diff options
| author | Ophestra <cat@gensokyo.uk> | 2026-10-06 22:23:20 +0900 |
|---|---|---|
| committer | Ophestra <cat@gensokyo.uk> | 2026-10-06 23:09:19 +0900 |
| commit | a9e2749f6654d0aa07b274a45c9177d10323f80a (patch) | |
| tree | 291f5b23a67af036cbe5d374b3d3fb0240fc438c /test/sandbox/seccomp.patch | |
| parent | 19f36491f2e2a5029ac396c10408d653cad6c81b (diff) | |
internal/testsuite: move from test
This structure is a lot less clumsy than the old nix-centric layout.
Signed-off-by: Ophestra <cat@gensokyo.uk>
Diffstat (limited to 'test/sandbox/seccomp.patch')
| -rw-r--r-- | test/sandbox/seccomp.patch | 18 |
1 files changed, 0 insertions, 18 deletions
diff --git a/test/sandbox/seccomp.patch b/test/sandbox/seccomp.patch deleted file mode 100644 index ddabc71e..00000000 --- a/test/sandbox/seccomp.patch +++ /dev/null @@ -1,18 +0,0 @@ -diff --git a/kernel/seccomp.c b/kernel/seccomp.c -index 25f62867a16d..7b63ccc8daf4 100644 ---- a/kernel/seccomp.c -+++ b/kernel/seccomp.c -@@ -2216,8 +2216,12 @@ long seccomp_get_filter(struct task_struct *task, unsigned long filter_off, - struct seccomp_filter *filter; - struct sock_fprog_kern *fprog; - long ret; -+ struct user_namespace *user_ns = current_user_ns(); - -- if (!capable(CAP_SYS_ADMIN) || -+ if (in_userns(user_ns, task_cred_xxx(task, user_ns))) { -+ if (!ns_capable(user_ns, CAP_SYS_ADMIN)) -+ return -EACCES; -+ } else if (!capable(CAP_SYS_ADMIN) || - current->seccomp.mode != SECCOMP_MODE_DISABLED) { - return -EACCES; - } |
