From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-dy1-f174.google.com (mail-dy1-f174.google.com [74.125.82.174]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1B542AD24 for ; Sat, 13 Jun 2026 00:16:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.82.174 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781309762; cv=none; b=bA+V7Q81ySP18Vb4eQ78vPbRyeoitvzDpFP7EqDB5A2CU5ru4D6KyMbX1F5poBTS/RJ8x6n1q+ejBRYRWTi2/3oNI/RkWsAM+BA9ETb2yb/53cKNWwzwz8M4nHCBfZheGVZKgB639Aeibf9+SXmoq9+oIDE/+nBhilHxcaacnZ4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781309762; c=relaxed/simple; bh=12vFJDYovWVLFgoYCd1kSoyCrtdNQy2ar47PHmyY988=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=Kh4zIKMHzW0Zo++Ln5V/uN+UV7fH1FoVs7PWKzFMbnNCq4aXxo9B1+iAP41Fhb4KIeSkP59EElDtnZ7V/wk+G5uJJ6bRP63gXU9D3kCW/DRiRwj2/d5A3HPrrL7am+0TgnC+6pPVWFl9wudTgbTyca+1y7pVfOhZMHb1M2pJito= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=FaJKRr6o; arc=none smtp.client-ip=74.125.82.174 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="FaJKRr6o" Received: by mail-dy1-f174.google.com with SMTP id 5a478bee46e88-307263ad0cbso2450822eec.0 for ; Fri, 12 Jun 2026 17:16:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1781309760; x=1781914560; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=CPakkF3rfH+/QKX/KbF9ovfNSX5u7Fmf6LhKLOA+bfE=; b=FaJKRr6oY/ycsRpZ3c/e4lbsiJMyutSt2BGMkbcc1mXBH3V36ACO0NK9nYYaHJ8H7P 59ufoQz2aO+yGgEkndKngorIdORN94cn1mmsuWJjT9GQUiVFbQAklkmTwyCBA6W5PG1z aPTN5m2PGF7M9VD84/r3IVCFuAVtCISJUyv+BZaJ8fjRBKgS5KnrLDn6yYXl9Yrar48i GWdVJgQcIwV5Ke444tEJuUMY5mMcLkcWnT+6y6bO50mhGHcAaT5HJvRr1wmu1kZR7fE9 YOLl0IgKn35Yn80Rvk4zjyTl9i2p+bSLf5MK8ee4lMFMjg9G+hkl/80XcEaCLwfFoiEE imVw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781309760; x=1781914560; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=CPakkF3rfH+/QKX/KbF9ovfNSX5u7Fmf6LhKLOA+bfE=; b=l9OJN5OKQiwaOZ/6loKToLyqKAJukTL0Z3HyyKyo6vph6QekeCt0LsvbkmcQgoNFDt liNvVBSuM4LuME0R8GucCIG2rl4+UNrtmoU4RtFEvYyq1XTNMvWGd0Od/88JWnmcOF/l J5p/Wr86JwFo2MPz/1JOUfvg7J2UizHJ4BrhQFlbDGpHKDOGKkajXKNeK7+3itsmLB6h HQnhcQzttf8irM134eUDpXtSXtYZo8ZOCGyigXzBZckd2Quouuaj1atFOsvNsQi5cupK 7nJxzoRUkOELDCtNJKHwHwahKTcliwMY+5xevqcbtEl7WcNPy8vmNo0YEK0Qyyd4tvrs onvg== X-Forwarded-Encrypted: i=1; AFNElJ91SWQTrvaguw9C12yrWpuGyVGVf0LRyvV6fq0UOkXYPHIzV6ltBu5zNXA6igYGCIVsmlZ/Uc7EHAovhmw=@vger.kernel.org X-Gm-Message-State: AOJu0YxHy9GSJc2LywA88p9qW7CRDlFoq3eANP9Vb+mr4nlpTEpWWKD9 q+KINjPT+KlkBlCzOWHeFRQcgPePdHVJUDe1vTsoQMSL+S9GodQ+G3tdfyxIVw== X-Gm-Gg: Acq92OFFT15D1JKlaO8OpepuR8OYxLjwiM3fbTV/kyJyXkbEAshUfcS1rJPLuLXsxuC lqak9wc3LDqzOEZRP7VRz5vMaQn7w7pWJFdHqfBisJeZ9s9EKBWrIcLu5sNHMaJrpCA4dSv9UDd 4uvB/MEwg17lKwsbNFspz6AdPrzDqhX3PRvH+XU2yhopmg1SVFfqqVKv480dH8b3DgOF3DBch4x BRlVT6uWa9VZEsoJmmMC1iSjtGLjXbx5Nk7+T6H6JKB5LoDFgrEM1TTif5yjWMyu2ze51QqtygD D7FyC5sfc2KdGo6jsEf3n1P8OMqMXZSMSwsuV/TNqxitRxUoXrC2KUuOF3Mh2ev5Uw153vvdjnK BuyeXrDdgEwkONg5KY4+cPSLLo9erLkjEf6ejN8NVTbSr/gH0lDBbPN/1VjeHcgqNJkO/xnW0xm Q4BE9QWRCX/oJVXVWFt3bjYeFO4XDK+9P0nfmsj4hzFyrStSIbdTlhBcYtDo7pChCi0w== X-Received: by 2002:a05:7300:5710:b0:2c1:7793:7bbb with SMTP id 5a478bee46e88-3093e2a95b6mr1017151eec.27.1781309760131; Fri, 12 Jun 2026 17:16:00 -0700 (PDT) Received: from pop-os.scu.edu ([129.210.115.107]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3081e4898c0sm5710567eec.3.2026.06.12.17.15.59 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 12 Jun 2026 17:15:59 -0700 (PDT) From: Cong Wang To: Andy Lutomirski Cc: Kees Cook , linux-kernel@vger.kernel.org, Will Drewry , Christian Brauner Subject: [RFC PATCH v3 0/3] seccomp: non-cooperative