[RFC PATCH v2 0/3] security: Add PR_CAPBSET_DROP_MASK
Jinjie Ruan
ruanjinjie at huawei.com
Tue Sep 29 13:01:57 UTC 2026
PR_CAPBSET_DROP only affects the calling thread, so dropping capabilities
for a whole process means one call per capability per thread. For a
long-lived, multi-threaded process such as gVisor's sentry this is
stop-the-world signal delivery and costs milliseconds per sandbox on a
many-core host.
This series adds PR_CAPBSET_DROP_MASK, which removes a 64-bit mask of
capabilities from the whole thread group in a single call. The drop is
recorded per thread group and folded into the bounding set wherever it
gates gaining a capability, so already-running, concurrently-created and
later-created threads -- as well as children forked by a sibling -- all
observe it.
Trimming 41 capabilities in an arm64 KVM guest goes from ~8.5-23.6ms with
the per-thread loop to ~11-14us, independent of the thread count.
Changes in RFC v2:
- Solve concurrently clone and concurrently drop mask problem.
- Solove sashiko problems in [1].
- Link to RFC v1: https://lore.kernel.org/all/20260922095816.1191799-1-ruanjinjie@huawei.com/
[1] https://sashiko.dev/#/patchset/20260922095816.1191799-1-ruanjinjie%40huawei.com
Jinjie Ruan (3):
capability: Move mk_kernel_cap() to header
security: Add PR_CAPBSET_DROP_MASK for process-wide bounding-set drops
selftests: prctl: add process-wide bounding-set drop tests
fs/proc/array.c | 3 +-
include/linux/capability.h | 10 +
include/linux/sched/signal.h | 8 +
include/uapi/linux/prctl.h | 1 +
kernel/capability.c | 5 -
kernel/fork.c | 1 +
security/commoncap.c | 91 ++-
tools/testing/selftests/prctl/Makefile | 12 +-
.../selftests/prctl/cap-bset-drop-test.c | 641 ++++++++++++++++++
9 files changed, 759 insertions(+), 13 deletions(-)
create mode 100644 tools/testing/selftests/prctl/cap-bset-drop-test.c
--
2.34.1
More information about the Linux-security-module-archive
mailing list