From a9e2749f6654d0aa07b274a45c9177d10323f80a Mon Sep 17 00:00:00 2001 From: Ophestra Date: Tue, 6 Oct 2026 22:23:20 +0900 Subject: internal/testsuite: move from test This structure is a lot less clumsy than the old nix-centric layout. Signed-off-by: Ophestra --- internal/workflows/seccomp.patch | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) create mode 100644 internal/workflows/seccomp.patch (limited to 'internal/workflows/seccomp.patch') diff --git a/internal/workflows/seccomp.patch b/internal/workflows/seccomp.patch new file mode 100644 index 00000000..ddabc71e --- /dev/null +++ b/internal/workflows/seccomp.patch @@ -0,0 +1,18 @@ +diff --git a/kernel/seccomp.c b/kernel/seccomp.c +index 25f62867a16d..7b63ccc8daf4 100644 +--- a/kernel/seccomp.c ++++ b/kernel/seccomp.c +@@ -2216,8 +2216,12 @@ long seccomp_get_filter(struct task_struct *task, unsigned long filter_off, + struct seccomp_filter *filter; + struct sock_fprog_kern *fprog; + long ret; ++ struct user_namespace *user_ns = current_user_ns(); + +- if (!capable(CAP_SYS_ADMIN) || ++ if (in_userns(user_ns, task_cred_xxx(task, user_ns))) { ++ if (!ns_capable(user_ns, CAP_SYS_ADMIN)) ++ return -EACCES; ++ } else if (!capable(CAP_SYS_ADMIN) || + current->seccomp.mode != SECCOMP_MODE_DISABLED) { + return -EACCES; + } -- cgit v1.3.1