Commit 5bf417c0 authored by Mickaël Salaün's avatar Mickaël Salaün Committed by Juerg Haefliger

selftest/seccomp: Fix the flag name SECCOMP_FILTER_FLAG_TSYNC

CVE-2018-3639 (x86)

Rename SECCOMP_FLAG_FILTER_TSYNC to SECCOMP_FILTER_FLAG_TSYNC to match
the UAPI.
Signed-off-by: default avatarMickaël Salaün <mic@digikod.net>
Cc: Andy Lutomirski <luto@amacapital.net>
Cc: Kees Cook <keescook@chromium.org>
Cc: Shuah Khan <shuahkh@osg.samsung.com>
Cc: Will Drewry <wad@chromium.org>
Acked-by: default avatarKees Cook <keescook@chromium.org>
Signed-off-by: default avatarShuah Khan <shuahkh@osg.samsung.com>

(backported from commit 6c045d07)
[juergh: Context adjustments.]
Signed-off-by: default avatarJuerg Haefliger <juergh@canonical.com>
parent ec5587e9
...@@ -1575,8 +1575,8 @@ TEST_F(TRACE_syscall, syscall_dropped) ...@@ -1575,8 +1575,8 @@ TEST_F(TRACE_syscall, syscall_dropped)
#define SECCOMP_GET_ACTION_AVAIL 2 #define SECCOMP_GET_ACTION_AVAIL 2
#endif #endif
#ifndef SECCOMP_FLAG_FILTER_TSYNC #ifndef SECCOMP_FILTER_FLAG_TSYNC
#define SECCOMP_FLAG_FILTER_TSYNC 1 #define SECCOMP_FILTER_FLAG_TSYNC 1
#endif #endif
#ifndef SECCOMP_FILTER_FLAG_LOG #ifndef SECCOMP_FILTER_FLAG_LOG
...@@ -1756,7 +1756,7 @@ TEST(TSYNC_first) ...@@ -1756,7 +1756,7 @@ TEST(TSYNC_first)
TH_LOG("Kernel does not support PR_SET_NO_NEW_PRIVS!"); TH_LOG("Kernel does not support PR_SET_NO_NEW_PRIVS!");
} }
ret = seccomp(SECCOMP_SET_MODE_FILTER, SECCOMP_FLAG_FILTER_TSYNC, ret = seccomp(SECCOMP_SET_MODE_FILTER, SECCOMP_FILTER_FLAG_TSYNC,
&prog); &prog);
ASSERT_NE(ENOSYS, errno) { ASSERT_NE(ENOSYS, errno) {
TH_LOG("Kernel does not support seccomp syscall!"); TH_LOG("Kernel does not support seccomp syscall!");
...@@ -1974,7 +1974,7 @@ TEST_F(TSYNC, two_siblings_with_ancestor) ...@@ -1974,7 +1974,7 @@ TEST_F(TSYNC, two_siblings_with_ancestor)
self->sibling_count++; self->sibling_count++;
} }
ret = seccomp(SECCOMP_SET_MODE_FILTER, SECCOMP_FLAG_FILTER_TSYNC, ret = seccomp(SECCOMP_SET_MODE_FILTER, SECCOMP_FILTER_FLAG_TSYNC,
&self->apply_prog); &self->apply_prog);
ASSERT_EQ(0, ret) { ASSERT_EQ(0, ret) {
TH_LOG("Could install filter on all threads!"); TH_LOG("Could install filter on all threads!");
...@@ -2035,7 +2035,7 @@ TEST_F(TSYNC, two_siblings_with_no_filter) ...@@ -2035,7 +2035,7 @@ TEST_F(TSYNC, two_siblings_with_no_filter)
TH_LOG("Kernel does not support PR_SET_NO_NEW_PRIVS!"); TH_LOG("Kernel does not support PR_SET_NO_NEW_PRIVS!");
} }
ret = seccomp(SECCOMP_SET_MODE_FILTER, SECCOMP_FLAG_FILTER_TSYNC, ret = seccomp(SECCOMP_SET_MODE_FILTER, SECCOMP_FILTER_FLAG_TSYNC,
