Skip to content

Commit

Permalink
seccomp: check TSYNC host capability
Browse files Browse the repository at this point in the history
Remove -sandbox option if the host is not capable of TSYNC, since the
sandbox will fail at setup time otherwise. This will help libvirt, for
ex, to figure out if -sandbox will work.

Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Signed-off-by: Eduardo Otubo <otubo@redhat.com>
Acked-by: Eduardo Otubo <otubo@redhat.com>
  • Loading branch information
elmarco authored and otubo committed Sep 26, 2018
1 parent 19b599f commit 5780760
Show file tree
Hide file tree
Showing 2 changed files with 20 additions and 3 deletions.
19 changes: 18 additions & 1 deletion qemu-seccomp.c
Original file line number Diff line number Diff line change
Expand Up @@ -282,7 +282,24 @@ static QemuOptsList qemu_sandbox_opts = {

static void seccomp_register(void)
{
qemu_add_opts(&qemu_sandbox_opts);
bool add = false;

/* FIXME: use seccomp_api_get() >= 2 check when released */

#if defined(SECCOMP_FILTER_FLAG_TSYNC)
int check;

/* check host TSYNC capability, it returns errno == ENOSYS if unavailable */
check = qemu_seccomp(SECCOMP_SET_MODE_FILTER,
SECCOMP_FILTER_FLAG_TSYNC, NULL);
if (check < 0 && errno == EFAULT) {
add = true;
}
#endif

if (add) {
qemu_add_opts(&qemu_sandbox_opts);
}
}
opts_init(seccomp_register);
#endif
4 changes: 2 additions & 2 deletions vl.c
Original file line number Diff line number Diff line change
Expand Up @@ -4007,8 +4007,8 @@ int main(int argc, char **argv, char **envp)
}

#ifdef CONFIG_SECCOMP
if (qemu_opts_foreach(qemu_find_opts("sandbox"),
parse_sandbox, NULL, NULL)) {
olist = qemu_find_opts_err("sandbox", NULL);
if (olist && qemu_opts_foreach(olist, parse_sandbox, NULL, NULL)) {
exit(1);
}
#endif
Expand Down

0 comments on commit 5780760

Please sign in to comment.