Re: [PATCH 0/3] seccomp: opt in to restarting notifications before receipt

From: Kees Cook

Date: Tue Oct 06 2026 - 04:28:46 EST


On Thu, 24 Sep 2026 13:42:06 -0700, Cong Wang wrote:
> From: Cong Wang <cwang@xxxxxxxxxxxxxx>
>
> Sandlock is an unprivileged Linux process sandbox that uses Landlock and
> seccomp to confine untrusted programs.
>
> While using seccomp user notifications to enforce process limits,
> sandlock encountered intermittent shell pipeline failures: SIGCHLD can
> interrupt a pending fork notification and make fork return EINTR before
> it executes [1]. The same pre-execution interruption can leave an
> intercepted close returning EINTR with its descriptor still open.
>
> [...]

Applied to for-next/seccomp, thanks!

[1/3] seccomp: allow restarting interrupted unreceived notifications
https://git.kernel.org/kees/c/c63c136194e9
[2/3] selftests/seccomp: cover restart of unreceived notifications
https://git.kernel.org/kees/c/c3597f6d03f2
[3/3] docs/seccomp: describe the SECCOMP_FILTER_FLAG_RESTART_BEFORE_RECV flag
https://git.kernel.org/kees/c/e0eb7e155762

Take care,

--
Kees Cook