diff options
| author | Ophestra <cat@gensokyo.uk> | 2026-10-04 01:05:10 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2026-10-06 19:41:06 +0900 |
| commit | a7383510fb05abc98b992240cb76ad4b6c598956 (patch) | |
| tree | 90881e9d6952e050128f1378d66452c7d733d012 /test/sandbox/seccomp.patch | |
| parent | b452e1047ccd3e1826da16416430e6638270155b (diff) | |
test/sandbox: migrate tests
This significantly improves performance, removing overhead of nix,
python, and virtualisation. Running this in an unprivileged container
required patching the kernel, but since special runner setup was already
needed, that was an acceptable tradeoff.
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'test/sandbox/seccomp.patch')
| -rw-r--r-- | test/sandbox/seccomp.patch | 18 |
1 files changed, 18 insertions, 0 deletions
diff --git a/test/sandbox/seccomp.patch b/test/sandbox/seccomp.patch new file mode 100644 index 00000000..ddabc71e --- /dev/null +++ b/test/sandbox/seccomp.patch @@ -0,0 +1,18 @@ +diff --git a/kernel/seccomp.c b/kernel/seccomp.c +index 25f62867a16d..7b63ccc8daf4 100644 +--- a/kernel/seccomp.c ++++ b/kernel/seccomp.c +@@ -2216,8 +2216,12 @@ long seccomp_get_filter(struct task_struct *task, unsigned long filter_off, + struct seccomp_filter *filter; + struct sock_fprog_kern *fprog; + long ret; ++ struct user_namespace *user_ns = current_user_ns(); + +- if (!capable(CAP_SYS_ADMIN) || ++ if (in_userns(user_ns, task_cred_xxx(task, user_ns))) { ++ if (!ns_capable(user_ns, CAP_SYS_ADMIN)) ++ return -EACCES; ++ } else if (!capable(CAP_SYS_ADMIN) || + current->seccomp.mode != SECCOMP_MODE_DISABLED) { + return -EACCES; + } |
