Thread (77 messages) flat view 77 messages, 12 authors, 2011-05-29
STALE5578d

Re: [PATCH 3/5] v2 seccomp_filters: Enable ftrace-based system call filtering

From: Arnd Bergmann <arnd@arndb.de>
Date: 2011-05-15 06:42:07
Also in: linux-arm-kernel, linux-mips

On Saturday 14 May 2011, Will Drewry wrote:
Depending on integration, it could even be limited to ioctl commands
that are appropriate to a known fd if the fd is opened prior to
entering seccomp mode 2. Alternatively, __NR__ioctl could be allowed
with a filter of "1" then narrowed through a later addition of
something like "(fd == %u && (cmd == %u || cmd == %u))" or something
along those lines.

Does that make sense?
Thanks for the explanation. This sounds like it's already doing all
we need.

	Arnd
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help