Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1437496 > unrolled thread
| Started by | Olof Johansson <olof@lixom.net> |
|---|---|
| First post | 2016-07-06 09:00 +0200 |
| Last post | 2016-07-07 20:00 +0200 |
| Articles | 4 — 2 participants |
Back to article view | Back to linux.kernel
[PATCH] samples/seccomp: Add standalone config option Olof Johansson <olof@lixom.net> - 2016-07-06 09:00 +0200
Re: [PATCH] samples/seccomp: Add standalone config option Kees Cook <keescook@chromium.org> - 2016-07-06 20:00 +0200
Re: [PATCH] samples/seccomp: Add standalone config option Olof Johansson <olof@lixom.net> - 2016-07-07 19:20 +0200
Re: [PATCH] samples/seccomp: Add standalone config option Kees Cook <keescook@chromium.org> - 2016-07-07 20:00 +0200
| From | Olof Johansson <olof@lixom.net> |
|---|---|
| Date | 2016-07-06 09:00 +0200 |
| Subject | [PATCH] samples/seccomp: Add standalone config option |
| Message-ID | <rROYp-5Ma-15@gated-at.bofh.it> |
Add a separate Kconfig option for SAMPLES_SECCOMP. Main reason for this is that, just like other samples, it's forced to be a module. Without this, since the sample is a target only controlled by CONFIG_SECCOMP_FILTER, the samples will be built before include files are put in place properly. For example, from an arm64 allmodconfig built with "make -sk -j 32" (without specific target), the following happens: samples/seccomp/bpf-fancy.c:13:27: fatal error: linux/seccomp.h: No such file or directory samples/seccomp/bpf-helper.h:20:50: fatal error: linux/seccomp.h: No such file or directory samples/seccomp/dropper.c:20:27: fatal error: linux/seccomp.h: No such file or directory samples/seccomp/bpf-direct.c:21:27: fatal error: linux/seccomp.h: No such file or directory So, just stick to the same format as other samples. Signed-off-by: Olof Johansson <olof@lixom.net> --- samples/Kconfig | 7 +++++++ samples/seccomp/Makefile | 2 +- 2 files changed, 8 insertions(+), 1 deletion(-) Hi Kees, This has been showing up for a while on my builder, and I finally had a bit of time to sit down and look at it. It'd be nice to see this in 4.7, but please consider for 4.8 at the least. Thanks! -Olof diff --git a/samples/Kconfig b/samples/Kconfig index 559a58b..ccc50be 100644 --- a/samples/Kconfig +++ b/samples/Kconfig @@ -85,4 +85,11 @@ config SAMPLE_CONNECTOR with it. See also Documentation/connector/connector.txt +config SAMPLE_SECCOMP + tristate "Build seccomp sample code -- loadable modules only" + depends on SECCOMP_FILTER && m + help + Build samples of seccomp filters using various methods of + BPF filter construction. + endif # SAMPLES diff --git a/samples/seccomp/Makefile b/samples/seccomp/Makefile index 1b4e4b8..ae7ff6f 100644 --- a/samples/seccomp/Makefile +++ b/samples/seccomp/Makefile @@ -1,7 +1,7 @@ # kbuild trick to avoid linker error. Can be omitted if a module is built. obj- := dummy.o -hostprogs-$(CONFIG_SECCOMP_FILTER) := bpf-fancy dropper bpf-direct +hostprogs-$(CONFIG_SAMPLE_SECCOMP) := bpf-fancy dropper bpf-direct HOSTCFLAGS_bpf-fancy.o += -I$(objtree)/usr/include HOSTCFLAGS_bpf-fancy.o += -idirafter $(objtree)/include -- 2.8.0.rc3.29.gb552ff8
[toc] | [next] | [standalone]
| From | Kees Cook <keescook@chromium.org> |
|---|---|
| Date | 2016-07-06 20:00 +0200 |
| Message-ID | <rRZh7-3OH-3@gated-at.bofh.it> |
| In reply to | #1437496 |