pinned-memfd argument redirect Date: Fri, 12 Jun 2026 17:15:30 -0700 Message-ID: <20260613001533.314739-1-xiyou.wangcong@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit The seccomp user-notification SECCOMP_USER_NOTIF_FLAG_CONTINUE response carries an inherent TOCTOU: once the supervisor decides to let a syscall continue, the target (or a CLONE_VM peer) can rewrite the memory behind a pointer argument before the kernel reads it. This is documented in the UAPI header and is why the notifier "cannot be used to implement a security policy" today. The cooperative way around this is for the target to map a shared memfd and mseal() it during a trusted setup window, so the supervisor can hand the kernel an immutable buffer. That window does not exist for the common fork()+execve() sandbox model, where the supervisor wants to confine an uncooperative (or legacy) binary it did not write. This series lets the supervisor close the TOCTOU without any target-side cooperation: - The kernel installs a sealed, read-only, MAP_SHARED mapping of a supervisor-owned memfd directly into the trapped task's mm (SECCOMP_IOCTL_NOTIF_PIN_INSTALL). The mapping is VM_SEALED at creation, so neither the target nor a CLONE_VM peer can unmap, remap, mprotect or MAP_FIXED-stomp it. The supervisor writes the intended argument data through its own mapping of the same memfd. - The supervisor then resumes the syscall with selected argument registers rewritten to point into that pin (SECCOMP_IOCTL_NOTIF_SEND_REDIRECT). Pointer substitutions are validated so the whole access [ptr, ptr+len) lies inside a pin that still lives in the target's current mm; original registers are restored at syscall exit for ABI compliance. Because the data the kernel acts on lives in an immutable pin, the target can no longer win the race. execve() is handled as a first-class case: its pathname is copied from the pin before the old mm is torn down, and the register-restore is skipped once the program image has been replaced (detected via self_exec_id). Patch 1 adds the mm plumbing: __do_mmap(), a variant of do_mmap() that targets a caller-supplied mm (do_mmap() stays a current->mm wrapper, so no existing caller changes), and vm_mmap_seal_remote(), a tailored high-level helper for installing the sealed pin. Patch 2 is the seccomp ABI and implementation. Patch 3 adds selftests. Changes since v2: v3 is a redesign rather than an incremental revision. v2 added a SECCOMP_IOCTL_NOTIF_INJECT ioctl: the supervisor described a substitute syscall plus an input buffer, and on CONTINUE the kernel copied that buffer in and ran a kernel-side helper for a small whitelist of syscalls (openat, bind, write) without re-reading the target's memory. That closed the TOCTOU, but required an in-kernel reimplementation of every supported syscall and a fixed whitelist, and never actually ran the real syscall. v3 drops the kernel-side helpers entirely as suggested by Andy. All four pinned-memfd selftests pass. --- Cong Wang (3): mm: add __do_mmap() and vm_mmap_seal_remote() seccomp: add kernel-installed pinned-memfd redirect selftests/seccomp: cover non-cooperative pinned-memfd install include/linux/mm.h | 2 + include/linux/seccomp.h | 8 + include/uapi/linux/seccomp.h | 99 ++ kernel/seccomp.c | 366 +++++++ mm/internal.h | 5 + mm/mmap.c | 29 +- mm/nommu.c | 12 +- mm/util.c | 50 + mm/vma.c | 18 +- mm/vma.h | 6 +- tools/testing/selftests/seccomp/seccomp_bpf.c | 960 ++++++++++++++++++ 11 files changed, 1533 insertions(+), 22 deletions(-) base-commit: 28608283615e5e7e92ea79c8ea13507f4b5e0cbe -- 2.43.0