Thread (109 messages) 109 messages, 16 authors, 2026-09-01

Re: [patch 11/18] seccomp, treewide: Rename and convert __secure_computing() to return boolean

From: Kees Cook <kees@kernel.org>
Date: 2026-07-09 16:22:06
Also in: linux-alpha, linux-arch, linux-doc, linux-m68k, linux-mips, linux-riscv, linux-s390, linux-sh, linux-um, lkml, loongarch, sparclinux

On Tue, Jul 07, 2026 at 09:06:40PM +0200, Thomas Gleixner wrote:
From: Jinjie Ruan <redacted>

The return value of __secure_computing() currently uses 0 to indicate
that a system call should be allowed, and -1 to indicate that it should
be blocked/killed. This 0/-1 pattern is non-intuitive for a security
check function and makes the control flow at the call sites less readable.
Conceptually, I'm good with this. Just make sure that the
tools/testing/selftests/seccomp/seccomp_bpf tests still passes. :)

-- 
Kees Cook
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help