Re: [PATCH v8 5/8] seccomp: Add SECCOMP_RET_TRAP

From: Markus Gutschke
Date: Thu Feb 16 2012 - 15:28:49 EST


On Thu, Feb 16, 2012 at 12:02, Will Drewry <wad@xxxxxxxxxxxx> wrote:
> Adds a new return value to seccomp filters that triggers a SIGTRAP to be delivered with the new TRAP_SECCOMP si_code.
>
> This allows in-process system call emulation -- including just specifying an errno or cleanly dumping core -- rather than just dying.

SIGTRAP might not be the ideal choice of signal number, as it can make
it very difficult to debug the program in gdb. Other than that, I love
this feature. It'll significantly simplify the code that we have in
Chrome.


Markus
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/