Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1411792
| From | Kees Cook <keescook@chromium.org> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | Re: [PATCH] seccomp: plug syscall-dodging ptrace hole |
| Date | 2016-06-02 05:10 +0200 |
| Message-ID | <rFrbb-uw-1@gated-at.bofh.it> (permalink) |
| References | (2 earlier) <rDg0x-65I-3@gated-at.bofh.it> <rDhSF-7hl-5@gated-at.bofh.it> <rDuZA-71l-13@gated-at.bofh.it> <rDw5k-7Db-33@gated-at.bofh.it> <rDwoG-7YU-9@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Fri, May 27, 2016 at 1:14 PM, Andy Lutomirski <luto@amacapital.net> wrote: > On Fri, May 27, 2016 at 12:52 PM, Andy Lutomirski <luto@amacapital.net> wrote: >>> Right, I know, it's aesthetically much nicer that way, but I really >>> want to stay totally paranoid and keep seccomp absolutely first on the >>> path. >>> >>> How about this: we'll use this patch as-is for now, since I'd like to >>> be able to start getting feedback from the container-using folks ASAP, >>> and then we can redesign the 2-phase system going forward from there. >>> >> >> I think I'd rather change the ABI as few times as possible. On the >> other hand, it's still early, and I see nothing wrong with adding it >> to -next. > > To get the ball rolling: > > https://git.kernel.org/cgit/linux/kernel/git/luto/linux.git/log/?h=seccomp > > It's incomplete, but it should be straightforward to finish it. The > only interesting bit is dealing with SECCOMP_RET_TRACE. I did a bit more from there (though it needs further cleanup, I see my "const" fixes landed in the wrong patch), this passes my tests on x86, the other architectures need reordering and testing: http://git.kernel.org/cgit/linux/kernel/git/kees/linux.git/log/?h=seccomp/reorder-ptrace -Kees -- Kees Cook Chrome OS & Brillo Security
Back to linux.kernel | Previous | Next | Find similar | Unroll thread
Re: [PATCH] seccomp: plug syscall-dodging ptrace hole Kees Cook <keescook@chromium.org> - 2016-06-02 05:10 +0200
csiph-web