Re: ARM audit, seccomp, etc are broken wrt OABI syscalls

From: Henrique de Moraes Holschuh
Date: Thu Nov 07 2013 - 14:04:59 EST

On Thu, 07 Nov 2013, Kees Cook wrote:
> On Thu, Nov 7, 2013 at 4:55 AM, Henrique de Moraes Holschuh
> <hmh@xxxxxxxxxx> wrote:
> > On Tue, 05 Nov 2013, Andy Lutomirski wrote:
> >> Maybe the thing to do is to put a warning in the config text for
> >> CONFIG_OABI_COMPAT that describes the problems (malicious userspace
> >> can confuse syscall auditors, strace, etc.), change the "if in doubt"
> >> part to N, and disable seccomp filters if CONFIG_OABI_COMPAT. That
> >> might even get Debian to change their default.
> >
> > Bug reported to the Debian BTS: #728975
> >
> FWIW, Ubuntu has also now disabled OABI_COMPAT going forward:

Unless something very weird happens, it looks like that's also what Debian
will do.

"One disk to rule them all, One disk to find them. One disk to bring
them all and in the darkness grind them. In the Land of Redmond
where the shadows lie." -- The Silicon Valley Tarot
Henrique Holschuh
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at
Please read the FAQ at