From nobody Sat Jul 25 23:06:00 2026 Received: from galois.linutronix.de (Galois.linutronix.de [193.142.43.55]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id EF7383ACA77; Sun, 12 Jul 2026 12:44:07 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=193.142.43.55 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783860255; cv=none; b=dUa/CPxEqN2q6kBkXzTYp2K6Ue9OFnnSG+N2FLQGchE9JS07B7JnTFpltvjjp1DR7f7jVxRn8M/jn42Vx+wMVVTPjHCuDwFkaQtL9jE470F6eaWxDVJJmRGrhJH1i+bwhVn+W0qpi0lqcuIxKhN1y1bXtLxQsH9kCm2+wIYK3TA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783860255; c=relaxed/simple; bh=f40/+KUPWAE2i1x2IpkaqFsPZ6qlEPsDvhvXQrNvLr8=; h=Date:From:To:Subject:Cc:In-Reply-To:References:MIME-Version: Message-ID:Content-Type; b=Deh50Pw5TrECr+NOT7ZsLkmge424fjsT9nOkdyd2SgRH6fZ1sgOB7ozvcjsMdKbXFld6YRTGyLHXm4KH/u9Tz+/IuMW4RLAJg5yyQf5uV5L8s1TKaqH0/RwJC0XhUIyo1Hr1+4X0ofxAg/TN284nxPYIAnjVEEN/11TlOLhifSE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linutronix.de; spf=pass smtp.mailfrom=linutronix.de; dkim=pass (2048-bit key) header.d=linutronix.de header.i=@linutronix.de header.b=u3esTWTh; dkim=permerror (0-bit key) header.d=linutronix.de header.i=@linutronix.de header.b=Q0i+hlkt; arc=none smtp.client-ip=193.142.43.55 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linutronix.de Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linutronix.de Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=linutronix.de header.i=@linutronix.de header.b="u3esTWTh"; dkim=permerror (0-bit key) header.d=linutronix.de header.i=@linutronix.de header.b="Q0i+hlkt" Date: Sun, 12 Jul 2026 12:43:59 -0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020; t=1783860241; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=UXgjXefUmo/MM8mP6i/AQuy2P/thMsJ08w38jUZsNtg=; b=u3esTWTh15UZAgVaIZh35IYHNiLN9VFyw8x/HS/yzwfyWcSHV3MZ3pn7fOSxuTPpmba3K+ Ls8vauU57f2KpcONK8Kjk0L6EEdd3VxLFyNyRaEFrZI8BcI7WruULcdTpp5hcOr4kVy3Mw VOvjQBfXCa8yYg27oLnu7k2kzWdzD8ypoYRKpEpKdjG37JNnIRbGv0d06MuMtK5P9ruUYq ob/8riAZxsbrGOhWRrJOkCN2IxWidBKetz9YZkCpwkQi8bFRY56euW3HCypbJMOiJwrdil tcfqz4FWKotKzZ3Orsr4BloFkBwYalGk1QDF4HabM/U1NurnAtvGtqO2k7l89g== DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/relaxed; d=linutronix.de; s=2020e; t=1783860241; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=UXgjXefUmo/MM8mP6i/AQuy2P/thMsJ08w38jUZsNtg=; b=Q0i+hlktbiWdocDpYtZzIgJ5nKaFUMWnH+bcjRUaswTkyakf5oAkH4DHnxqfHeazsiuwsU X/PD7Tfkv0yKRGDQ== From: "tip-bot2 for Jinjie Ruan" Sender: tip-bot2@linutronix.de Reply-to: linux-kernel@vger.kernel.org To: linux-tip-commits@vger.kernel.org Subject: [tip: core/entry] seccomp, treewide: Rename and convert __secure_computing() to return boolean Cc: Thomas Gleixner , Mark Rutland , Jinjie Ruan , "Mukesh Kumar Chaurasiya (IBM)" , Oleg Nesterov , x86@kernel.org, linux-kernel@vger.kernel.org In-Reply-To: <20260707190254.230735780@kernel.org> References: <20260707190254.230735780@kernel.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Message-ID: <178386023936.1844600.17572383270485035851.tip-bot2@tip-bot2> Robot-ID: Robot-Unsubscribe: Contact to get blacklisted from these emails Precedence: bulk Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable The following commit has been merged into the core/entry branch of tip: Commit-ID: 7ba2ba74713c83408cc942b60dd869ab2c34c84f Gitweb: https://git.kernel.org/tip/7ba2ba74713c83408cc942b60dd869ab2= c34c84f Author: Jinjie Ruan AuthorDate: Tue, 07 Jul 2026 21:06:40 +02:00 Committer: