test: check that per-task restrictions survive exec
Per-task io_uring restrictions must keep applying to rings created after
exec, also when the task used io_uring before exec. Kernels without
commit bc0e8faf90e7 ("io_uring: preserve task restrictions across exec")
free the restrictions with the task context on exec in that case, so the
new image can create unrestricted rings. task-restrict.t doesn't cover
exec, so it passes on those kernels.
Restrict a child to NOP, optionally use a ring, re-exec the test and
check that a fresh ring still denies a read. Cover both the opcode
allowlist and a BPF filter.
Skips on 6.18, fails on 7.0, passes on 7.2.9.
Assisted-by: Claude:claude-opus-5-5
Signed-off-by: Eugene Gvozdetsky <gvozdet@gmail.com>
2 files changed