From: "Daniel P. Berrange" <berrange@redhat.com>
To: Eduardo Otubo <otubo@redhat.com>
Cc: pbonzini@redhat.com, thuth@redhat.com, qemu-devel@nongnu.org
Subject: Re: [Qemu-devel] [PATCH v3 2/6] seccomp: add obsolete argument to command line
Date: Wed, 2 Aug 2017 13:38:58 +0100 [thread overview]
Message-ID: <20170802123858.GK4098@redhat.com> (raw)
In-Reply-To: <20170802123356.GI4098@redhat.com>
On Wed, Aug 02, 2017 at 01:33:56PM +0100, Daniel P. Berrange wrote:
> On Fri, Jul 28, 2017 at 02:10:36PM +0200, Eduardo Otubo wrote:
> > This patch introduces the argument [,obsolete=allow] to the `-sandbox on'
> > option. It allows Qemu to run safely on old system that still relies on
> > old system calls.
> >
> > Signed-off-by: Eduardo Otubo <otubo@redhat.com>
> > ---
> > include/sysemu/seccomp.h | 4 +++-
> > qemu-options.hx | 9 +++++++--
> > qemu-seccomp.c | 32 +++++++++++++++++++++++++++++++-
> > vl.c | 16 +++++++++++++++-
> > 4 files changed, 56 insertions(+), 5 deletions(-)
> > @@ -1032,7 +1036,17 @@ static int parse_sandbox(void *opaque, QemuOpts *opts, Error **errp)
> > {
> > if (qemu_opt_get_bool(opts, "enable", false)) {
> > #ifdef CONFIG_SECCOMP
> > - if (seccomp_start() < 0) {
> > + uint8_t seccomp_opts = 0x0000;
> > + const char *value = NULL;
> > +
> > + value = qemu_opt_get(opts, "obsolete");
> > + if (value) {
> > + if (strcmp(value, "allow") == 0) {
> > + seccomp_opts |= OBSOLETE;
> > + }
> > + }
>
> IIUC, the values will all be booleans, so we should just use
>
> if (qemu_opt_get_bool(opts, "obsolete", false))
> seccomp_opts |= OBSOLETE;
Oh ignore this. I see from the next patch, we can't treat it as a boolean.
We should however explicitly look for 'value == deny', and then reject
all other values with an error message
>
> > +
> > + if (seccomp_start(seccomp_opts) < 0) {
> > error_report("failed to install seccomp syscall filter "
> > "in the kernel");
> > return -1;
Regards,
Daniel
--
|: https://berrange.com -o- https://www.flickr.com/photos/dberrange :|
|: https://libvirt.org -o- https://fstop138.berrange.com :|
|: https://entangle-photo.org -o- https://www.instagram.com/dberrange :|
next prev parent reply other threads:[~2017-08-02 12:39 UTC|newest]
Thread overview: 20+ messages / expand[flat|nested] mbox.gz Atom feed top
2017-07-28 12:10 [Qemu-devel] [PATCH v3 0/6] seccomp: feature refactoring Eduardo Otubo
2017-07-28 12:10 ` [Qemu-devel] [PATCH v3 1/6] seccomp: changing from whitelist to blacklist Eduardo Otubo
2017-08-02 12:25 ` Daniel P. Berrange
2017-08-03 16:54 ` Thomas Huth
2017-08-11 9:51 ` Eduardo Otubo
2017-08-11 10:10 ` Daniel P. Berrange
2017-07-28 12:10 ` [Qemu-devel] [PATCH v3 2/6] seccomp: add obsolete argument to command line Eduardo Otubo
2017-08-02 12:33 ` Daniel P. Berrange
2017-08-02 12:38 ` Daniel P. Berrange [this message]
2017-08-11 9:12 ` Eduardo Otubo
2017-08-11 9:25 ` Daniel P. Berrange
2017-08-11 9:49 ` Eduardo Otubo
2017-07-28 12:10 ` [Qemu-devel] [PATCH v3 3/6] seccomp: add elevateprivileges " Eduardo Otubo
2017-08-02 12:37 ` Daniel P. Berrange
2017-08-03 16:59 ` Thomas Huth
2017-07-28 12:10 ` [Qemu-devel] [PATCH v3 4/6] seccomp: add spawn " Eduardo Otubo
2017-07-28 12:10 ` [Qemu-devel] [PATCH v3 5/6] seccomp: add resourcecontrol " Eduardo Otubo
2017-07-28 12:10 ` [Qemu-devel] [PATCH v3 6/6] seccomp: adding documentation to new seccomp model Eduardo Otubo
2017-08-02 12:39 ` Daniel P. Berrange
2017-08-03 17:14 ` Thomas Huth
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20170802123858.GK4098@redhat.com \
--to=berrange@redhat.com \
--cc=otubo@redhat.com \
--cc=pbonzini@redhat.com \
--cc=qemu-devel@nongnu.org \
--cc=thuth@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.