On Mon, May 17, 2021 at 12:39:04PM -0700, Sargun Dhillon wrote: > This is somewhat of a respin of "Handle seccomp notification preemption" > but without the controversial parts. > > > This patchset addresses a race condition we've dealt with recently with > seccomp. Specifically programs interrupting syscalls while they're in > progress. This was exacerbated by Golang's recent adoption of "async > preemption", in which they try to interrupt any syscall that's been running > for more than 10ms during GC. During certain syscalls, it's non-trivial to > write them in a reetrant manner in userspace (socket). > > It focuses on one use cases, which is adding file descriptors to a process > "atomically" during the seccomp reply, as opposed to discretizing the calls > which may result in a potential file descriptor leak and inconsistent > program state. Looks good, Acked-by: Christian Brauner <christian.brauner@xxxxxxxxxx>