All of lore.kernel.org
 help / color / mirror / Atom feed
From: Christopher Lusk <clusk@northecho.dev>
To: Greg Ungerer <gerg@linux-m68k.org>,
	Geert Uytterhoeven <geert@linux-m68k.org>
Cc: Kees Cook <kees@kernel.org>, Andy Lutomirski <luto@kernel.org>,
	Will Drewry <wad@chromium.org>,
	Michael Schmitz <schmitzmic@gmail.com>,
	linux-m68k@lists.linux-m68k.org, linux-kernel@vger.kernel.org,
	stable@vger.kernel.org
Subject: [PATCH] m68k: Fix seccomp filtering on ColdFire and 68000
Date: Sat, 12 Sep 2026 19:06:51 -0400	[thread overview]
Message-ID: <20260912230651.461269-1-clusk@northecho.dev> (raw)

m68k selects HAVE_ARCH_SECCOMP_FILTER for all configurations, but the
ColdFire and 68000 syscall entry paths only branch to
syscall_trace_enter() for TIF_SYSCALL_TRACE. TIF_SECCOMP alone falls
through to syscall dispatch, leaving installed filters ineffective.

Test TIF_SECCOMP in both paths and route it through the existing slow
path, matching the classic MMU syscall entry implementation.

Validated under QEMU mcf5208evb (ColdFire): a task installing a seccomp
filter denying getpid() still executed the syscall before this change and
returns -EPERM with it; likewise for a filter denying
openat/unlinkat/reboot. A classic-MMU control (q800) denied the filtered
syscall both before and after, confirming the gap is specific to the
ColdFire/68000 entry paths. The 68000 path shares the same source-level
omission and receives the identical fix but was not separately emulated.
Compile-tested W=1 with CONFIG_SECCOMP_FILTER=y on m5208evb_defconfig.

Fixes: 6baaade15594 ("m68k: Add kernel seccomp support")
Cc: stable@vger.kernel.org # v6.3+
Assisted-by: Claude:claude-opus-4-8
Assisted-by: Codex:gpt-5.6-sol
Signed-off-by: Christopher Lusk <clusk@northecho.dev>
---

Notes:
    No in-tree m68k defconfig selects the pure-68000/DragonBall path.
    Compile-tested W=1 with a custom no-MMU UCSIMM configuration and
    CONFIG_SECCOMP_FILTER=y; arch/m68k/68000/entry.o and vmlinux both built
    successfully. The added gate is form-identical to the ColdFire and
    classic-MMU gates.

 arch/m68k/68000/entry.S    | 2 ++
 arch/m68k/coldfire/entry.S | 2 ++
 2 files changed, 4 insertions(+)

diff --git a/arch/m68k/68000/entry.S b/arch/m68k/68000/entry.S
index c257cc415..093be0a66 100644
--- a/arch/m68k/68000/entry.S
+++ b/arch/m68k/68000/entry.S
@@ -81,6 +81,8 @@ ENTRY(system_call)
 	getthreadinfo
 	btst	#(TIF_SYSCALL_TRACE%8),%a2@(TINFO_FLAGS+(31-TIF_SYSCALL_TRACE)/8)
 	jne	do_trace
+	btst	#(TIF_SECCOMP%8),%a2@(TINFO_FLAGS+(31-TIF_SECCOMP)/8)
+	jne	do_trace
 	cmpl	#NR_syscalls,%d0
 	jcc	badsys
 	lsl	#2,%d0
diff --git a/arch/m68k/coldfire/entry.S b/arch/m68k/coldfire/entry.S
index 4ea08336e..b73de9585 100644
--- a/arch/m68k/coldfire/entry.S
+++ b/arch/m68k/coldfire/entry.S
@@ -74,6 +74,8 @@ ENTRY(system_call)
 	movel	%sp,%a1@(TASK_THREAD+THREAD_ESP0)
 	btst	#(TIF_SYSCALL_TRACE%8),%a0@(TINFO_FLAGS+(31-TIF_SYSCALL_TRACE)/8)
 	bnes	1f
+	btst	#(TIF_SECCOMP%8),%a0@(TINFO_FLAGS+(31-TIF_SECCOMP)/8)
+	bnes	1f
 
 	movel	%d3,%a0
 	jbsr	%a0@
-- 
2.55.0


             reply	other threads:[~2026-09-12 23:07 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-12 23:06 Christopher Lusk [this message]
2026-09-13 10:01 ` [PATCH] m68k: Fix seccomp filtering on ColdFire and 68000 Andreas Schwab
2026-09-13 13:17 ` [PATCH v2] " Christopher Lusk

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260912230651.461269-1-clusk@northecho.dev \
    --to=clusk@northecho.dev \
    --cc=geert@linux-m68k.org \
    --cc=gerg@linux-m68k.org \
    --cc=kees@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-m68k@lists.linux-m68k.org \
    --cc=luto@kernel.org \
    --cc=schmitzmic@gmail.com \
    --cc=stable@vger.kernel.org \
    --cc=wad@chromium.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.