Thread (9 messages) 9 messages, 7 authors, 2016-01-25

Re: [RFC PATCH 1/1] seccomp: provide information about the previous syscall

From: Alexei Starovoitov <hidden>
Date: 2016-01-22 17:30:52
Also in: lkml

On Fri, Jan 22, 2016 at 03:30:00PM +0900, Daniel Sangorrin wrote:
This patch allows applications to restrict the order in which
its system calls may be requested. In order to do that, we
provide seccomp-BPF scripts with information about the
previous system call requested.

An example use case consists of detecting (and stopping) return
oriented attacks that disturb the normal execution flow of
a user program.

Signed-off-by: Daniel Sangorrin <redacted>
...
quoted hunk ↗ jump to hunk
diff --git a/include/uapi/linux/seccomp.h b/include/uapi/linux/seccomp.h
...
quoted hunk ↗ jump to hunk
 struct seccomp_data {
 	int nr;
+	int prev_nr;
 	__u32 arch;
 	__u64 instruction_pointer;
 	__u64 args[6];
this will break abi for existing seccomp programs.
New field has to be at the end.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help