YiFei Zhu
c639e51eef
UPSTREAM: seccomp/cache: Add "emulator" to check if filter is constant allow
...
SECCOMP_CACHE will only operate on syscalls that do not access
any syscall arguments or instruction pointer. To facilitate
this we need a static analyser to know whether a filter will
return allow regardless of syscall arguments for a given
architecture number / syscall number pair. This is implemented
here with a pseudo-emulator, and stored in a per-filter bitmap.
In order to build this bitmap at filter attach time, each filter is
emulated for every syscall (under each possible architecture), and
checked for any accesses of struct seccomp_data that are not the "arch"
nor "nr" (syscall) members. If only "arch" and "nr" are examined, and
the program returns allow, then we can be sure that the filter must
return allow independent from syscall arguments.
Nearly all seccomp filters are built from these cBPF instructions:
BPF_LD | BPF_W | BPF_ABS
BPF_JMP | BPF_JEQ | BPF_K
BPF_JMP | BPF_JGE | BPF_K
BPF_JMP | BPF_JGT | BPF_K
BPF_JMP | BPF_JSET | BPF_K
BPF_JMP | BPF_JA
BPF_RET | BPF_K
BPF_ALU | BPF_AND | BPF_K
Each of these instructions are emulated. Any weirdness or loading
from a syscall argument will cause the emulator to bail.
The emulation is also halted if it reaches a return. In that case,
if it returns an SECCOMP_RET_ALLOW, the syscall is marked as good.
Emulator structure and comments are from Kees [1] and Jann [2].
Emulation is done at attach time. If a filter depends on more
filters, and if the dependee does not guarantee to allow the
syscall, then we skip the emulation of this syscall.
[1] https://lore.kernel.org/lkml/20200923232923.3142503-5-keescook@chromium.org/
[2] https://lore.kernel.org/lkml/CAG48ez1p=dR_2ikKq=xVxkoGg0fYpTBpkhJSv1w-6BG=76PAvw@mail.gmail.com/
Suggested-by: Jann Horn <jannh@google.com>
Signed-off-by: YiFei Zhu <yifeifz2@illinois.edu>
Reviewed-by: Jann Horn <jannh@google.com>
Co-developed-by: Kees Cook <keescook@chromium.org>
Signed-off-by: Kees Cook <keescook@chromium.org>
Link: https://lore.kernel.org/r/71c7be2db5ee08905f41c3be5c1ad6e2601ce88f.1602431034.git.yifeifz2@illinois.edu
(cherry picked from commit 8e01b51a31a1e08e2c3e8fcc0ef6790441be2f61)
Signed-off-by: Jeff Vander Stoep <jeffv@google.com>
Change-Id: I5047f7f0d6502e5de6c047743f1053fda3025a6e
Bug: 176068146
2026-05-07 10:17:17 -04:00
..
bpf
UPSTREAM: bpf, netns: Fix build without CONFIG_INET
2026-01-14 18:13:18 -08:00
cgroup
UPSTREAM: cgroup: remove redundant kernfs_activate in cgroup_setup_root()
2026-01-14 18:13:14 -08:00
configs
debug
BACKPORT: maccess: rename probe_kernel_{read,write} to copy_{from,to}_kernel_nofault
2026-01-14 18:13:21 -08:00
dma
Merge tag 'ASB-2024-10-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
2024-10-09 18:08:17 +00:00
events
UPSTREAM: bpf: Fail PERF_EVENT_IOC_SET_BPF when bpf_get_[stack|stackid] cannot work
2026-01-14 18:12:08 -08:00
gcov
gcov: add support for GCC 15
2025-12-03 12:45:19 +01:00
irq
Merge branch 'android11-5.4-lts' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
2025-10-08 15:23:13 +03:00
livepatch
UPSTREAM: ftrace: Introduce PERMANENT ftrace_ops flag
2025-12-23 13:35:45 -08:00
locking
Merge tag 'ASB-2025-06-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
2025-06-30 10:49:17 +03:00
power
Merge tag 'ASB-2025-10-06_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
2025-10-08 15:17:54 +03:00
printk
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
rcu
BACKPORT: rcu-tasks: Add a grace-period start time for throttling and debug
2026-01-14 18:13:22 -08:00
sched
UPSTREAM: sched/core: Add function to sample state of locked-down task
2026-01-14 18:13:18 -08:00
time
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
trace
UPSTREAM: bpf: Fix passing zero to PTR_ERR() in bpf_btf_printf_prepare
2026-02-01 20:44:47 -08:00
.gitignore
acct.c
acct: perform last write from workqueue
2025-03-13 12:43:26 +01:00
async.c
treewide: Remove uninitialized_var() usage
2023-06-09 10:29:01 +02:00
audit.c
audit: Send netlink ACK before setting connection in auditd_set
2024-02-23 08:24:54 +01:00
audit.h
audit_fsnotify.c
audit_tree.c
audit_watch.c
audit: don't WARN_ON_ONCE(!current->mm) in audit_exe_compare()
2023-11-28 16:50:18 +00:00
auditfilter.c
auditsc.c
audit: fix possible soft lockup in __audit_inode_child()
2023-09-23 10:59:46 +02:00
backtracetest.c
treewide: Replace DECLARE_TASKLET() with DECLARE_TASKLET_OLD()
2023-04-20 12:07:32 +02:00
bounds.c
bounds: Use the right number of bits for power-of-two CONFIG_NR_CPUS
2024-05-02 16:18:37 +02:00
capability.c
cfi.c
compat.c
sched_getaffinity: don't assume 'cpumask_size()' is fully initialized
