From: takahiro.akashi@linaro.org (AKASHI Takahiro)
To: linux-arm-kernel@lists.infradead.org
Subject: [PATCH v2 2/3] arm64: Add seccomp support
Date: Thu, 06 Mar 2014 11:34:46 +0900 [thread overview]
Message-ID: <5317DEC6.4060103@linaro.org> (raw)
In-Reply-To: <20140228172006.GF30996@mudshark.cambridge.arm.com>
On 03/01/2014 02:20 AM, Will Deacon wrote:
> On Tue, Feb 25, 2014 at 09:20:24AM +0000, AKASHI Takahiro wrote:
>> secure_computing() should always be called first in syscall_trace(), and
>> if it returns non-zero, we should stop further handling. Then that system
>> call may eventually fail, be trapped or the process itself be killed
>> depending on loaded rules.
>
> [...]
>
>> diff --git a/arch/arm64/kernel/ptrace.c b/arch/arm64/kernel/ptrace.c
>> index d4ce70e..f2a74bc 100644
>> --- a/arch/arm64/kernel/ptrace.c
>> +++ b/arch/arm64/kernel/ptrace.c
>> @@ -20,12 +20,14 @@
>> */
>>
>> #include <linux/audit.h>
>> +#include <linux/errno.h>
>> #include <linux/kernel.h>
>> #include <linux/sched.h>
>> #include <linux/mm.h>
>> #include <linux/smp.h>
>> #include <linux/ptrace.h>
>> #include <linux/user.h>
>> +#include <linux/seccomp.h>
>> #include <linux/security.h>
>> #include <linux/init.h>
>> #include <linux/signal.h>
>> @@ -1064,6 +1066,10 @@ asmlinkage int syscall_trace(int dir, struct pt_regs *regs)
>> {
>> unsigned long saved_reg;
>>
>> + if (!dir && secure_computing((int)regs->syscallno))
>
> Why do you need this cast to (int)?
OK. I will remove it because gcc doesn't complain about it anyway.
> Also, it's probably better to check for
> -1 explicitly here.
I wil fix it.
> I'm slightly surprised that we do the secure computing check first. Doesn't
> this allow a debugger to change the syscall to something else after we've
> decided that it's ok?
To be honest, I just followed other architectures' implementation.
Can you elaborate any use case that you have in your mind?
-Takahiro AKASHI
> Will
>
next prev parent reply other threads:[~2014-03-06 2:34 UTC|newest]
Thread overview: 30+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-02-07 10:11 [PATCH 0/2] arm64: Add seccomp support AKASHI Takahiro
2014-02-07 10:11 ` [PATCH 1/2] " AKASHI Takahiro
2014-02-07 14:44 ` Arnd Bergmann
[not found] ` <CAB5YjtB6XnXRd90AUw=rJCOBKyfcngTQd3Kxft33XLCK+K=Vuw@mail.gmail.com>
2014-02-12 11:05 ` Arnd Bergmann
2014-02-12 11:17 ` Arnd Bergmann
2014-02-18 15:38 ` Catalin Marinas
2014-02-19 11:39 ` AKASHI Takahiro
2014-02-19 16:41 ` Catalin Marinas
2014-02-20 0:34 ` AKASHI Takahiro
2014-02-07 10:11 ` [PATCH 2/2] arm64: is_compat_task is defined both in asm/compat.h and linux/compat.h AKASHI Takahiro
2014-02-17 19:32 ` Will Deacon
2014-02-19 11:16 ` AKASHI Takahiro
2014-02-25 9:20 ` [PATCH v2 0/3] arm64: Add seccomp support AKASHI Takahiro
2014-02-25 9:20 ` [PATCH v2 1/3] asm-generic: Add generic seccomp.h for secure computing mode 1 AKASHI Takahiro
2014-02-25 9:20 ` [PATCH v2 2/3] arm64: Add seccomp support AKASHI Takahiro
2014-02-28 17:20 ` Will Deacon
2014-03-06 2:34 ` AKASHI Takahiro [this message]
2014-03-06 15:24 ` Will Deacon
2014-02-25 9:20 ` [PATCH v2 3/3] arm64: is_compat_task is defined both in asm/compat.h and linux/compat.h AKASHI Takahiro
2014-02-28 16:58 ` Will Deacon
2014-03-13 10:17 ` [PATCH v3 0/3] arm64: Add seccomp support AKASHI Takahiro
2014-03-13 10:17 ` [PATCH v3 1/3] asm-generic: Add generic seccomp.h for secure computing mode 1 AKASHI Takahiro
2014-03-14 17:08 ` Catalin Marinas
2014-03-13 10:17 ` [PATCH v3 2/3] arm64: Add seccomp support AKASHI Takahiro
2014-03-13 10:17 ` [PATCH v3 3/3] arm64: is_compat_task is defined both in asm/compat.h and linux/compat.h AKASHI Takahiro
2014-03-15 5:50 ` [PATCH_v4 0/2] arm64: Add seccomp support AKASHI Takahiro
2014-03-15 5:50 ` [PATCH_v4 1/2] asm-generic: Add generic seccomp.h for secure computing mode 1 AKASHI Takahiro
2014-03-15 5:50 ` [PATCH_v4 2/2] arm64: Add seccomp support AKASHI Takahiro
2014-06-25 14:53 ` [PATCH_v4 0/2] " Mark Salter
2014-06-26 0:57 ` AKASHI Takahiro
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=5317DEC6.4060103@linaro.org \
--to=takahiro.akashi@linaro.org \
--cc=linux-arm-kernel@lists.infradead.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).