[RFC PATCH v2 0/3] security: Add PR_CAPBSET_DROP_MASK
From: Jinjie Ruan <hidden>
Date: 2026-09-29 13:02:05
Also in:
linux-fsdevel, linux-kselftest, linux-mm, lkml
PR_CAPBSET_DROP only affects the calling thread, so dropping capabilities for a whole process means one call per capability per thread. For a long-lived, multi-threaded process such as gVisor's sentry this is stop-the-world signal delivery and costs milliseconds per sandbox on a many-core host. This series adds PR_CAPBSET_DROP_MASK, which removes a 64-bit mask of capabilities from the whole thread group in a single call. The drop is recorded per thread group and folded into the bounding set wherever it gates gaining a capability, so already-running, concurrently-created and later-created threads -- as well as children forked by a sibling -- all observe it. Trimming 41 capabilities in an arm64 KVM guest goes from ~8.5-23.6ms with the per-thread loop to ~11-14us, independent of the thread count. Changes in RFC v2: - Solve concurrently clone and concurrently drop mask problem. - Solove sashiko problems in [1]. - Link to RFC v1: https://lore.kernel.org/all/20260922095816.1191799-1-ruanjinjie@huawei.com/ (local) [1] https://sashiko.dev/#/patchset/20260922095816.1191799-1-ruanjinjie%40huawei.com Jinjie Ruan (3): capability: Move mk_kernel_cap() to header security: Add PR_CAPBSET_DROP_MASK for process-wide bounding-set drops selftests: prctl: add process-wide bounding-set drop tests fs/proc/array.c | 3 +- include/linux/capability.h | 10 + include/linux/sched/signal.h | 8 + include/uapi/linux/prctl.h | 1 + kernel/capability.c | 5 - kernel/fork.c | 1 + security/commoncap.c | 91 ++- tools/testing/selftests/prctl/Makefile | 12 +- .../selftests/prctl/cap-bset-drop-test.c | 641 ++++++++++++++++++ 9 files changed, 759 insertions(+), 13 deletions(-) create mode 100644 tools/testing/selftests/prctl/cap-bset-drop-test.c -- 2.34.1