Tycho Andersen
f8e529ed94
seccomp, ptrace: add support for dumping seccomp filters
...
This patch adds support for dumping a process' (classic BPF) seccomp
filters via ptrace.
PTRACE_SECCOMP_GET_FILTER allows the tracer to dump the user's classic BPF
seccomp filters. addr should be an integer which represents the ith seccomp
filter (0 is the most recently installed filter). data should be a struct
sock_filter * with enough room for the ith filter, or NULL, in which case
the filter is not saved. The return value for this command is the number of
BPF instructions the program represents, or negative in the case of errors.
Command specific errors are ENOENT: which indicates that there is no ith
filter in this seccomp tree, and EMEDIUMTYPE, which indicates that the ith
filter was not installed as a classic BPF filter.
A caveat with this approach is that there is no way to get explicitly at
the heirarchy of seccomp filters, and users need to memcmp() filters to
decide which are inherited. This means that a task which installs two of
the same filter can potentially confuse users of this interface.
v2: * make save_orig const
* check that the orig_prog exists (not necessary right now, but when
grows eBPF support it will be)
* s/n/filter_off and make it an unsigned long to match ptrace
* count "down" the tree instead of "up" when passing a filter offset
v3: * don't take the current task's lock for inspecting its seccomp mode
* use a 0x42** constant for the ptrace command value
v4: * don't copy to userspace while holding spinlocks
v5: * add another condition to WARN_ON
v6: * rebase on net-next
Signed-off-by: Tycho Andersen <tycho.andersen@canonical.com>
Acked-by: Kees Cook <keescook@chromium.org>
CC: Will Drewry <wad@chromium.org>
Reviewed-by: Oleg Nesterov <oleg@redhat.com>
CC: Andy Lutomirski <luto@amacapital.net>
CC: Pavel Emelyanov <xemul@parallels.com>
CC: Serge E. Hallyn <serge.hallyn@ubuntu.com>
CC: Alexei Starovoitov <ast@kernel.org>
CC: Daniel Borkmann <daniel@iogearbox.net>
Acked-by: Alexei Starovoitov <ast@kernel.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
2015-10-27 19:55:13 -07:00
..
bpf
bpf: fix bpf_perf_event_read() helper
2015-10-26 21:49:26 -07:00
configs
kconfig: add xenconfig defconfig helper
2015-06-16 11:04:29 +01:00
debug
events
perf: pad raw data samples automatically
2015-10-22 06:42:13 -07:00
gcov
gcov: add support for GCC 5.1
2015-06-30 19:44:57 -07:00
irq
Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net
2015-10-20 06:08:27 -07:00
livepatch
livepatch: Improve error handling in klp_disable_func()
2015-07-14 22:48:06 +02:00
locking
locking/lockdep: Fix hlock->pin_count reset on lock stack rebuilds
2015-09-23 09:48:53 +02:00
power
Merge branch 'for-4.3/core' of git://git.kernel.dk/linux-block
2015-09-02 13:10:25 -07:00
printk
kexec: split kexec_load syscall from kexec core code
2015-09-10 13:29:01 -07:00
rcu
rcu: Suppress lockdep false positive for rcp->exp_funnel_mutex
2015-09-20 21:01:22 -07:00
sched
sched/core: Fix TASK_DEAD race in finish_task_switch()
2015-10-06 17:05:17 +02:00
time
timekeeping: Increment clock_was_set_seq in timekeeping_init()
2015-10-16 15:50:22 +02:00
trace
bpf: make tracing helpers gpl only
2015-10-26 21:53:34 -07:00
.gitignore
acct.c
async.c
audit.c
Merge branch 'upstream' of git://git.infradead.org/users/pcmoore/audit
2015-09-08 13:34:59 -07:00
audit.h
Merge branch 'upstream' of git://git.infradead.org/users/pcmoore/audit
2015-09-08 13:34:59 -07:00
audit_fsnotify.c
audit: clean simple fsnotify implementation
2015-08-06 16:14:53 -04:00
audit_tree.c
Merge branch 'upstream' of git://git.infradead.org/users/pcmoore/audit
2015-09-08 13:34:59 -07:00
audit_watch.c
Merge branch 'upstream' of git://git.infradead.org/users/pcmoore/audit
2015-09-08 13:34:59 -07:00
auditfilter.c
audit: implement audit by executable
2015-08-06 16:17:25 -04:00
auditsc.c
Merge branch 'upstream' of git://git.infradead.org/users/pcmoore/audit
2015-09-08 13:34:59 -07:00
backtracetest.c
bounds.c
capability.c
cgroup.c
Revert "sched, cgroup: replace signal_struct->group_rwsem with a global percpu_rwsem"
2015-09-16 11:51:12 -04:00
cgroup_freezer.c
cgroup: allow a cgroup subsystem to reject a fork
2015-07-14 17:29:23 -04:00
cgroup_pids.c
cgroup: pids: fix invalid get/put usage
2015-08-25 14:19:25 -04:00
compat.c
compat: cleanup coding in compat_get_bitmap() and compat_put_bitmap()
2015-06-04 23:57:18 +02:00
configs.c
