mailarchive of the ptxdist mailing list
 help / color / mirror / Atom feed
* [ptxdist] systemd: seccomp
@ 2015-11-29 15:21 Clemens Gruber
  2015-11-29 15:47 ` Uwe Kleine-König
  0 siblings, 1 reply; 3+ messages in thread
From: Clemens Gruber @ 2015-11-29 15:21 UTC (permalink / raw)
  To: ptxdist; +Cc: Michael Olbrich

Hi,

I noticed that the systemd rule in ptxdist explicitly disables seccomp
support. Would be great to have support for SystemCallFilter in service
files.

I therefore added libseccomp and modified the systemd rule to enable
seccomp (optionally via a menu entry).
I use the current git master Linux kernel with CONFIG_SECCOMP enabled.

Even though systemctl --version shows +SECCOMP, the SystemCallFilter
statement does not have any effect.
For testing, I only allowed one syscall for a program which needs much
more, but it did still run normally as if no SystemCallFilter had been
set at all.

Platform used:
- ARM (i.MX6Q) with ptxdist: SystemCallFilter had no effect
- x86_64 (Intel i7 6700K) with ArchLinux: Working perfectly

Can you reproduce this and do you have any idea why this isn't working?

Thanks,
Clemens

_______________________________________________
ptxdist mailing list
ptxdist@pengutronix.de

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2015-12-20 15:30 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2015-11-29 15:21 [ptxdist] systemd: seccomp Clemens Gruber
2015-11-29 15:47 ` Uwe Kleine-König
2015-12-20 15:30   ` Clemens Gruber

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox