]> git.proxmox.com Git - mirror_libseccomp.git/commit
api: Add support for SCMP_ACT_KILL_PROCESS
authorTom Hromatka <tom.hromatka@oracle.com>
Wed, 19 Sep 2018 15:26:25 +0000 (09:26 -0600)
committerPaul Moore <paul@paul-moore.com>
Wed, 19 Sep 2018 20:54:15 +0000 (16:54 -0400)
commitb2f15f3d02f302b12b9d1a37d83521e6f9e08841
treee9b3e4ae6b2a9dcaf68b2877c24d9b69fc1e7122
parent6646e21ed2734dca355c5b550cb45f0379330e02
api: Add support for SCMP_ACT_KILL_PROCESS

This patch adds support for killing the entire process via
the SCMP_ACT_KILL_PROCESS action.  To maintain backward
compatibility, SCMP_ACT_KILL defaults to SCMP_ACT_KILL_THREAD.
Support for KILL_PROCESS was added into the Linux kernel in
v4.14.

This addresses GitHub Issue #96 - RFE: add support for
SECCOMP_RET_KILL_PROCESS

Signed-off-by: Tom Hromatka <tom.hromatka@oracle.com>
[PM: minor comment tweak in seccomp.h.in]
Signed-off-by: Paul Moore <paul@paul-moore.com>
12 files changed:
doc/man/man3/seccomp_init.3
doc/man/man3/seccomp_rule_add.3
include/seccomp.h.in
src/api.c
src/gen_pfc.c
src/python/libseccomp.pxd
src/python/seccomp.pyx
src/system.c
src/system.h
tools/bpf.h
tools/scmp_bpf_disasm.c
tools/scmp_bpf_sim.c