Lf47zrFItrOBeZKcVCG6SiuyWGL4A0mHpRRfgZ5srwR9tGChQgPNxewWVH eU6Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:mime-version :message-id:date:subject:cc:to:from:dkim-signature; bh=7xooh3ENfgPFgNU5c1Z/paOWiAslSDCDRwGzwbnGZ/w=; b=Ad/sAZZIL/6OTEhdx2PDDzwP/I27sTbjs92zYWMFn0z/mIhTLrJ1tmiQVlJ/oVIUkU iFTFFmRYtL9RtKbVZaAQH27aMmGsJSFZWH1SrzPh0PXb1LFJc9LsKavCh24O4D/x6b2T A9Rz9vS5/e7MqRc+v6T4ocZcTBqJYHiPos2KvgO27qfmWomy7Rj8oGM9jeDDa3VE/4OU 0pDr+HE82TZxLqyuHHUVJks75QvaheIjSXO/p8ebGFx3glRg6wOFSYiYnP5WSATH/bfR +H+OlpevqT0rJPEg2dePYbkzvBxRe79v1I1+GoCG4rayl02fCfy7PMnwzwlCu6t8+XuB odiA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@tycho-ws.20150623.gappssmtp.com header.s=20150623 header.b=Pi5JsJCn; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id b63si13468284pfa.250.2018.12.02.19.30.46; Sun, 02 Dec 2018 19:31:00 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@tycho-ws.20150623.gappssmtp.com header.s=20150623 header.b=Pi5JsJCn; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1725913AbeLCD2p (ORCPT + 99 others); Sun, 2 Dec 2018 22:28:45 -0500 Received: from mail-it1-f193.google.com ([209.85.166.193]:36824 "EHLO mail-it1-f193.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1725811AbeLCD2p (ORCPT ); Sun, 2 Dec 2018 22:28:45 -0500 Received: by mail-it1-f193.google.com with SMTP id c9so6562334itj.1 for ; Sun, 02 Dec 2018 19:28:41 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=tycho-ws.20150623.gappssmtp.com; s=20150623; h=from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=7xooh3ENfgPFgNU5c1Z/paOWiAslSDCDRwGzwbnGZ/w=; b=Pi5JsJCn6oBLwQtcUsKn7bvqtUMKLq8B2984aScPxb4BrMEph1TBPzijUHBLQItVho UFLpkgYdpIIDYPbXjH2TcESV319d3Yztif5hfP1i9o+ubQlVih0HapM+BvI5bS70SUM0 af5jGnTdkczjIg84vlTo1E8Lt4bNUwxLdnHLJQGuoUovTpJ/DPtOqTo1jvWvYhfycz9H 1x7RNamWxJbodU1kkPUZ2fDNpLF8vK8BlSmHDQ6aKYlmFTr58bnTDxbqbQhYcsieHX5D n+qlOER3dmVDWDD31mySh2w3sSgtgVxmd70sN9SAmyLPo9ngE2GIQu0nzk5jKlogHTOJ z1lQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=7xooh3ENfgPFgNU5c1Z/paOWiAslSDCDRwGzwbnGZ/w=; b=T8AF53d3O3oV0covAgtW2W7iPL//AB5GBP9UEtUyy3VjEO22nl5uz8poMFkH2duS0X AVbWKjuS85coDYf6hQokQRm52YjuKSLlISbMj+qpyUxzTgIGYkp12n0B4bOggNHqmA4X iEL2chIKHyg5IoweeovQpptrUyyWWMLxvwnjUW6kU8kBjgN+mfEKZzfBKqwRRv4wpzxT k7dFx/TXQurl5o5/IUAGXQ5tbguXafMQarEzGhsbDMIiYp7N6s+7z8ZWYs8KJAIBaXsj dR7DmgJc0dmh7+BavXS9o56WLGYVKvsm8EJhfmnwgfC9vZhJSANW+/jhMM73Tp6bz5/j QLVA== X-Gm-Message-State: AA+aEWYYJa5ICPNg1BSEDRkH6astraQtlIpLklfy0JIhBAAKEss2hzeQ MMFJPrkge+i2OqzKojH23FtBEg== X-Received: by 2002:a05:660c:742:: with SMTP id a2mr5624226itl.121.1543807720992; Sun, 02 Dec 2018 19:28:40 -0800 (PST) Received: from cisco.lan (71-218-133-134.hlrn.qwest.net. [71.218.133.134]) by smtp.gmail.com with ESMTPSA id n136sm3243529itb.35.2018.12.02.19.28.39 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Sun, 02 Dec 2018 19:28:40 -0800 (PST) From: Tycho Andersen To: Kees Cook Cc: Andy Lutomirski , Oleg Nesterov , "Eric W . Biederman" , "Serge E . Hallyn" , Christian Brauner , Tyler Hicks , Akihiro Suda , Aleksa Sarai , Jann Horn , linux-kernel@vger.kernel.org, containers@lists.linux-foundation.org, linux-api@vger.kernel.org, Tycho Andersen Subject: [PATCH v9 0/4] seccomp trap to userspace Date: Sun, 2 Dec 2018 20:28:23 -0700 Message-Id: <20181203032827.27978-1-tycho@tycho.ws> X-Mailer: git-send-email 2.19.1 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Hi all, Here's a v9 of the seccomp trap to userspace series. Major changes are: * drop the whole SIGNALED flag thing. This was confusing to a number of people, and Oleg pointed out that it makes it fairly easy to get a task into an uninterruptible sleep. Now, replies to a task with a signal will just get ENOENT, indicating that something happened to the other end. * refactor the tests so that each test tests only one thing :) * several other minor bug fixes Cheers, Tycho Link to v8: https://lore.kernel.org/lkml/20181029224031.29809-1-tycho@tycho.ws/T/#u Tycho Andersen (4): seccomp: hoist struct seccomp_data recalculation higher seccomp: switch system call argument type to void * seccomp: add a return code to trap to userspace samples: add an example of seccomp user trap Documentation/ioctl/ioctl-number.txt | 1 + .../userspace-api/seccomp_filter.rst | 84 ++++ include/linux/seccomp.h | 9 +- include/uapi/linux/seccomp.h | 40 +- kernel/seccomp.c | 468 +++++++++++++++++- samples/seccomp/.gitignore | 1 + samples/seccomp/Makefile | 7 +- samples/seccomp/user-trap.c | 375 ++++++++++++++ tools/testing/selftests/seccomp/seccomp_bpf.c | 447 ++++++++++++++++- 9 files changed, 1410 insertions(+), 22 deletions(-) create mode 100644 samples/seccomp/user-trap.c -- 2.19.1