seccomp: Only dump core when single-threaded
The SECCOMP_RET_KILL filter return code has always killed the current thread, not the entire process. Changing this as a side-effect of dumping core isn't a safe thing to do (a few test suites have already flagged this behavioral change). Instead, restore the RET_KILL semantics, but still dump core when a RET_KILL delivers SIGSYS to a single-threaded process. Fixes: b25e6716 ("seccomp: dump core when using SECCOMP_RET_KILL") Signed-off-by: NKees Cook <keescook@chromium.org> Acked-by: NAndrei Vagin <avagin@virtuozzo.com> Signed-off-by: NJames Morris <james.l.morris@oracle.com>
Showing
想要评论请 注册 或 登录