aboutsummaryrefslogtreecommitdiffhomepage
path: root/test/sandbox/seccomp.patch
diff options
context:
space:
mode:
authorOphestra <cat@gensokyo.uk>2026-10-01 22:34:51 +0900
committerOphestra <cat@gensokyo.uk>2026-10-02 19:05:34 +0900
commite332ef1e2549eaa6702d07fac77d9ad206bf4f4c (patch)
treea5dbcd8bd1649da392869539c95c9ba6ae1a2919 /test/sandbox/seccomp.patch
parent4b19686109b0962ea68dfe58feafffe3bac9c202 (diff)
test/sandbox: migrate tests
This benefits even more than the cmd/sharefs test suite, the slow python-based test script was a major bottleneck. Replacing the nix-represented test cases with compound literals also significantly increases readability. Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'test/sandbox/seccomp.patch')
-rw-r--r--test/sandbox/seccomp.patch18
1 files changed, 18 insertions, 0 deletions
diff --git a/test/sandbox/seccomp.patch b/test/sandbox/seccomp.patch
new file mode 100644
index 00000000..ddabc71e
--- /dev/null
+++ b/test/sandbox/seccomp.patch
@@ -0,0 +1,18 @@
+diff --git a/kernel/seccomp.c b/kernel/seccomp.c
+index 25f62867a16d..7b63ccc8daf4 100644
+--- a/kernel/seccomp.c
++++ b/kernel/seccomp.c
+@@ -2216,8 +2216,12 @@ long seccomp_get_filter(struct task_struct *task, unsigned long filter_off,
+ struct seccomp_filter *filter;
+ struct sock_fprog_kern *fprog;
+ long ret;
++ struct user_namespace *user_ns = current_user_ns();
+
+- if (!capable(CAP_SYS_ADMIN) ||
++ if (in_userns(user_ns, task_cred_xxx(task, user_ns))) {
++ if (!ns_capable(user_ns, CAP_SYS_ADMIN))
++ return -EACCES;
++ } else if (!capable(CAP_SYS_ADMIN) ||
+ current->seccomp.mode != SECCOMP_MODE_DISABLED) {
+ return -EACCES;
+ }