Thread (50 messages) flat view 50 messages, 8 authors, 2012-02-21

Re: [PATCH v8 3/8] seccomp: add system call filtering using BPF

From: "H. Peter Anvin" <hpa@zytor.com>
Date: 2012-02-17 04:33:04
Also in: linux-arch, lkml

On 02/16/2012 08:26 PM, Will Drewry wrote:
quoted
For x32 you have the option of introducing a new value or relying on bit
30 in eax (and AUDIT_ARCH_X86_64).  The latter is more natural, probably.
Will that bit be visible as the syscall number or will it be stripped
out before passing the number around?  If it's visible, then it
doesn't seem like there'd need to be a new AUDIT_ARCH, but I suspect
someone like Eric will have an actually useful opinion.
Bit 30 is visible in orig_eax; whether you export it as part of "the
syscall number" is presumably TBD, but I think it's more natural to do so.

	-hpa

-- 
H. Peter Anvin, Intel Open Source Technology Center
I work for Intel.  I don't speak on their behalf.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help