Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
seccomp: Only dump core when single-threaded
The SECCOMP_RET_KILL filter return code has always killed the current thread, not the entire process. Changing this as a side-effect of dumping core isn't a safe thing to do (a few test suites have already flagged this behavioral change). Instead, restore the RET_KILL semantics, but still dump core when a RET_KILL delivers SIGSYS to a single-threaded process. Fixes: b25e671 ("seccomp: dump core when using SECCOMP_RET_KILL") Signed-off-by: Kees Cook <[email protected]> Acked-by: Andrei Vagin <[email protected]> Signed-off-by: James Morris <[email protected]>
- Loading branch information