SPARC64 gains Linux seccomp filter support
The architecture was one of the last without the BPF sandboxing Docker, systemd, and Flatpak rely on.
SPARC64 can now use the Linux kernel's seccomp filter mode, ending a long gap that left the platform unable to run the BPF-based sandboxing modern container and service stacks expect.
Stian Halseth supplied the missing pieces. SPARC already had the audit and ptrace helpers filter mode needs, TIF_SECCOMP was already in the syscall-entry work mask, and strict-mode seccomp had been wired for years. What remained was letting seccomp veto a call and return the value the filter core had set, instead of assembler stubs always forcing ENOSYS back to userspace. The entry path now runs ptrace reporting before seccomp (so a tracer's changes are visible to the filter) and skips the syscall cleanly on denial while preserving the old ptrace-abort behaviour.
Filter mode is what Docker, systemd, Flatpak, and similar tools use to confine processes. Without it, SPARC64 could not take full advantage of those stacks even though libseccomp SPARC support was already pending. Halseth reports the seccomp_bpf selftests passing on an UltraSPARC T4-1, the full libseccomp suite succeeding including live tests, and Docker containers running under both the default profile and a custom errno-denial profile.
SPARC maintainer Andreas Larsson has accepted the work and notes 32-bit SPARC support is expected to follow on top. Kees Cook reviewed the selftest changes. Filter support is 64-bit only for now, matching how strict mode was already limited. Alpha remains the other architecture still without the feature.