[PATCH 0/2] seccomp: support O_PATH descriptors in addfd
From: Cong Wang
Date: Thu Sep 24 2026 - 18:31:33 EST
From: Cong Wang <cwang@xxxxxxxxxxxxxx>
The Sandlock project uses seccomp user notification to broker opens. To
maintain user-space application compatibility, it needs to return a
genuine O_PATH descriptor when an application requests one. Currently,
SECCOMP_IOCTL_NOTIF_ADDFD rejects the supervisor's O_PATH descriptor
with EBADF.
Allow addfd to transfer O_PATH descriptors and add a regression test for
their flags and read behavior. All 112 seccomp functional tests and all
7 benchmark checks passed.
Cong Wang (2):
seccomp: allow addfd to transfer O_PATH descriptors
selftests/seccomp: test addfd with an O_PATH descriptor
kernel/seccomp.c | 2 +-
tools/testing/selftests/seccomp/seccomp_bpf.c | 59 +++++++++++++++++++
2 files changed, 60 insertions(+), 1 deletion(-)
--
2.43.0