Re: [PATCH 0/2] seccomp: support O_PATH descriptors in addfd
From: Kees Cook
Date: Tue Oct 06 2026 - 04:30:45 EST
On Thu, 24 Sep 2026 15:30:15 -0700, Cong Wang wrote:
> From: Cong Wang <cwang@xxxxxxxxxxxxxx>
>
> The Sandlock project uses seccomp user notification to broker opens. To
> maintain user-space application compatibility, it needs to return a
> genuine O_PATH descriptor when an application requests one. Currently,
> SECCOMP_IOCTL_NOTIF_ADDFD rejects the supervisor's O_PATH descriptor
> with EBADF.
>
> [...]
Applied to for-next/seccomp, thanks!
[1/2] seccomp: allow addfd to transfer O_PATH descriptors
https://git.kernel.org/kees/c/151671cc5d50
[2/2] selftests/seccomp: test addfd with an O_PATH descriptor
https://git.kernel.org/kees/c/cefd42a719d9
Take care,
--
Kees Cook