&self->apply_prog); &self->apply_prog);
ASSERT_NE(ENOSYS, errno) { ASSERT_NE(ENOSYS, errno) {
TH_LOG("Kernel does not support seccomp syscall!"); TH_LOG("Kernel does not support seccomp syscall!");
...@@ -2083,7 +2083,7 @@ TEST_F(TSYNC, two_siblings_with_one_divergence) ...@@ -2083,7 +2083,7 @@ TEST_F(TSYNC, two_siblings_with_one_divergence)
self->sibling_count++; self->sibling_count++;
} }
ret = seccomp(SECCOMP_SET_MODE_FILTER, SECCOMP_FLAG_FILTER_TSYNC, ret = seccomp(SECCOMP_SET_MODE_FILTER, SECCOMP_FILTER_FLAG_TSYNC,
&self->apply_prog); &self->apply_prog);
ASSERT_EQ(self->sibling[0].system_tid, ret) { ASSERT_EQ(self->sibling[0].system_tid, ret) {
TH_LOG("Did not fail on diverged sibling."); TH_LOG("Did not fail on diverged sibling.");
...@@ -2135,7 +2135,7 @@ TEST_F(TSYNC, two_siblings_not_under_filter) ...@@ -2135,7 +2135,7 @@ TEST_F(TSYNC, two_siblings_not_under_filter)
TH_LOG("Kernel does not support SECCOMP_SET_MODE_FILTER!"); TH_LOG("Kernel does not support SECCOMP_SET_MODE_FILTER!");
} }
ret = seccomp(SECCOMP_SET_MODE_FILTER, SECCOMP_FLAG_FILTER_TSYNC, ret = seccomp(SECCOMP_SET_MODE_FILTER, SECCOMP_FILTER_FLAG_TSYNC,
&self->apply_prog); &self->apply_prog);
ASSERT_EQ(ret, self->sibling[0].system_tid) { ASSERT_EQ(ret, self->sibling[0].system_tid) {
TH_LOG("Did not fail on diverged sibling."); TH_LOG("Did not fail on diverged sibling.");
...@@ -2164,7 +2164,7 @@ TEST_F(TSYNC, two_siblings_not_under_filter) ...@@ -2164,7 +2164,7 @@ TEST_F(TSYNC, two_siblings_not_under_filter)
/* Switch to the remaining sibling */ /* Switch to the remaining sibling */
sib = !sib; sib = !sib;
ret = seccomp(SECCOMP_SET_MODE_FILTER, SECCOMP_FLAG_FILTER_TSYNC, ret = seccomp(SECCOMP_SET_MODE_FILTER, SECCOMP_FILTER_FLAG_TSYNC,
&self->apply_prog); &self->apply_prog);
ASSERT_EQ(0, ret) { ASSERT_EQ(0, ret) {
TH_LOG("Expected the remaining sibling to sync"); TH_LOG("Expected the remaining sibling to sync");
...@@ -2187,7 +2187,7 @@ TEST_F(TSYNC, two_siblings_not_under_filter) ...@@ -2187,7 +2187,7 @@ TEST_F(TSYNC, two_siblings_not_under_filter)
while (!kill(self->sibling[sib].system_tid, 0)) while (!kill(self->sibling[sib].system_tid, 0))
sleep(0.1); sleep(0.1);
ret = seccomp(SECCOMP_SET_MODE_FILTER, SECCOMP_FLAG_FILTER_TSYNC, ret = seccomp(SECCOMP_SET_MODE_FILTER, SECCOMP_FILTER_FLAG_TSYNC,
&self->apply_prog); &self->apply_prog);
ASSERT_EQ(0, ret); /* just us chickens */ ASSERT_EQ(0, ret); /* just us chickens */
} }
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment