android_kernel_motorola_sm6375/kernel
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Christian Brauner bcce8defc3 UPSTREAM: seccomp: add SECCOMP_USER_NOTIF_FLAG_CONTINUE
This allows the seccomp notifier to continue a syscall. A positive
discussion about this feature was triggered by a post to the
ksummit-discuss mailing list (cf. [3]) and took place during KSummit
(cf. [1]) and again at the containers/checkpoint-restore
micro-conference at Linux Plumbers.

Recently we landed seccomp support for SECCOMP_RET_USER_NOTIF (cf. [4])
which enables a process (watchee) to retrieve an fd for its seccomp
filter. This fd can then be handed to another (usually more privileged)
process (watcher). The watcher will then be able to receive seccomp
messages about the syscalls having been performed by the watchee.

This feature is heavily used in some userspace workloads. For example,
it is currently used to intercept mknod() syscalls in user namespaces
aka in containers.
The mknod() syscall can be easily filtered based on dev_t. This allows
us to only intercept a very specific subset of mknod() syscalls.
Furthermore, mknod() is not possible in user namespaces toto coelo and
so intercepting and denying syscalls that are not in the whitelist on
accident is not a big deal. The watchee won't notice a difference.

In contrast to mknod(), a lot of other syscall we intercept (e.g.
setxattr()) cannot be easily filtered like mknod() because they have
pointer arguments. Additionally, some of them might actually succeed in
user namespaces (e.g. setxattr() for all "user.*" xattrs). Since we
currently cannot tell seccomp to continue from a user notifier we are
stuck with performing all of the syscalls in lieu of the container. This
is a huge security liability since it is extremely difficult to
correctly assume all of the necessary privileges of the calling task
such that the syscall can be successfully emulated without escaping
other additional security restrictions (think missing CAP_MKNOD for
mknod(), or MS_NODEV on a filesystem etc.). This can be solved by
telling seccomp to resume the syscall.

One thing that came up in the discussion was the problem that another
thread could change the memory after userspace has decided to let the
syscall continue which is a well known TOCTOU with seccomp which is
present in other ways already.
The discussion showed that this feature is already very useful for any
syscall without pointer arguments. For any accidentally intercepted
non-pointer syscall it is safe to continue.
For syscalls with pointer arguments there is a race but for any cautious
userspace and the main usec cases the race doesn't matter. The notifier
is intended to be used in a scenario where a more privileged watcher
supervises the syscalls of lesser privileged watchee to allow it to get
around kernel-enforced limitations by performing the syscall for it
whenever deemed save by the watcher. Hence, if a user tricks the watcher
into allowing a syscall they will either get a deny based on
kernel-enforced restrictions later or they will have changed the
arguments in such a way that they manage to perform a syscall with
arguments that they would've been allowed to do anyway.
In general, it is good to point out again, that the notifier fd was not
intended to allow userspace to implement a security policy but rather to
work around kernel security mechanisms in cases where the watcher knows
that a given action is safe to perform.

/* References */
[1]: https://linuxplumbersconf.org/event/4/contributions/560
[2]: https://linuxplumbersconf.org/event/4/contributions/477
[3]: https://lore.kernel.org/r/20190719093538.dhyopljyr5ns33qx@brauner.io
[4]: commit 6a21cc50f0 ("seccomp: add a return code to trap to userspace")

Co-developed-by: Kees Cook <keescook@chromium.org>
Signed-off-by: Christian Brauner <christian.brauner@ubuntu.com>
Reviewed-by: Tycho Andersen <tycho@tycho.ws>
Cc: Andy Lutomirski <luto@amacapital.net>
Cc: Will Drewry <wad@chromium.org>
CC: Tyler Hicks <tyhicks@canonical.com>
Link: https://lore.kernel.org/r/20190920083007.11475-2-christian.brauner@ubuntu.com
Signed-off-by: Kees Cook <keescook@chromium.org>
(cherry picked from commit fb3c5386b382d4097476ce9647260fc89b34afdb)
Signed-off-by: Jeff Vander Stoep <jeffv@google.com>
Bug: 176068146
Change-Id: Ifd5de971a0da6a507cb8ca1178381ca715693e07
2026-05-07 10:17:17 -04:00
..
bpf UPSTREAM: bpf, netns: Fix build without CONFIG_INET 2026-01-14 18:13:18 -08:00
cgroup UPSTREAM: cgroup: remove redundant kernfs_activate in cgroup_setup_root() 2026-01-14 18:13:14 -08:00
configs
debug BACKPORT: maccess: rename probe_kernel_{read,write} to copy_{from,to}_kernel_nofault 2026-01-14 18:13:21 -08:00
dma Merge tag 'ASB-2024-10-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina 2024-10-09 18:08:17 +00:00
events UPSTREAM: bpf: Fail PERF_EVENT_IOC_SET_BPF when bpf_get_[stack|stackid] cannot work 2026-01-14 18:12:08 -08:00
gcov gcov: add support for GCC 15 2025-12-03 12:45:19 +01:00
irq Merge branch 'android11-5.4-lts' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina 2025-10-08 15:23:13 +03:00
livepatch UPSTREAM: ftrace: Introduce PERMANENT ftrace_ops flag 2025-12-23 13:35:45 -08:00
locking Merge tag 'ASB-2025-06-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina 2025-06-30 10:49:17 +03:00
power Merge tag 'ASB-2025-10-06_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina 2025-10-08 15:17:54 +03:00
printk BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
rcu BACKPORT: rcu-tasks: Add a grace-period start time for throttling and debug 2026-01-14 18:13:22 -08:00
sched UPSTREAM: sched/core: Add function to sample state of locked-down task 2026-01-14 18:13:18 -08:00
time BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
trace UPSTREAM: bpf: Fix passing zero to PTR_ERR() in bpf_btf_printf_prepare 2026-02-01 20:44:47 -08:00
.gitignore
acct.c acct: perform last write from workqueue 2025-03-13 12:43:26 +01:00
async.c treewide: Remove uninitialized_var() usage 2023-06-09 10:29:01 +02:00
audit.c audit: Send netlink ACK before setting connection in auditd_set 2024-02-23 08:24:54 +01:00
audit.h
audit_fsnotify.c audit: fix potential double free on error path from fsnotify_add_inode_mark 2022-09-05 10:27:38 +02:00
audit_tree.c
audit_watch.c audit: don't WARN_ON_ONCE(!current->mm) in audit_exe_compare() 2023-11-28 16:50:18 +00:00
auditfilter.c
auditsc.c audit: fix possible soft lockup in __audit_inode_child() 2023-09-23 10:59:46 +02:00
backtracetest.c treewide: Replace DECLARE_TASKLET() with DECLARE_TASKLET_OLD() 2023-04-20 12:07:32 +02:00
bounds.c bounds: Use the right number of bits for power-of-two CONFIG_NR_CPUS 2024-05-02 16:18:37 +02:00
capability.c
cfi.c
compat.c sched_getaffinity: don't assume 'cpumask_size()' is fully initialized 2023-04-05 11:16:42 +02:00
configs.c
context_tracking.c
cpu.c hrtimers: Handle CPU state correctly on hotplug 2025-02-01 18:18:51 +01:00
cpu_pm.c
crash_core.c
crash_dump.c
cred.c Revert "cred: switch to using atomic_long_t" 2024-01-03 17:00:08 +00:00
delayacct.c
dma.c
exec_domain.c
exit.c BACKPORT: seccomp: release filter after task is fully dead 2026-05-07 10:17:17 -04:00
extable.c UPSTREAM: bpf: Remove bpf_image tree 2025-12-23 13:36:07 -08:00
fail_function.c kernel/fail_function: fix memory leak with using debugfs_lookup() 2023-03-11 16:44:15 +01:00
fork.c BACKPORT: seccomp: release filter after task is fully dead 2026-05-07 10:17:17 -04:00
freezer.c
futex.c Merge 5.4.246 into android11-5.4-lts 2023-06-20 19:13:58 +00:00
gen_kheaders.sh Merge tag 'ASB-2025-03-05_11-5.4' into android13-5.4-lahaina 2025-04-12 09:31:28 +00:00
groups.c BACKPORT: mm: remove the pgprot argument to __vmalloc 2026-01-14 17:48:09 -08:00
hung_task.c kernel/hung_task.c: make type annotations consistent 2026-02-01 20:38:49 -08:00
iomem.c
irq_work.c UPSTREAM: irq_work: Convert flags to atomic_t 2025-12-23 13:35:39 -08:00
jump_label.c
kallsyms.c
kcmp.c
Kconfig.freezer
Kconfig.hz
Kconfig.locks
Kconfig.preempt
kcov.c
kexec.c
kexec_core.c kexec: fix a memory leak in crash_shrink_memory() 2023-07-27 08:37:10 +02:00
kexec_elf.c kexec: initialize ELF lowest address to ULONG_MAX 2025-04-10 14:29:41 +02:00
kexec_file.c kexec: support purgatories with .text.hot sections 2023-06-21 15:44:10 +02:00
kexec_internal.h
kheaders.c kheaders: Use array declaration instead of char 2023-05-17 11:35:33 +02:00
kmod.c
kprobes.c BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
ksysfs.c
kthread.c BACKPORT: maccess: rename probe_kernel_{read,write} to copy_{from,to}_kernel_nofault 2026-01-14 18:13:21 -08:00
latencytop.c BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
Makefile UPSTREAM: bpf: Add kernel module with user mode driver that populates bpffs. 2026-01-14 18:12:16 -08:00
module-internal.h
module.c BACKPORT: mm: remove the pgprot argument to __vmalloc 2026-01-14 17:48:09 -08:00
module_signature.c
module_signing.c
notifier.c
nsproxy.c
padata.c padata: Reset next CPU when reorder sequence wraps around 2025-10-29 14:00:01 +01:00
panic.c panic: Flush kernel log buffer at the end 2024-04-13 12:51:37 +02:00
params.c module: ensure that kobject_put() is safe for module type kobjects 2025-06-04 14:32:27 +02:00
pid.c Merge tag 'ASB-2025-12-01_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina 2025-12-04 19:21:35 +02:00
pid_namespace.c BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
profile.c profiling: fix shift too large makes kernel panic 2022-08-25 11:18:02 +02:00
ptrace.c
range.c
reboot.c This is the 5.4.262 stable release 2023-11-29 10:18:14 +00:00
relay.c relayfs: fix out-of-bounds access in relay_file_read 2023-05-17 11:35:58 +02:00
resource.c resource: fix region_intersects() vs add_memory_driver_managed() 2024-11-08 16:20:46 +01:00
rseq.c
scs.c
seccomp.c UPSTREAM: seccomp: add SECCOMP_USER_NOTIF_FLAG_CONTINUE 2026-05-07 10:17:17 -04:00
signal.c Merge tag 'ASB-2024-12-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina 2024-12-17 03:24:53 +02:00
smp.c Merge tag 'ASB-2024-11-05_11-5.4' of https://android.googlesource.com/kernel/common into android13-5.4-lahaina 2024-11-08 15:36:32 +00:00
smpboot.c
smpboot.h
softirq.c Revert "tasklet: Introduce new initialization API" 2025-03-13 17:21:46 +00:00
stackleak.c stackleak: let stack_erasing_sysctl take a kernel pointer buffer 2026-02-01 20:38:37 -08:00
stacktrace.c
stop_machine.c
sys.c Merge 5.4.272 into android11-5.4-lts 2024-04-05 12:37:33 +00:00
sys_ni.c BACKPORT: epoll: wire up syscall epoll_pwait2 2025-12-22 07:42:50 +02:00
sysctl-test.c
sysctl.c bpf, sysctl: Let bpf_stats_handler take a kernel pointer buffer 2026-02-01 20:37:19 -08:00
sysctl_binary.c
task_work.c
taskstats.c
test_kprobes.c
torture.c
tracepoint.c UPSTREAM: module: Fix up module_notifier return values 2026-01-14 18:12:53 -08:00
tsacct.c
ucount.c
uid16.c
uid16.h
umh.c BACKPORT: umh: Separate the user mode driver and the user mode helper support 2026-01-14 18:12:14 -08:00
up.c
user-return-notifier.c
user.c
user_namespace.c
usermode_driver.c UPSTREAM: bpf: Fix umd memory leak in copy_process() 2026-01-14 18:12:50 -08:00
utsname.c
utsname_sysctl.c BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
watchdog.c BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
watchdog_hld.c watchdog/perf: properly initialize the turbo mode timestamp and rearm counter 2024-08-19 05:33:39 +02:00
workqueue.c BACKPORT: maccess: rename probe_kernel_{read,write} to copy_{from,to}_kernel_nofault 2026-01-14 18:13:21 -08:00
workqueue_internal.h