2023-04-05 11:16:42 +02:00
configs.c
context_tracking.c
cpu.c
hrtimers: Handle CPU state correctly on hotplug
2025-02-01 18:18:51 +01:00
cpu_pm.c
crash_core.c
crash_dump.c
cred.c
Revert "cred: switch to using atomic_long_t"
2024-01-03 17:00:08 +00:00
delayacct.c
dma.c
exec_domain.c
exit.c
BACKPORT: seccomp: release filter after task is fully dead
2026-05-07 10:17:17 -04:00
extable.c
UPSTREAM: bpf: Remove bpf_image tree
2025-12-23 13:36:07 -08:00
fail_function.c
kernel/fail_function: fix memory leak with using debugfs_lookup()
2023-03-11 16:44:15 +01:00
fork.c
BACKPORT: seccomp: release filter after task is fully dead
2026-05-07 10:17:17 -04:00
freezer.c
futex.c
Merge 5.4.246 into android11-5.4-lts
2023-06-20 19:13:58 +00:00
gen_kheaders.sh
Merge tag 'ASB-2025-03-05_11-5.4' into android13-5.4-lahaina
2025-04-12 09:31:28 +00:00
groups.c
BACKPORT: mm: remove the pgprot argument to __vmalloc
2026-01-14 17:48:09 -08:00
hung_task.c
kernel/hung_task.c: make type annotations consistent
2026-02-01 20:38:49 -08:00
iomem.c
irq_work.c
UPSTREAM: irq_work: Convert flags to atomic_t
2025-12-23 13:35:39 -08:00
jump_label.c
kallsyms.c
kcmp.c
Kconfig.freezer
Kconfig.hz
Kconfig.locks
Kconfig.preempt
kcov.c
kexec.c
kexec_core.c
kexec: fix a memory leak in crash_shrink_memory()
2023-07-27 08:37:10 +02:00
kexec_elf.c
kexec: initialize ELF lowest address to ULONG_MAX
2025-04-10 14:29:41 +02:00
kexec_file.c
kexec: support purgatories with .text.hot sections
2023-06-21 15:44:10 +02:00
kexec_internal.h
kheaders.c
kheaders: Use array declaration instead of char
2023-05-17 11:35:33 +02:00
kmod.c
kprobes.c
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
ksysfs.c
kthread.c
BACKPORT: maccess: rename probe_kernel_{read,write} to copy_{from,to}_kernel_nofault
2026-01-14 18:13:21 -08:00
latencytop.c
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
Makefile
UPSTREAM: bpf: Add kernel module with user mode driver that populates bpffs.
2026-01-14 18:12:16 -08:00
module-internal.h
module.c
BACKPORT: mm: remove the pgprot argument to __vmalloc
2026-01-14 17:48:09 -08:00
module_signature.c
module_signing.c
notifier.c
nsproxy.c
padata.c
padata: Reset next CPU when reorder sequence wraps around
2025-10-29 14:00:01 +01:00
panic.c
panic: Flush kernel log buffer at the end
2024-04-13 12:51:37 +02:00
params.c
module: ensure that kobject_put() is safe for module type kobjects
2025-06-04 14:32:27 +02:00
pid.c
Merge tag 'ASB-2025-12-01_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
2025-12-04 19:21:35 +02:00
pid_namespace.c
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
profile.c
ptrace.c
range.c
reboot.c
This is the 5.4.262 stable release
2023-11-29 10:18:14 +00:00
relay.c
relayfs: fix out-of-bounds access in relay_file_read
2023-05-17 11:35:58 +02:00
resource.c
resource: fix region_intersects() vs add_memory_driver_managed()
2024-11-08 16:20:46 +01:00
rseq.c
scs.c
seccomp.c
UPSTREAM: seccomp/cache: Add "emulator" to check if filter is constant allow
2026-05-07 10:17:17 -04:00
signal.c
Merge tag 'ASB-2024-12-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
2024-12-17 03:24:53 +02:00
smp.c
Merge tag 'ASB-2024-11-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina
2024-11-08 15:36:32 +00:00
smpboot.c
smpboot.h
softirq.c
Revert "tasklet: Introduce new initialization API"
2025-03-13 17:21:46 +00:00
stackleak.c
stackleak: let stack_erasing_sysctl take a kernel pointer buffer
2026-02-01 20:38:37 -08:00
stacktrace.c
stop_machine.c
sys.c
Merge 5.4.272 into android11-5.4-lts
2024-04-05 12:37:33 +00:00
sys_ni.c
BACKPORT: epoll: wire up syscall epoll_pwait2
2025-12-22 07:42:50 +02:00
sysctl-test.c
sysctl.c
bpf, sysctl: Let bpf_stats_handler take a kernel pointer buffer
2026-02-01 20:37:19 -08:00
sysctl_binary.c
task_work.c
taskstats.c
test_kprobes.c
torture.c
tracepoint.c
UPSTREAM: module: Fix up module_notifier return values
2026-01-14 18:12:53 -08:00
tsacct.c
ucount.c
uid16.c
uid16.h
umh.c
BACKPORT: umh: Separate the user mode driver and the user mode helper support
2026-01-14 18:12:14 -08:00
up.c
user-return-notifier.c
user.c
user_namespace.c
usermode_driver.c
UPSTREAM: bpf: Fix umd memory leak in copy_process()
2026-01-14 18:12:50 -08:00
utsname.c
utsname_sysctl.c
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
watchdog.c
BACKPORT: sysctl: pass kernel pointers to ->proc_handler
2025-12-23 13:36:15 -08:00
watchdog_hld.c
watchdog/perf: properly initialize the turbo mode timestamp and rearm counter
2024-08-19 05:33:39 +02:00
workqueue.c
BACKPORT: maccess: rename probe_kernel_{read,write} to copy_{from,to}_kernel_nofault
2026-01-14 18:13:21 -08:00
workqueue_internal.h