Fix seccomp sandbox rules for openat #27315

The need for casting negative syscall arguments depends on the
glibc version. This affects the rules for the openat syscall which
uses the constant AT_FDCWD that is defined as a negative number.
This commit adds logic to only apply the cast when necessary, on
glibc versions from 2.27 onwards.
This commit is contained in:
Daniel Pinto
2020-07-01 20:30:04 +01:00
parent c9751e2611
commit d75e7daaab
2 changed files with 38 additions and 10 deletions
+6
View File
@@ -0,0 +1,6 @@
o Minor bugfixes (linux seccomp2 sandbox):
- Fix a regression on sandboxing rules for the openat() syscall.
The fix for bug 25440 fixed the problem on systems with glibc >=
2.27 but broke tor on previous versions of glibc. We now apply
the correct seccomp rule according to the running glibc version.
Patch from Daniel Pinto. Fixes bug 27315; bugfix on 0.3.5.11.