The initializer for these syscalls missed the seccomp action field, so it got the default action which was to kill the calling thread, instead of returning an errno value, which the other equivalent syscalls use.
Since we don't ever intend to use a seccomp filter without a defined action, use an assert to validate that action is always set to non-zero. Reported-by: Igor Santos-Grueiro (gitlab:@igorsantosgrueiro) Fixes: https://gitlab.com/qemu-project/qemu/-/work_items/4600 Fixes: 4638057110 (seccomp: block setns, unshare and execveat syscalls) Signed-off-by: Daniel P. Berrangé <[email protected]> --- system/qemu-seccomp.c | 15 ++++++++++++--- 1 file changed, 12 insertions(+), 3 deletions(-) diff --git a/system/qemu-seccomp.c b/system/qemu-seccomp.c index f8e1238b914..3889d48b4f2 100644 --- a/system/qemu-seccomp.c +++ b/system/qemu-seccomp.c @@ -249,10 +249,13 @@ static const struct QemuSeccompSyscall denylist[] = { 0, NULL, SCMP_ACT_ERRNO(ENOSYS) }, #endif #ifdef __SNR_execveat - { SCMP_SYS(execveat), QEMU_SECCOMP_SET_SPAWN }, + { SCMP_SYS(execveat), QEMU_SECCOMP_SET_SPAWN, + ARRAY_SIZE(clone_arg_none), clone_arg_none, SCMP_ACT_ERRNO(EPERM) }, #endif - { SCMP_SYS(setns), QEMU_SECCOMP_SET_SPAWN }, - { SCMP_SYS(unshare), QEMU_SECCOMP_SET_SPAWN }, + { SCMP_SYS(setns), QEMU_SECCOMP_SET_SPAWN, + ARRAY_SIZE(clone_arg_none), clone_arg_none, SCMP_ACT_ERRNO(EPERM) }, + { SCMP_SYS(unshare), QEMU_SECCOMP_SET_SPAWN, + ARRAY_SIZE(clone_arg_none), clone_arg_none, SCMP_ACT_ERRNO(EPERM) }, /* resource control */ { SCMP_SYS(setpriority), QEMU_SECCOMP_SET_RESOURCECTL, 0, NULL, SCMP_ACT_ERRNO(EPERM) }, @@ -337,6 +340,12 @@ static int seccomp_start(uint32_t seccomp_opts, Error **errp) if (!(seccomp_opts & denylist[i].set)) { continue; } + /* + * action == 0 is SCMP_ACT_KILL_THREAD which is not + * something we ever want to use. Validate it to protect + * against missing struct field initializers + */ + assert(denylist[i].action); action = qemu_seccomp_update_action(denylist[i].action); rc = seccomp_rule_add_array(ctx, action, denylist[i].num, -- 2.55.0
