commit | ce6526e8afa4b6ad0ab134a4cc50c9c863319637 | [log] [tgz] |
---|---|---|
author | Kees Cook <keescook@chromium.org> | Wed Jun 01 19:29:15 2016 -0700 |
committer | Kees Cook <keescook@chromium.org> | Tue Jun 14 10:54:41 2016 -0700 |
tree | c3074e4661ee9432faf518fd2eef8527c5811730 | |
parent | 8112c4f140fa03f9ee68aad2cc79afa7df5418d3 [diff] |
seccomp: recheck the syscall after RET_TRACE When RET_TRACE triggers, a tracer may change a syscall into something that should be filtered by seccomp. This re-runs seccomp after a trace event to make sure things continue to pass. Signed-off-by: Kees Cook <keescook@chromium.org> Cc: Andy Lutomirski <luto@kernel.org>