Re: [PATCH v8 5/8] seccomp: Add SECCOMP_RET_TRAP

2 messages, 2 authors, 2012-02-16 · open the first message on its own page

Re: [PATCH v8 5/8] seccomp: Add SECCOMP_RET_TRAP

From: Markus Gutschke <hidden>
Date: 2012-02-16 20:28:50

On Thu, Feb 16, 2012 at 12:02, Will Drewry [off-list ref] wrote:
Adds a new return value to seccomp filters that triggers a SIGTRAP to be delivered with the new TRAP_SECCOMP si_code.

This allows in-process system call emulation -- including just specifying an errno or cleanly dumping core -- rather than just dying.
SIGTRAP might not be the ideal choice of signal number, as it can make
it very difficult to debug the program in gdb. Other than that, I love
this feature. It'll significantly simplify the code that we have in
Chrome.


Markus

Re: [PATCH v8 5/8] seccomp: Add SECCOMP_RET_TRAP

From: "H. Peter Anvin" <hpa@zytor.com>
Date: 2012-02-16 21:24:54

On 02/16/2012 12:28 PM, Markus Gutschke wrote:
On Thu, Feb 16, 2012 at 12:02, Will Drewry [off-list ref] wrote:
quoted
Adds a new return value to seccomp filters that triggers a SIGTRAP to be delivered with the new TRAP_SECCOMP si_code.

This allows in-process system call emulation -- including just specifying an errno or cleanly dumping core -- rather than just dying.
SIGTRAP might not be the ideal choice of signal number, as it can make
it very difficult to debug the program in gdb. Other than that, I love
this feature. It'll significantly simplify the code that we have in
Chrome.
Sounds like SIGSYS to me.

	-hpa

-- 
H. Peter Anvin, Intel Open Source Technology Center
I work for Intel.  I don't speak on their behalf.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help