Linux Security Modules development
 help / color / mirror / Atom feed
* [RFC PATCH v2 0/3] security: Add PR_CAPBSET_DROP_MASK
@ 2026-09-29 13:01 Jinjie Ruan
  2026-09-29 13:01 ` [RFC PATCH v2 1/3] capability: Move mk_kernel_cap() to header Jinjie Ruan
                   ` (2 more replies)
  0 siblings, 3 replies; 8+ messages in thread
From: Jinjie Ruan @ 2026-09-29 13:01 UTC (permalink / raw)
  To: serge, kees, akpm, david, ljs, liam, vbabka, rppt, surenb, mhocko,
	mingo, peterz, juri.lelli, vincent.guittot, dietmar.eggemann,
	rostedt, bsegall, mgorman, vschneid, kprateek.nayak, paul,
	jmorris, shuah, oleg, brauner, alexjlzheng, jannh, jaime.saguillo,
	elver, blbllhy, bvanassche, pjw, broonie, debug, tglx,
	aleksey.oladko, linux-kernel, linux-fsdevel,
	linux-security-module, linux-mm, linux-kselftest, morgan
  Cc: ruanjinjie

PR_CAPBSET_DROP only affects the calling thread, so dropping capabilities
for a whole process means one call per capability per thread.  For a
long-lived, multi-threaded process such as gVisor's sentry this is
stop-the-world signal delivery and costs milliseconds per sandbox on a
many-core host.

This series adds PR_CAPBSET_DROP_MASK, which removes a 64-bit mask of
capabilities from the whole thread group in a single call.  The drop is
recorded per thread group and folded into the bounding set wherever it
gates gaining a capability, so already-running, concurrently-created and
later-created threads -- as well as children forked by a sibling -- all
observe it.

Trimming 41 capabilities in an arm64 KVM guest goes from ~8.5-23.6ms with
the per-thread loop to ~11-14us, independent of the thread count.

Changes in RFC v2:
- Solve concurrently clone and concurrently drop mask problem.
- Solove sashiko problems in [1].
- Link to RFC v1: https://lore.kernel.org/all/20260922095816.1191799-1-ruanjinjie@huawei.com/
[1] https://sashiko.dev/#/patchset/20260922095816.1191799-1-ruanjinjie%40huawei.com

Jinjie Ruan (3):
  capability: Move mk_kernel_cap() to header
  security: Add PR_CAPBSET_DROP_MASK for process-wide bounding-set drops
  selftests: prctl: add process-wide bounding-set drop tests

 fs/proc/array.c                               |   3 +-
 include/linux/capability.h                    |  10 +
 include/linux/sched/signal.h                  |   8 +
 include/uapi/linux/prctl.h                    |   1 +
 kernel/capability.c                           |   5 -
 kernel/fork.c                                 |   1 +
 security/commoncap.c                          |  91 ++-
 tools/testing/selftests/prctl/Makefile        |  12 +-
 .../selftests/prctl/cap-bset-drop-test.c      | 641 ++++++++++++++++++
 9 files changed, 759 insertions(+), 13 deletions(-)
 create mode 100644 tools/testing/selftests/prctl/cap-bset-drop-test.c

-- 
2.34.1


^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2026-09-29 17:15 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-29 13:01 [RFC PATCH v2 0/3] security: Add PR_CAPBSET_DROP_MASK Jinjie Ruan
2026-09-29 13:01 ` [RFC PATCH v2 1/3] capability: Move mk_kernel_cap() to header Jinjie Ruan
2026-09-29 13:06   ` sashiko-bot
2026-09-29 17:15   ` Bradley Morgan
2026-09-29 13:01 ` [RFC PATCH v2 2/3] security: Add PR_CAPBSET_DROP_MASK for process-wide bounding-set drops Jinjie Ruan
2026-09-29 13:19   ` sashiko-bot
2026-09-29 13:02 ` [RFC PATCH v2 3/3] selftests: prctl: add process-wide bounding-set drop tests Jinjie Ruan
2026-09-29 13:11   ` sashiko-bot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox