Thread (53 messages) 53 messages, 9 authors, 2012-02-29

Re: [PATCH v11 07/12] seccomp: add SECCOMP_RET_ERRNO

From: Oleg Nesterov <oleg@redhat.com>
Date: 2012-02-27 17:19:17
Also in: linux-arch, lkml

On 02/24, Will Drewry wrote:
 static u32 seccomp_run_filters(int syscall)
 {
 	struct seccomp_filter *f;
-	u32 ret = SECCOMP_RET_KILL;
 	static const struct bpf_load_fn fns = {
 		bpf_load,
 		sizeof(struct seccomp_data),
 	};
+	u32 ret = SECCOMP_RET_ALLOW;
 	const void *sc_ptr = (const void *)(uintptr_t)syscall;
 
+	/* Ensure unexpected behavior doesn't result in failing open. */
+	if (unlikely(current->seccomp.filter == NULL))
+		ret = SECCOMP_RET_KILL;
Is "seccomp.filter == NULL" really possible?

Oleg.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help