Thomas Gleixner CommitterDate: Sun, 12 Jul 2026 12:38:02 +02:00 seccomp, treewide: Rename and convert __secure_computing() to return boolean The return value of __secure_computing() currently uses 0 to indicate that a system call should be allowed, and -1 to indicate that it should be blocked/killed. This 0/-1 pattern is non-intuitive for a security check function and makes the control flow at the call sites less readable. Furthermore, any potential future changes to these return values would require a high-risk, error-prone audit of all its users across different architectures. Sanitize this logic by converting the return type of __secure_computing() to a proper boolean, where 'true' explicitly means 'allow' and 'false' means 'fail/deny'. Update all the two dozen or so call sites across the tree to align with this new boolean semantic. No functional changes are intended, as the callers still return -1 to the lower-level assembly entry code upon seccomp denial. Rename the function to __seccomp_permit_syscall() so that the purpose is entirely clear. [ tglx: Rename the function ] Suggested-by: Thomas Gleixner Suggested-by: Mark Rutland Signed-off-by: Jinjie Ruan Signed-off-by: Thomas Gleixner Tested-by: Mukesh Kumar Chaurasiya (IBM) Reviewed-by: Mukesh Kumar Chaurasiya (IBM) Acked-by: Oleg Nesterov Link: https://patch.msgid.link/20260707190254.230735780@kernel.org --- arch/Kconfig | 2 +- arch/alpha/kernel/ptrace.c | 2 +- arch/arm/kernel/ptrace.c | 2 +- arch/arm64/kernel/ptrace.c | 2 +- arch/csky/kernel/ptrace.c | 2 +- arch/m68k/kernel/ptrace.c | 2 +- arch/mips/kernel/ptrace.c | 2 +- arch/parisc/kernel/ptrace.c | 2 +- arch/sh/kernel/ptrace_32.c | 2 +- arch/um/kernel/skas/syscall.c | 2 +- arch/x86/entry/vsyscall/vsyscall_64.c | 14 +++++----- arch/xtensa/kernel/ptrace.c | 3 +-- include/linux/entry-common.h | 9 +++---- include/linux/seccomp.h | 12 ++++----- kernel/seccomp.c | 36 ++++++++++++-------------- 15 files changed, 45 insertions(+), 49 deletions(-) diff --git a/arch/Kconfig b/arch/Kconfig index 0c01521..d2dbed5 100644 --- a/arch/Kconfig +++ b/arch/Kconfig @@ -647,7 +647,7 @@ config HAVE_ARCH_SECCOMP_FILTER - syscall_set_return_value() - SIGSYS siginfo_t support - secure_computing is called from a ptrace_event()-safe context - - secure_computing return value is checked and a return value of -1 + - secure_computing return value is checked and if false it results in the system call being skipped immediately. - seccomp syscall wired up - if !HAVE_SPARSE_SYSCALL_NR, have SECCOMP_ARCH_NATIVE, diff --git a/arch/alpha/kernel/ptrace.c b/arch/alpha/kernel/ptrace.c index 0687760..2870101 100644 --- a/arch/alpha/kernel/ptrace.c +++ b/arch/alpha/kernel/ptrace.c @@ -387,7 +387,7 @@ asmlinkage unsigned long syscall_trace_enter(void) * If this fails, seccomp may already have set up the return value * (e.g. SECCOMP_RET_ERRNO / TRACE). */ - if (secure_computing() =3D=3D -1) { + if (!seccomp_permit_syscall()) { if (regs->r19 =3D=3D 0 && regs->r0 =3D=3D (unsigned long)-1) syscall_set_return_value(current, regs, -ENOSYS, 0); syscall_set_nr(current, regs, -1); diff --git a/arch/arm/kernel/ptrace.c b/arch/arm/kernel/ptrace.c index 7951b2c..45076fc 100644 --- a/arch/arm/kernel/ptrace.c +++ b/arch/arm/kernel/ptrace.c @@ -855,7 +855,7 @@ asmlinkage int syscall_trace_enter(struct pt_regs *regs) =20 /* Do seccomp after ptrace; syscall may have changed. */ #ifdef CONFIG_HAVE_ARCH_SECCOMP_FILTER - if (secure_computing() =3D=3D -1) + if (!seccomp_permit_syscall()) return -1; #else /* XXX: remove this once OABI gets fixed */ diff --git a/arch/arm64/kernel/ptrace.c b/arch/arm64/kernel/ptrace.c index 4d08598..253ce5d 100644 --- a/arch/arm64/kernel/ptrace.c +++ b/arch/arm64/kernel/ptrace.c @@ -2420,7 +2420,7 @@ int syscall_trace_enter(struct pt_regs *regs) } =20 /* Do the secure computing after ptrace; failures should be fast. */ - if (secure_computing() =3D=3D -1) + if (!seccomp_permit_syscall()) return NO_SYSCALL; =20 if (test_thread_flag(TIF_SYSCALL_TRACEPOINT)) diff --git a/arch/csky/kernel/ptrace.c b/arch/csky/kernel/ptrace.c index 6bb685a..b902358 100644 --- a/arch/csky/kernel/ptrace.c +++ b/arch/csky/kernel/ptrace.c @@ -323,7 +323,7 @@ asmlinkage int syscall_trace_enter(struct pt_regs *regs) if (ptrace_report_syscall_entry(regs)) return -1; =20 - if (secure_computing() =3D=3D -1) + if (!seccomp_permit_syscall()) return -1; =20 if (test_thread_flag(TIF_SYSCALL_TRACEPOINT)) diff --git a/arch/m68k/kernel/ptrace.c b/arch/m68k/kernel/ptrace.c index cfa2df2..28546d7 100644 --- a/arch/m68k/kernel/ptrace.c +++ b/arch/m68k/kernel/ptrace.c @@ -281,7 +281,7 @@ asmlinkage int syscall_trace_enter(void) if (test_thread_flag(TIF_SYSCALL_TRACE)) ret =3D ptrace_report_syscall_entry(task_pt_regs(current)); =20 - if (secure_computing() =3D=3D -1) + if (!seccomp_permit_syscall()) return -1; =20 return ret; diff --git a/arch/mips/kernel/ptrace.c b/arch/mips/kernel/ptrace.c index 3f4c94c..af1e005 100644 --- a/arch/mips/kernel/ptrace.c +++ b/arch/mips/kernel/ptrace.c @@ -1328,7 +1328,7 @@ asmlinkage long syscall_trace_enter(struct pt_regs *r= egs) return -1; } =20 - if (secure_computing()) + if (!seccomp_permit_syscall()) return -1; =20 if (unlikely(test_thread_flag(TIF_SYSCALL_TRACEPOINT))) diff --git a/arch/parisc/kernel/ptrace.c b/arch/parisc/kernel/ptrace.c index 8a17ab7..ac5d077 100644 --- a/arch/parisc/kernel/ptrace.c +++ b/arch/parisc/kernel/ptrace.c @@ -351,7 +351,7 @@ long do_syscall_trace_enter(struct pt_regs *regs) } =20 /* Do the secure computing check after ptrace. */ - if (secure_computing() =3D=3D -1) + if (!seccomp_permit_syscall()) return -1; =20 #ifdef CONFIG_HAVE_SYSCALL_TRACEPOINTS diff --git a/arch/sh/kernel/ptrace_32.c b/arch/sh/kernel/ptrace_32.c index 06f765d..7594bd5 100644 --- a/arch/sh/kernel/ptrace_32.c +++ b/arch/sh/kernel/ptrace_32.c @@ -460,7 +460,7 @@ asmlinkage long do_syscall_trace_enter(struct pt_regs *= regs) return -1; } =20 - if (secure_computing() =3D=3D -1) + if (!seccomp_permit_syscall()) return -1; =20 if (unlikely(test_thread_flag(TIF_SYSCALL_TRACEPOINT))) diff --git a/arch/um/kernel/skas/syscall.c b/arch/um/kernel/skas/syscall.c index ba7494f..bc11773 100644 --- a/arch/um/kernel/skas/syscall.c +++ b/arch/um/kernel/skas/syscall.c @@ -27,7 +27,7 @@ void handle_syscall(struct uml_pt_regs *r) goto out; =20 /* Do the seccomp check after ptrace; failures should be fast. */ - if (secure_computing() =3D=3D -1) + if (!seccomp_permit_syscall()) goto out; =20 syscall =3D UPT_SYSCALL_NR(r); diff --git a/arch/x86/entry/vsyscall/vsyscall_64.c b/arch/x86/entry/vsyscal= l/vsyscall_64.c index ea36de9..1b68c1c 100644 --- a/arch/x86/entry/vsyscall/vsyscall_64.c +++ b/arch/x86/entry/vsyscall/vsyscall_64.c @@ -118,10 +118,10 @@ static bool write_ok_or_segv(unsigned long ptr, size_= t size) =20 static bool __emulate_vsyscall(struct pt_regs *regs, unsigned long address) { - unsigned long caller; - int vsyscall_nr, syscall_nr, tmp; + unsigned long caller, orig_dx; + int vsyscall_nr, syscall_nr; + bool skip; long ret; - unsigned long orig_dx; =20 /* Confirm that the fault happened in 64-bit user mode */ if (!user_64bit_mode(regs)) @@ -197,16 +197,16 @@ static bool __emulate_vsyscall(struct pt_regs *regs, = unsigned long address) */ regs->orig_ax =3D syscall_nr; regs->ax =3D -ENOSYS; - tmp =3D secure_computing(); - if ((!tmp && regs->orig_ax !