seccomp: Add filter flag to opt-out of SSB mitigation
If a seccomp user is not interested in Speculative Store Bypass mitigation by default, it can set the new SECCOMP_FILTER_FLAG_SPEC_ALLOW flag when adding filters. Signed-off-by:Kees Cook <keescook@chromium.org> Signed-off-by:
Thomas Gleixner <tglx@linutronix.de>
Showing
- include/linux/seccomp.h 3 additions, 2 deletionsinclude/linux/seccomp.h
- include/uapi/linux/seccomp.h 3 additions, 2 deletionsinclude/uapi/linux/seccomp.h
- kernel/seccomp.c 11 additions, 8 deletionskernel/seccomp.c
- tools/testing/selftests/seccomp/seccomp_bpf.c 19 additions, 3 deletionstools/testing/selftests/seccomp/seccomp_bpf.c
Loading
Please register or sign in to comment