25 Mar, 2020

1 commit


12 Dec, 2018

1 commit

  • The idea here is just to give a demonstration of how one could safely use
    the SECCOMP_RET_USER_NOTIF feature to do mount policies. This particular
    policy is (as noted in the comment) not very interesting, but it serves to
    illustrate how one might apply a policy dodging the various TOCTOU issues.

    Signed-off-by: Tycho Andersen
    CC: Kees Cook
    CC: Andy Lutomirski
    CC: Oleg Nesterov
    CC: Eric W. Biederman
    CC: "Serge E. Hallyn"
    CC: Christian Brauner
    CC: Tyler Hicks
    CC: Akihiro Suda
    Signed-off-by: Kees Cook

    Tycho Andersen
     

28 Jun, 2012

1 commit