commit | 93e35efb8de45393cf61ed07f7b407629bf698ea | [log] [tgz] |
---|---|---|
author | Kees Cook <keescook@chromium.org> | Thu Jun 09 12:36:50 2016 -0700 |
committer | Kees Cook <keescook@chromium.org> | Tue Jun 14 10:54:41 2016 -0700 |
tree | 862d7e65445f7c7a53025fbfc097eb9e4f363715 | |
parent | ce6526e8afa4b6ad0ab134a4cc50c9c863319637 [diff] |
x86/ptrace: run seccomp after ptrace This moves seccomp after ptrace on x86 to that seccomp can catch changes made by ptrace. Emulation should skip the rest of processing too. We can get rid of test_thread_flag because there's no longer any opportunity for seccomp to mess with ptrace state before invoking ptrace. Suggested-by: Andy Lutomirski <luto@kernel.org> Signed-off-by: Kees Cook <keescook@chromium.org> Cc: x86@kernel.org Cc: Andy Lutomirski <luto@kernel.org>