Re: [PATCH] selftests/seccomp: Handle namespace failures gracefully

From: Tycho Andersen
Date: Fri Apr 12 2019 - 11:25:49 EST


On Thu, Apr 11, 2019 at 04:56:31PM -0700, Kees Cook wrote:
> When running without USERNS or PIDNS the seccomp test would hang since
> it was waiting forever for the child to trigger the user notification
> since it seems the glibc() abort handler makes a call to getpid(),
> which would trap again. This changes the getpid filter to getppid, and
> makes sure ASSERTs execute to stop from spawning the listener.
>
> Reported-by: Shuah Khan <shuah@xxxxxxxxxx>
> Fixes: 6a21cc50f0c7 ("seccomp: add a return code to trap to userspace")
> Signed-off-by: Kees Cook <keescook@xxxxxxxxxxxx>

Sorry for the delay, thanks for looking at this!

Reviewed-by: Tycho Andersen <tycho@xxxxxxxx>