From: sashiko-bot@kernel.org
Cc: linux-security-module@vger.kernel.org
Subject: Re: [RFC PATCH v2 3/3] selftests: prctl: add process-wide bounding-set drop tests
Date: Tue, 29 Sep 2026 13:11:35 +0000 [thread overview]
Message-ID: <20260929131135.B40351F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260929130200.1638343-4-ruanjinjie@huawei.com>
Thank you for your contribution! Sashiko AI review found 4 potential issue(s) to consider:
- [Medium] selftests: prctl: test fails to verify concurrent thread creation due to synchronous pthread_join
- [Medium] selftests: prctl: deadlock on drop_cap() error path in conc_test_child()
- [Medium] selftests: prctl: uninitialized thread ID passed to pthread_join() on pthread_create() failure
- [Medium] selftests: prctl: unmaterialized drop inheritance test is nullified by syscall before fork
--
commit efe86d5c1a9f1d9daea13c0d844c2621fc972d8d
Author: Jinjie Ruan <ruanjinjie@huawei.com>
Subject: selftests: prctl: add process-wide bounding-set drop tests
This commit adds tests for PR_CAPBSET_DROP_MASK. It covers argument validation,
permission checking, and process-wide application of the bounding set drop
across sibling threads and forked children.
> diff --git a/tools/testing/selftests/prctl/cap-bset-drop-test.c b/tools/testing/selftests/prctl/cap-bset-drop-test.c
> new file mode 100644
> index 0000000000000..d0432f9b58377
> --- /dev/null
> +++ b/tools/testing/selftests/prctl/cap-bset-drop-test.c
[ ... ]
> +static void *fork_sibling(void *arg)
> +{
> + pid_t pid;
> + int status;
> +
> + (void)arg;
> +
> + while (!atomic_load(&fork_go))
> + sched_yield();
> +
> + if (bset_has(dropped_cap))
> + atomic_store(&fork_ok, 0);
> +
> + pid = fork();
[Severity: Medium]
Does calling bset_has() here defeat the purpose of the test? bset_has() invokes
prctl(), which is a syscall. Returning to userspace from this syscall forces
pending task work (TIF_NOTIFY_RESUME) to be processed, fully materializing the
credentials before fork() occurs. This nullifies the intent of verifying that an
unmaterialized drop is properly inherited by a child thread.
> + if (pid == 0)
> + _exit(bset_has(dropped_cap) ? 1 : 0);
[ ... ]
> +static void *conc_spawner(void *arg)
> +{
> + (void)arg;
> +
> + while (!atomic_load(&conc_stop)) {
> + pthread_t t;
> +
> + if (pthread_create(&t, NULL, conc_worker, NULL) == 0)
> + pthread_join(t, NULL);
[Severity: Medium]
Does this synchronous wait serialize thread creation? Calling pthread_join()
immediately after pthread_create() blocks the spawner thread until the spawned
worker unblocks. As a result, no new threads are actively created during the
capability drop, nullifying the concurrent thread creation test.
> + }
> + return NULL;
> +}
> +
> +static int conc_test_child(void)
> +{
> + pthread_t sp[4];
> + int i;
> +
> + atomic_store(&conc_stop, 0);
> + atomic_store(&conc_dropped, 0);
> + atomic_store(&conc_bad, 0);
> +
> + for (i = 0; i < 4; i++) {
> + if (pthread_create(&sp[i], NULL, conc_spawner, NULL))
> + return CHILD_FAIL;
> + }
> +
> + if (drop_cap(dropped_cap)) {
> + atomic_store(&conc_stop, 1);
> + for (i = 0; i < 4; i++)
> + pthread_join(sp[i], NULL);
> + return CHILD_FAIL;
> + }
[Severity: Medium]
Can this error path lead to an infinite hang? If drop_cap() fails, conc_dropped
is never set to 1. The worker threads will spin infinitely waiting for it to
change. This in turn causes the spawner threads to block infinitely in
pthread_join() waiting for the workers, and the main thread blocks infinitely
here waiting for the spawners.
> + atomic_store(&conc_dropped, 1);
> + usleep(20000);
[ ... ]
> +static void *multi_spawner(void *arg)
> +{
> + (void)arg;
> +
> + while (!atomic_load(&multi_done)) {
> + pthread_t t;
> +
> + if (pthread_create(&t, NULL, multi_reader, NULL) == 0)
> + pthread_join(t, NULL);
[Severity: Medium]
Similar to the issue in conc_spawner(), does this synchronous wait prevent the
intended concurrency test? Waiting on the worker prevents thread creation races
with the concurrent capability drops.
> + }
> + return NULL;
> +}
[ ... ]
> +static int multi_drop_test_child(void)
> +{
> + pthread_t dr[MULTI_DROP], sp[4], late;
> + int i;
[ ... ]
> + if (multi_bset_has_any()) /* the calling thread itself */
> + return CHILD_FAIL;
> + if (atomic_load(&multi_bad))
> + return CHILD_FAIL;
> +
> + pthread_create(&late, NULL, multi_reader, NULL);
> + pthread_join(late, NULL);
[Severity: Medium]
Is it safe to unconditionally join this thread? If pthread_create() fails, late
remains uninitialized. Passing an uninitialized thread ID to pthread_join()
causes undefined behavior and could result in a crash or hang.
> + if (atomic_load(&multi_bad))
> + return CHILD_FAIL;
> +
> + return CHILD_PASS;
> +}
[ ... ]
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260929130200.1638343-1-ruanjinjie@huawei.com?part=3
prev parent reply other threads:[~2026-09-29 13:11 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 13:01 [RFC PATCH v2 0/3] security: Add PR_CAPBSET_DROP_MASK Jinjie Ruan
2026-09-29 13:01 ` [RFC PATCH v2 1/3] capability: Move mk_kernel_cap() to header Jinjie Ruan
2026-09-29 13:06 ` sashiko-bot
2026-09-29 17:15 ` Bradley Morgan
2026-09-29 13:01 ` [RFC PATCH v2 2/3] security: Add PR_CAPBSET_DROP_MASK for process-wide bounding-set drops Jinjie Ruan
2026-09-29 13:19 ` sashiko-bot
2026-09-29 13:02 ` [RFC PATCH v2 3/3] selftests: prctl: add process-wide bounding-set drop tests Jinjie Ruan
2026-09-29 13:11 ` sashiko-bot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260929131135.B40351F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox