[PATCH 0/2] seccomp: support O_PATH descriptors in addfd

From: Cong Wang

Date: Thu Sep 24 2026 - 18:31:33 EST


From: Cong Wang <cwang@xxxxxxxxxxxxxx>

The Sandlock project uses seccomp user notification to broker opens. To
maintain user-space application compatibility, it needs to return a
genuine O_PATH descriptor when an application requests one. Currently,
SECCOMP_IOCTL_NOTIF_ADDFD rejects the supervisor's O_PATH descriptor
with EBADF.

Allow addfd to transfer O_PATH descriptors and add a regression test for
their flags and read behavior. All 112 seccomp functional tests and all
7 benchmark checks passed.

Cong Wang (2):
seccomp: allow addfd to transfer O_PATH descriptors
selftests/seccomp: test addfd with an O_PATH descriptor

kernel/seccomp.c | 2 +-
tools/testing/selftests/seccomp/seccomp_bpf.c | 59 +++++++++++++++++++
2 files changed, 60 insertions(+), 1 deletion(-)

--
2.43.0