context_tracking.c
cpu.c
Merge branch 'sched-core-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
2015-08-31 20:26:22 -07:00
cpu_pm.c
kernel/cpu_pm: fix cpu_cluster_pm_exit comment
2015-09-03 02:42:20 +02:00
cpuset.c
cpuset: use trialcs->mems_allowed as a temp variable
2015-08-10 11:18:41 -04:00
crash_dump.c
cred.c
kernel/cred.c: remove unnecessary kdebug atomic reads
2015-09-10 13:29:01 -07:00
delayacct.c
dma.c
elfcore.c
exec_domain.c
exit.c
kernel: exit: fix typo in comment
2015-08-07 13:59:49 +02:00
extable.c
kernel/extable.c: remove duplicated include
2015-09-10 13:29:01 -07:00
fork.c
Revert "sched, cgroup: replace signal_struct->group_rwsem with a global percpu_rwsem"
2015-09-16 11:51:12 -04:00
freezer.c
futex.c
futex: Make should_fail_futex() static
2015-07-20 21:43:54 +02:00
futex_compat.c
groups.c
hung_task.c
irq_work.c
jump_label.c
locking/static_keys: Add selftest
2015-08-03 11:34:16 +02:00
kallsyms.c
kcmp.c
Kconfig.freezer
Kconfig.hz
Kconfig.locks
Kconfig.preempt
kexec.c
kexec: split kexec_load syscall from kexec core code
2015-09-10 13:29:01 -07:00
kexec_core.c
kexec: export KERNEL_IMAGE_SIZE to vmcoreinfo
2015-09-10 13:29:01 -07:00
kexec_file.c
kexec: split kexec_file syscall code to kexec_file.c
2015-09-10 13:29:01 -07:00
kexec_internal.h
kexec: split kexec_file syscall code to kexec_file.c
2015-09-10 13:29:01 -07:00
kmod.c
kmod: handle UMH_WAIT_PROC from system unbound workqueue
2015-09-10 13:29:01 -07:00
kprobes.c
perf/x86/hw_breakpoints: Disallow kernel breakpoints unless kprobe-safe
2015-08-04 10:16:54 +02:00
ksysfs.c
kexec: split kexec_load syscall from kexec core code
2015-09-10 13:29:01 -07:00
kthread.c
kernel/kthread.c:kthread_create_on_node(): clarify documentation
2015-09-04 16:54:41 -07:00
latencytop.c
Makefile
sys_membarrier(): system-wide memory barrier (generic, x86)
2015-09-11 15:21:34 -07:00
membarrier.c
sys_membarrier(): system-wide memory barrier (generic, x86)
2015-09-11 15:21:34 -07:00
memremap.c
add devm_memremap_pages
2015-08-27 19:40:58 -04:00
module-internal.h
module.c
module: weaken locking assertion for oops path.
2015-07-29 06:13:22 +09:30
module_signing.c
PKCS#7: Appropriately restrict authenticated attributes and content type
2015-08-12 17:01:01 +01:00
notifier.c
Merge branch 'x86-asm-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
2015-09-01 08:40:25 -07:00
nsproxy.c
padata.c
panic.c
kernel/panic/kexec: fix "crash_kexec_post_notifiers" option issue in oops path
2015-06-30 19:44:57 -07:00
params.c
Minor merge needed, due to function move.
2015-07-01 10:49:25 -07:00
pid.c
rcu: Rename rcu_lockdep_assert() to RCU_LOCKDEP_WARN()
2015-07-22 15:27:32 -07:00
pid_namespace.c
profile.c
mm: rename alloc_pages_exact_node() to __alloc_pages_node()
2015-09-08 15:35:28 -07:00
ptrace.c
seccomp, ptrace: add support for dumping seccomp filters
2015-10-27 19:55:13 -07:00
range.c
reboot.c
kexec: split kexec_load syscall from kexec core code
2015-09-10 13:29:01 -07:00
relay.c
kernel/relay.c: use kvfree() in relay_free_page_array()
2015-06-30 19:44:59 -07:00
resource.c
mm: enhance region_is_ram() to region_intersects()
2015-08-10 23:07:05 -04:00
seccomp.c
seccomp, ptrace: add support for dumping seccomp filters
2015-10-27 19:55:13 -07:00
signal.c
signal: fix information leak in copy_siginfo_to_user
2015-08-07 04:39:40 +03:00
smp.c
smpboot.c
smpboot: allow passing the cpumask on per-cpu thread registration
2015-09-04 16:54:41 -07:00
smpboot.h
softirq.c
stacktrace.c
stop_machine.c
stop_machine: Remove cpu_stop_work's from list in cpu_stop_park()
2015-08-03 12:21:28 +02:00
sys.c
vfs: Commit to never having exectuables on proc and sysfs.
2015-07-10 10:39:25 -05:00
sys_ni.c
sys_membarrier(): system-wide memory barrier (generic, x86)
2015-09-11 15:21:34 -07:00
sysctl.c
bpf: enable non-root eBPF programs
2015-10-12 19:13:35 -07:00
sysctl_binary.c
task_work.c
task_work: remove fifo ordering guarantee
2015-09-05 13:46:58 -07:00
taskstats.c
test_kprobes.c
torture.c
rcu: Convert ACCESS_ONCE() to READ_ONCE() and WRITE_ONCE()
2015-05-27 12:56:15 -07:00
tracepoint.c
tsacct.c
uid16.c
up.c
user-return-notifier.c
user.c
user_namespace.c
capabilities: ambient capabilities
2015-09-04 16:54:41 -07:00
utsname.c
utsname_sysctl.c
watchdog.c
watchdog: rename watchdog_suspend() and watchdog_resume()
2015-09-04 16:54:41 -07:00
workqueue.c
workqueue: make sure delayed work run in local cpu
2015-09-30 13:06:46 -04:00
workqueue_internal.h