=3D syscall_nr) || regs->ip !=3D address) { + skip =3D !seccomp_permit_syscall(); + if ((!skip && regs->orig_ax !=3D syscall_nr) || regs->ip !=3D address) { warn_bad_vsyscall(KERN_DEBUG, regs, "seccomp tried to change syscall nr or ip"); force_exit_sig(SIGSYS); return true; } regs->orig_ax =3D -1; - if (tmp) - goto do_ret; /* skip requested */ + if (skip) + goto do_ret; =20 /* * With a real vsyscall, page faults cause SIGSEGV. diff --git a/arch/xtensa/kernel/ptrace.c b/arch/xtensa/kernel/ptrace.c index b80d54b..5c3ebb0 100644 --- a/arch/xtensa/kernel/ptrace.c +++ b/arch/xtensa/kernel/ptrace.c @@ -553,8 +553,7 @@ int do_syscall_trace_enter(struct pt_regs *regs) return 0; } =20 - if (regs->syscall =3D=3D NO_SYSCALL || - secure_computing() =3D=3D -1) { + if (regs->syscall =3D=3D NO_SYSCALL || !seccomp_permit_syscall()) { do_syscall_trace_leave(regs); return 0; } diff --git a/include/linux/entry-common.h b/include/linux/entry-common.h index c837352..99c49a4 100644 --- a/include/linux/entry-common.h +++ b/include/linux/entry-common.h @@ -102,9 +102,8 @@ static __always_inline long syscall_trace_enter(struct = pt_regs *regs, unsigned l =20 /* Do seccomp after ptrace, to catch any tracer changes. */ if (work & SYSCALL_WORK_SECCOMP) { - ret =3D __secure_computing(); - if (ret =3D=3D -1L) - return ret; + if (!__seccomp_permit_syscall()) + return -1L; } =20 /* Either of the above might have changed the syscall number */ @@ -115,7 +114,7 @@ static __always_inline long syscall_trace_enter(struct = pt_regs *regs, unsigned l =20 syscall_enter_audit(regs, syscall); =20 - return ret ? : syscall; + return syscall; } =20 /** @@ -138,7 +137,7 @@ static __always_inline long syscall_trace_enter(struct = pt_regs *regs, unsigned l * It handles the following work items: * * 1) syscall_work flag dependent invocations of - * ptrace_report_syscall_entry(), __secure_computing(), trace_sys_ente= r() + * ptrace_report_syscall_entry(), __seccomp_permit_syscall(), trace_sy= s_enter() * 2) Invocation of audit_syscall_entry() */ static __always_inline long syscall_enter_from_user_mode_work(struct pt_re= gs *regs, long syscall) diff --git a/include/linux/seccomp.h b/include/linux/seccomp.h index 9b95997..fcb3eb9 100644 --- a/include/linux/seccomp.h +++ b/include/linux/seccomp.h @@ -22,14 +22,14 @@ #include #include =20 -extern int __secure_computing(void); +extern bool __seccomp_permit_syscall(void); =20 #ifdef CONFIG_HAVE_ARCH_SECCOMP_FILTER -static inline int secure_computing(void) +static __always_inline bool seccomp_permit_syscall(void) { if (unlikely(test_syscall_work(SECCOMP))) - return __secure_computing(); - return 0; + return __seccomp_permit_syscall(); + return true; } #else extern void secure_computing_strict(int this_syscall); @@ -50,11 +50,11 @@ static inline int seccomp_mode(struct seccomp *s) struct seccomp_data; =20 #ifdef CONFIG_HAVE_ARCH_SECCOMP_FILTER -static inline int secure_computing(void) { return 0; } +static inline bool seccomp_permit_syscall(void) { return true; } #else static inline void