From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:44273) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1VThq1-0005Wo-HV for qemu-devel@nongnu.org; Tue, 08 Oct 2013 20:41:26 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1VThps-0007ky-Gx for qemu-devel@nongnu.org; Tue, 08 Oct 2013 20:41:17 -0400 Received: from e24smtp02.br.ibm.com ([32.104.18.86]:53147) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1VThps-0007ae-2q for qemu-devel@nongnu.org; Tue, 08 Oct 2013 20:41:08 -0400 Received: from /spool/local by e24smtp02.br.ibm.com with IBM ESMTP SMTP Gateway: Authorized Use Only! Violators will be prosecuted for from ; Tue, 8 Oct 2013 21:41:02 -0300 Received: from d24relay03.br.ibm.com (d24relay03.br.ibm.com [9.13.184.25]) by d24dlp01.br.ibm.com (Postfix) with ESMTP id 4FF613520060 for ; Tue, 8 Oct 2013 20:40:59 -0400 (EDT) Received: from d24av04.br.ibm.com (d24av04.br.ibm.com [9.8.31.97]) by d24relay03.br.ibm.com (8.13.8/8.13.8/NCO v10.0) with ESMTP id r990dJn151839198 for ; Tue, 8 Oct 2013 21:39:20 -0300 Received: from d24av04.br.ibm.com (localhost [127.0.0.1]) by d24av04.br.ibm.com (8.14.4/8.14.4/NCO v10.0 AVout) with ESMTP id r990ewnW022714 for ; Tue, 8 Oct 2013 21:40:58 -0300 Message-ID: <5254A619.3040907@linux.vnet.ibm.com> Date: Tue, 08 Oct 2013 21:40:57 -0300 From: Eduardo Otubo MIME-Version: 1.0 References: <1378495308-24560-1-git-send-email-otubo@linux.vnet.ibm.com> <1378495308-24560-4-git-send-email-otubo@linux.vnet.ibm.com> <5230A0A8.2000205@linux.vnet.ibm.com> In-Reply-To: <5230A0A8.2000205@linux.vnet.ibm.com> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Subject: Re: [Qemu-devel] [PATCHv3 3/3] seccomp: general fixes List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Corey Bryant Cc: pmoore@redhat.com, qemu-devel@nongnu.org On 09/11/2013 01:56 PM, Corey Bryant wrote: > > > On 09/06/2013 03:21 PM, Eduardo Otubo wrote: >> 1) On qemu-seccomp.c:255, the variable ctx was being used >> uninitialized; now it's initialized with NULL and it's being checked at >> the end of the function. >> >> 2) Changed the name of the command line option from "enable" to >> "sandbox" for a better understanding from user side. >> >> Signed-off-by: Eduardo Otubo >> --- >> qemu-seccomp.c | 5 +++-- >> vl.c | 6 +++--- >> 2 files changed, 6 insertions(+), 5 deletions(-) >> >> diff --git a/qemu-seccomp.c b/qemu-seccomp.c >> index 5e85eb5..f39d636 100644 >> --- a/qemu-seccomp.c >> +++ b/qemu-seccomp.c >> @@ -252,7 +252,7 @@ seccomp_return: >> int seccomp_start(int list_type) >> { >> int rc = 0; >> - scmp_filter_ctx ctx; >> + scmp_filter_ctx ctx = NULL; >> >> switch (list_type) { >> case WHITELIST: >> @@ -280,6 +280,7 @@ int seccomp_start(int list_type) >> rc = seccomp_load(ctx); >> >> seccomp_return: >> - seccomp_release(ctx); >> + if (!ctx) > > You need to remove the ! from this check. > >> + seccomp_release(ctx); >> return rc; >> } >> diff --git a/vl.c b/vl.c >> index 909f685..129919d 100644 >> --- a/vl.c >> +++ b/vl.c >> @@ -323,11 +323,11 @@ static QemuOptsList qemu_rtc_opts = { >> >> static QemuOptsList qemu_sandbox_opts = { >> .name = "sandbox", >> - .implied_opt_name = "enable", >> + .implied_opt_name = "sandbox", > > So does this technically make it -sandbox,sandbox=on?If I understand No. Qemu command line options is a little tricky and I had to spent some time to understand it. It actually make "-sandbox on,strict=on" > correctly, I don't think the implied option is ever seen or used by the > user anyway so it probably doesn't matter. But I don't know if it's > worth changing. I changed the name so I can remember how it works in the future, since it's not that trivial. > >> .head = QTAILQ_HEAD_INITIALIZER(qemu_sandbox_opts.head), >> .desc = { >> { >> - .name = "enable", >> + .name = "sandbox", >> .type = QEMU_OPT_BOOL, >> },{ >> .name = "strict", >> @@ -1036,7 +1036,7 @@ static int parse_sandbox(QemuOpts *opts, void >> *opaque) >> { >> const char * strict_value = NULL; >> /* FIXME: change this to true for 1.3 */ >> - if (qemu_opt_get_bool(opts, "enable", false)) { >> + if (qemu_opt_get_bool(opts, "sandbox", false)) { >> #ifdef CONFIG_SECCOMP >> if (seccomp_start(WHITELIST) < 0) { >> qerror_report(ERROR_CLASS_GENERIC_ERROR, >> -- 1.8.3.1 >> > -- Eduardo Otubo IBM Linux Technology Center