Re: [PATCH] seccomp: plug syscall-dodging ptrace hole

From: Andy Lutomirski
Date: Fri May 27 2016 - 16:15:04 EST

On Fri, May 27, 2016 at 12:52 PM, Andy Lutomirski <luto@xxxxxxxxxxxxxx> wrote:
>> Right, I know, it's aesthetically much nicer that way, but I really
>> want to stay totally paranoid and keep seccomp absolutely first on the
>> path.
>> How about this: we'll use this patch as-is for now, since I'd like to
>> be able to start getting feedback from the container-using folks ASAP,
>> and then we can redesign the 2-phase system going forward from there.
> I think I'd rather change the ABI as few times as possible. On the
> other hand, it's still early, and I see nothing wrong with adding it
> to -next.

To get the ball rolling:

It's incomplete, but it should be straightforward to finish it. The
only interesting bit is dealing with SECCOMP_RET_TRACE.