mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* seccomp vs ptrace
@ 2015-03-18 21:30 Serge E. Hallyn
  2015-03-18 21:38 ` Kees Cook
  2015-03-18 21:39 ` Andy Lutomirski
  0 siblings, 2 replies; 6+ messages in thread
From: Serge E. Hallyn @ 2015-03-18 21:30 UTC (permalink / raw)
  To: lkml, Kees Cook, Andy Lutomirski, stgraber

Hi,

I'm writing to ask about

        The seccomp check will not be run again after the tracer is
        notified.  (This means that seccomp-based sandboxes MUST NOT
        allow use of ptrace, even of other sandboxed processes, without
        extreme care; ptracers can use this mechanism to escape.)

This basically means that seccomp cannot be safely used with for instance
an upstart based container.  I've been told that Andy was working on
changing the order so that ptrace checks would be done before seccomp.
Is there any update on that?  Is it likely to happen?  Scrapped?

thanks,
-serge

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2015-03-18 22:06 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2015-03-18 21:30 seccomp vs ptrace Serge E. Hallyn
2015-03-18 21:38 ` Kees Cook
2015-03-18 21:42   ` Andy Lutomirski
2015-03-18 21:44     ` Kees Cook
2015-03-18 22:06       ` Andy Lutomirski
2015-03-18 21:39 ` Andy Lutomirski

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®