BACKPORT: seccomp: Add a seccomp_data parameter secure_computing()

Currently, if arch code wants to supply seccomp_data directly to
seccomp (which is generally much faster than having seccomp do it
using the syscall_get_xyz() API), it has to use the two-phase
seccomp hooks. Add it to the easy hooks, too.

Cc: linux-arch@vger.kernel.org
Signed-off-by: Andy Lutomirski <luto@kernel.org>
Signed-off-by: Kees Cook <keescook@chromium.org>
(cherry picked from commit 2f275de5d1)

Bug: 119769499
Change-Id: I96876ecd8d1743c289ecef6d2deb65361d1f5baa
[ghackmann@google.com: drop changes to parisc, tile, and um, which
 didn't implement seccomp support in this kernel version]
Signed-off-by: Greg Hackmann <ghackmann@google.com>

Signed-off-by: Amit Pundir <amit.pundir@linaro.org>
This commit is contained in:
Andy Lutomirski
2016-05-27 12:57:02 -07:00
committed by Amit Pundir
parent 6b2efe86a1
commit ec8e12f60f
9 changed files with 13 additions and 13 deletions

View File

@@ -579,9 +579,9 @@ void secure_computing_strict(int this_syscall)
BUG();
}
#else
int __secure_computing(void)
int __secure_computing(const struct seccomp_data *sd)
{
u32 phase1_result = seccomp_phase1(NULL);
u32 phase1_result = seccomp_phase1(sd);
if (likely(phase1_result == SECCOMP_PHASE1_OK))
return 0;