diff options
| author | Ophestra <cat@gensokyo.uk> | 2026-10-01 22:34:51 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2026-10-02 16:23:46 +0900 |
| commit | 2e2107a05c18db67b2a32c6e9191b8fd97afa70b (patch) | |
| tree | 687cda8681bec98a638369be0b8bf1a2b0418147 /test/sandbox/seccomp.patch | |
| parent | 4b19686109b0962ea68dfe58feafffe3bac9c202 (diff) | |
test/sandbox: migrate tests
This benefits even more than the cmd/sharefs test suite, the slow
python-based test script was a major bottleneck. Replacing the
nix-represented test cases with compound literals also significantly
increases readability.
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'test/sandbox/seccomp.patch')
| -rw-r--r-- | test/sandbox/seccomp.patch | 18 |
1 files changed, 18 insertions, 0 deletions
diff --git a/test/sandbox/seccomp.patch b/test/sandbox/seccomp.patch new file mode 100644 index 00000000..1f359b19 --- /dev/null +++ b/test/sandbox/seccomp.patch @@ -0,0 +1,18 @@ +diff --git a/kernel/seccomp.c b/kernel/seccomp.c +index 25f62867a16d..a0d34dc05aa5 100644 +--- a/kernel/seccomp.c ++++ b/kernel/seccomp.c +@@ -2216,8 +2216,12 @@ long seccomp_get_filter(struct task_struct *task, unsigned long filter_off, + struct seccomp_filter *filter; + struct sock_fprog_kern *fprog; + long ret; ++ struct user_namespace *user_ns = current_user_ns(); + +- if (!capable(CAP_SYS_ADMIN) || ++ if (task_cred_xxx(task, user_ns) == user_ns) { ++ if (!ns_capable(user_ns, CAP_SYS_ADMIN)) ++ return -EACCES; ++ } else if (!capable(CAP_SYS_ADMIN) || + current->seccomp.mode != SECCOMP_MODE_DISABLED) { + return -EACCES; + } |
