Thread (9 messages) 9 messages, 7 authors, 2016-01-25

Re: [RFC PATCH 1/1] seccomp: provide information about the previous syscall

flat view

From: Kees Cook <hidden>
Date: 2016-01-22 21:23:26
Also in: lkml

On Fri, Jan 22, 2016 at 9:30 AM, Alexei Starovoitov
[off-list ref] wrote:
On Fri, Jan 22, 2016 at 03:30:00PM +0900, Daniel Sangorrin wrote:
quoted
This patch allows applications to restrict the order in which
its system calls may be requested. In order to do that, we
provide seccomp-BPF scripts with information about the
previous system call requested.

An example use case consists of detecting (and stopping) return
oriented attacks that disturb the normal execution flow of
a user program.

Signed-off-by: Daniel Sangorrin <redacted>
...
quoted
diff --git a/include/uapi/linux/seccomp.h b/include/uapi/linux/seccomp.h
...
quoted
 struct seccomp_data {
      int nr;
+     int prev_nr;
      __u32 arch;
      __u64 instruction_pointer;
      __u64 args[6];
this will break abi for existing seccomp programs.
New field has to be at the end.
Yeah, and if we break abi, we need to add further sanity checking to
the parser to determine which "version" of seccomp_data we need. I'm
not convinced that there is enough utility here to break ABI.

(Though if we do, I'd like to add tid to the seccomp_data, which has
been requested in the past to make some pid-based arg checks easier to
do.)

-Kees

-- 
Kees Cook
Chrome OS & Brillo Security
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help