On Wed, Jul 6, 2016 at 2:53 AM, Olof Johansson <olof@lixom.net> wrote: > Add a separate Kconfig option for SAMPLES_SECCOMP. > > Main reason for this is that, just like other samples, it's forced to be a module. > > Without this, since the sample is a target only controlled by > CONFIG_SECCOMP_FILTER, the samples will be built before include files are > put in place properly. For example, from an arm64 allmodconfig built with > "make -sk -j 32" (without specific target), the following happens: > > samples/seccomp/bpf-fancy.c:13:27: fatal error: linux/seccomp.h: No such file or directory > samples/seccomp/bpf-helper.h:20:50: fatal error: linux/seccomp.h: No such file or directory > samples/seccomp/dropper.c:20:27: fatal error: linux/seccomp.h: No such file or directory > samples/seccomp/bpf-direct.c:21:27: fatal error: linux/seccomp.h: No such file or directory Ah-ha! Yes, that's ugly. > So, just stick to the same format as other samples. Agreed, that makes sense to me. > > Signed-off-by: Olof Johansson <olof@lixom.net> > --- > samples/Kconfig | 7 +++++++ > samples/seccomp/Makefile | 2 +- > 2 files changed, 8 insertions(+), 1 deletion(-) > > > Hi Kees, > > This has been showing up for a while on my builder, and I finally had > a bit of time to sit down and look at it. > > It'd be nice to see this in 4.7, but please consider for 4.8 at the least. > > > Thanks! > > -Olof > > diff --git a/samples/Kconfig b/samples/Kconfig > index 559a58b..ccc50be 100644 > --- a/samples/Kconfig > +++ b/samples/Kconfig > @@ -85,4 +85,11 @@ config SAMPLE_CONNECTOR > with it. > See also Documentation/connector/connector.txt > > +config SAMPLE_SECCOMP > + tristate "Build seccomp sample code -- loadable modules only" > + depends on SECCOMP_FILTER && m > + help > + Build samples of seccomp filters using various methods of > + BPF filter construction. > + > endif # SAMPLES > diff --git a/samples/seccomp/Makefile b/samples/seccomp/Makefile > index 1b4e4b8..ae7ff6f 100644 > --- a/samples/seccomp/Makefile > +++ b/samples/seccomp/Makefile > @@ -1,7 +1,7 @@ > # kbuild trick to avoid linker error. Can be omitted if a module is built. > obj- := dummy.o Can the above two lines be dropped now since it'll always be a module? > > -hostprogs-$(CONFIG_SECCOMP_FILTER) := bpf-fancy dropper bpf-direct > +hostprogs-$(CONFIG_SAMPLE_SECCOMP) := bpf-fancy dropper bpf-direct > > HOSTCFLAGS_bpf-fancy.o += -I$(objtree)/usr/include > HOSTCFLAGS_bpf-fancy.o += -idirafter $(objtree)/include > -- > 2.8.0.rc3.29.gb552ff8 > -Kees -- Kees Cook Chrome OS & Brillo Security
[toc] | [prev] | [next] | [standalone]
| From | Olof Johansson <olof@lixom.net> |
|---|---|
| Date | 2016-07-07 19:20 +0200 |
| Message-ID | <rSl7Z-1t6-89@gated-at.bofh.it> |
| In reply to | #1437879 |
Hi, On Wed, Jul 6, 2016 at 10:55 AM, Kees Cook <keescook@chromium.org> wrote: > On Wed, Jul 6, 2016 at 2:53 AM, Olof Johansson <olof@lixom.net> wrote: >> Add a separate Kconfig option for SAMPLES_SECCOMP. >> >> Main reason for this is that, just like other samples, it's forced to be a module. >> >> Without this, since the sample is a target only controlled by >> CONFIG_SECCOMP_FILTER, the samples will be built before include files are >> put in place properly. For example, from an arm64 allmodconfig built with >> "make -sk -j 32" (without specific target), the following happens: >> >> samples/seccomp/bpf-fancy.c:13:27: fatal error: linux/seccomp.h: No such file or directory >> samples/seccomp/bpf-helper.h:20:50: fatal error: linux/seccomp.h: No such file or directory >> samples/seccomp/dropper.c:20:27: fatal error: linux/seccomp.h: No such file or directory >> samples/seccomp/bpf-direct.c:21:27: fatal error: linux/seccomp.h: No such file or directory > > Ah-ha! Yes, that's ugly. > >> So, just stick to the same format as other samples. > > Agreed, that makes sense to me. > >> >> Signed-off-by: Olof Johansson <olof@lixom.net> >> --- >> samples/Kconfig | 7 +++++++ >> samples/seccomp/Makefile | 2 +- >> 2 files changed, 8 insertions(+), 1 deletion(-) >> >> >> Hi Kees, >> >> This has been showing up for a while on my builder, and I finally had >> a bit of time to sit down and look at it. >> >> It'd be nice to see this in 4.7, but please consider for 4.8 at the least. >> >> >> Thanks! >> >> -Olof >> >> diff --git a/samples/Kconfig b/samples/Kconfig >> index 559a58b..ccc50be 100644 >> --- a/samples/Kconfig >> +++ b/samples/Kconfig >> @@ -85,4 +85,11 @@ config SAMPLE_CONNECTOR >> with it. >> See also Documentation/connector/connector.txt >> >> +config SAMPLE_SECCOMP >> + tristate "Build seccomp sample code -- loadable modules only" >> + depends on SECCOMP_FILTER && m >> + help >> + Build samples of seccomp filters using various methods of >> + BPF filter construction. >> + >> endif # SAMPLES >> diff --git a/samples/seccomp/Makefile b/samples/seccomp/Makefile >> index 1b4e4b8..ae7ff6f 100644 >> --- a/samples/seccomp/Makefile >> +++ b/samples/seccomp/Makefile >> @@ -1,7 +1,7 @@ >> # kbuild trick to avoid linker error. Can be omitted if a module is built. >> obj- := dummy.o > > Can the above two lines be dropped now since it'll always be a module? Actually, they can't, since the only other target is a hostprogs one. Still needs a dummy module object file. -Olof
[toc] | [prev] | [next] | [standalone]
| From | Kees Cook <keescook@chromium.org> |
|---|---|
| Date | 2016-07-07 20:00 +0200 |
| Message-ID | <rSlKG-1Il-9@gated-at.bofh.it> |
| In reply to | #1437496 |
On Wed, Jul 6, 2016 at 2:53 AM, Olof Johansson <olof@lixom.net> wrote: > Add a separate Kconfig option for SAMPLES_SECCOMP. > > Main reason for this is that, just like other samples, it's forced to be a module. > > Without this, since the sample is a target only controlled by > CONFIG_SECCOMP_FILTER, the samples will be built before include files are > put in place properly. For example, from an arm64 allmodconfig built with > "make -sk -j 32" (without specific target), the following happens: > > samples/seccomp/bpf-fancy.c:13:27: fatal error: linux/seccomp.h: No such file or directory > samples/seccomp/bpf-helper.h:20:50: fatal error: linux/seccomp.h: No such file or directory > samples/seccomp/dropper.c:20:27: fatal error: linux/seccomp.h: No such file or directory > samples/seccomp/bpf-direct.c:21:27: fatal error: linux/seccomp.h: No such file or directory > > So, just stick to the same format as other samples. > > Signed-off-by: Olof Johansson <olof@lixom.net> > --- > samples/Kconfig | 7 +++++++ > samples/seccomp/Makefile | 2 +- > 2 files changed, 8 insertions(+), 1 deletion(-) > > > Hi Kees, > > This has been showing up for a while on my builder, and I finally had > a bit of time to sit down and look at it. > > It'd be nice to see this in 4.7, but please consider for 4.8 at the least. I feel like we're too late in 4.7, but I've applied this for 4.8. Thanks for tracking it down! -Kees > > > Thanks! > > -Olof > > diff --git a/samples/Kconfig b/samples/Kconfig > index 559a58b..ccc50be 100644 > --- a/samples/Kconfig > +++ b/samples/Kconfig > @@ -85,4 +85,11 @@ config SAMPLE_CONNECTOR > with it. > See also Documentation/connector/connector.txt > > +config SAMPLE_SECCOMP > + tristate "Build seccomp sample code -- loadable modules only" > + depends on SECCOMP_FILTER && m > + help > + Build samples of seccomp filters using various methods of > + BPF filter construction. > + > endif # SAMPLES > diff --git a/samples/seccomp/Makefile b/samples/seccomp/Makefile > index 1b4e4b8..ae7ff6f 100644 > --- a/samples/seccomp/Makefile > +++ b/samples/seccomp/Makefile > @@ -1,7 +1,7 @@ > # kbuild trick to avoid linker error. Can be omitted if a module is built. > obj- := dummy.o > > -hostprogs-$(CONFIG_SECCOMP_FILTER) := bpf-fancy dropper bpf-direct > +hostprogs-$(CONFIG_SAMPLE_SECCOMP) := bpf-fancy dropper bpf-direct > > HOSTCFLAGS_bpf-fancy.o += -I$(objtree)/usr/include > HOSTCFLAGS_bpf-fancy.o += -idirafter $(objtree)/include > -- > 2.8.0.rc3.29.gb552ff8 > -- Kees Cook Chrome OS & Brillo Security
[toc] | [prev] | [standalone]
Back to top | Article view | linux.kernel
csiph-web