secure_computing_strict(int this_syscall) { return; } #endif -static inline int __secure_computing(void) { return 0; } +static inline bool __seccomp_permit_syscall(void) { return true; } =20 static inline long prctl_get_seccomp(void) { diff --git a/kernel/seccomp.c b/kernel/seccomp.c index 0669093..86cf446 100644 --- a/kernel/seccomp.c +++ b/kernel/seccomp.c @@ -1100,12 +1100,13 @@ void secure_computing_strict(int this_syscall) else BUG(); } -int __secure_computing(void) + +bool __seccomp_permit_syscall(void) { int this_syscall =3D syscall_get_nr(current, current_pt_regs()); =20 secure_computing_strict(this_syscall); - return 0; + return true; } #else =20 @@ -1256,7 +1257,7 @@ out: return -1; } =20 -static int __seccomp_filter(int this_syscall, const bool recheck_after_tra= ce) +static bool __seccomp_filter(int this_syscall, const bool recheck_after_tr= ace) { u32 filter_ret, action; struct seccomp_data sd; @@ -1294,7 +1295,7 @@ static int __seccomp_filter(int this_syscall, const b= ool recheck_after_trace) case SECCOMP_RET_TRACE: /* We've been put in this state by the ptracer already. */ if (recheck_after_trace) - return 0; + return true; =20 /* ENOSYS these calls if there is no tracer attached. */ if (!ptrace_event_enabled(current, PTRACE_EVENT_SECCOMP)) { @@ -1329,20 +1330,17 @@ static int __seccomp_filter(int this_syscall, const= bool recheck_after_trace) * a reload of all registers. This does not goto skip since * a skip would have already been reported. */ - if (__seccomp_filter(this_syscall, true)) - return -1; - - return 0; + return __seccomp_filter(this_syscall, true); =20 case SECCOMP_RET_USER_NOTIF: if (seccomp_do_user_notification(this_syscall, match, &sd)) goto skip; =20 - return 0; + return true; =20 case SECCOMP_RET_LOG: seccomp_log(this_syscall, 0, action, true); - return 0; + return true; =20 case SECCOMP_RET_ALLOW: /* @@ -1350,7 +1348,7 @@ static int __seccomp_filter(int this_syscall, const b= ool recheck_after_trace) * this action since SECCOMP_RET_ALLOW is the starting * state in seccomp_run_filters(). */ - return 0; + return true; =20 case SECCOMP_RET_KILL_THREAD: case SECCOMP_RET_KILL_PROCESS: @@ -1367,46 +1365,46 @@ static int __seccomp_filter(int this_syscall, const= bool recheck_after_trace) } else { do_exit(SIGSYS); } - return -1; /* skip the syscall go directly to signal handling */ + return false; /* skip the syscall go directly to signal handling */ } =20 unreachable(); =20 skip: seccomp_log(this_syscall, 0, action, match ? match->log : false); - return -1; + return false; } #else -static int __seccomp_filter(int this_syscall, const bool recheck_after_tra= ce) +static bool __seccomp_filter(int this_syscall, const bool recheck_after_tr= ace) { BUG(); =20 - return -1; + return false; } #endif =20 -int __secure_computing(void) +bool __seccomp_permit_syscall(void) { int mode =3D current->seccomp.mode; int this_syscall; =20 if (IS_ENABLED(CONFIG_CHECKPOINT_RESTORE) && unlikely(current->ptrace & PT_SUSPEND_SECCOMP)) - return 0; + return true; =20 this_syscall =3D syscall_get_nr(current, current_pt_regs()); =20 switch (mode) { case SECCOMP_MODE_STRICT: __secure_computing_strict(this_syscall); /* may call do_exit */ - return 0; + return true; case SECCOMP_MODE_FILTER: return __seccomp_filter(this_syscall, false); /* Surviving SECCOMP_RET_KILL_* must be proactively impossible. */ case SECCOMP_MODE_DEAD: WARN_ON_ONCE(1); do_exit(SIGKILL); - return -1; + return false; default: BUG(); }