On Mon, Oct 5, 2026 at 1:01 PM Daniel P. Berrangé <[email protected]> wrote:
>
> The initializer for these syscalls missed the seccomp action
> field, so it got the default action which was to kill the calling
> thread, instead of returning an errno value, which the other
> equivalent syscalls use.
>
> Since we don't ever intend to use a seccomp filter without a
> defined action, use an assert to validate that action is always
> set to non-zero.
>
> Reported-by: Igor Santos-Grueiro (gitlab:@igorsantosgrueiro)
> Fixes: https://gitlab.com/qemu-project/qemu/-/work_items/4600
> Fixes: 4638057110 (seccomp: block setns, unshare and execveat syscalls)
> Signed-off-by: Daniel P. Berrangé <[email protected]>

Reviewed-by: Marc-André Lureau <[email protected]>

> ---
>  system/qemu-seccomp.c | 15 ++++++++++++---
>  1 file changed, 12 insertions(+), 3 deletions(-)
>
> diff --git a/system/qemu-seccomp.c b/system/qemu-seccomp.c
> index f8e1238b914..3889d48b4f2 100644
> --- a/system/qemu-seccomp.c
> +++ b/system/qemu-seccomp.c
> @@ -249,10 +249,13 @@ static const struct QemuSeccompSyscall denylist[] = {
>        0, NULL, SCMP_ACT_ERRNO(ENOSYS) },
>  #endif
>  #ifdef __SNR_execveat
> -    { SCMP_SYS(execveat),               QEMU_SECCOMP_SET_SPAWN },
> +    { SCMP_SYS(execveat),               QEMU_SECCOMP_SET_SPAWN,
> +      ARRAY_SIZE(clone_arg_none), clone_arg_none, SCMP_ACT_ERRNO(EPERM) },
>  #endif
> -    { SCMP_SYS(setns),                  QEMU_SECCOMP_SET_SPAWN },
> -    { SCMP_SYS(unshare),                QEMU_SECCOMP_SET_SPAWN },
> +    { SCMP_SYS(setns),                  QEMU_SECCOMP_SET_SPAWN,
> +      ARRAY_SIZE(clone_arg_none), clone_arg_none, SCMP_ACT_ERRNO(EPERM) },
> +    { SCMP_SYS(unshare),                QEMU_SECCOMP_SET_SPAWN,
> +      ARRAY_SIZE(clone_arg_none), clone_arg_none, SCMP_ACT_ERRNO(EPERM) },
>      /* resource control */
>      { SCMP_SYS(setpriority),            QEMU_SECCOMP_SET_RESOURCECTL,
>        0, NULL, SCMP_ACT_ERRNO(EPERM) },
> @@ -337,6 +340,12 @@ static int seccomp_start(uint32_t seccomp_opts, Error 
> **errp)
>          if (!(seccomp_opts & denylist[i].set)) {
>              continue;
>          }
> +        /*
> +         * action == 0 is SCMP_ACT_KILL_THREAD which is not
> +         * something we ever want to use. Validate it to protect
> +         * against missing struct field initializers
> +         */
> +        assert(denylist[i].action);
>
>          action = qemu_seccomp_update_action(denylist[i].action);
>          rc = seccomp_rule_add_array(ctx, action, denylist[i].num,
> --
> 2.55.0
>
>


-- 
Marc-André Lureau

Reply via email to