On Mon, Oct 5, 2026 at 1:01 PM Daniel P. Berrangé <[email protected]> wrote: > > The initializer for these syscalls missed the seccomp action > field, so it got the default action which was to kill the calling > thread, instead of returning an errno value, which the other > equivalent syscalls use. > > Since we don't ever intend to use a seccomp filter without a > defined action, use an assert to validate that action is always > set to non-zero. > > Reported-by: Igor Santos-Grueiro (gitlab:@igorsantosgrueiro) > Fixes: https://gitlab.com/qemu-project/qemu/-/work_items/4600 > Fixes: 4638057110 (seccomp: block setns, unshare and execveat syscalls) > Signed-off-by: Daniel P. Berrangé <[email protected]>
Reviewed-by: Marc-André Lureau <[email protected]> > --- > system/qemu-seccomp.c | 15 ++++++++++++--- > 1 file changed, 12 insertions(+), 3 deletions(-) > > diff --git a/system/qemu-seccomp.c b/system/qemu-seccomp.c > index f8e1238b914..3889d48b4f2 100644 > --- a/system/qemu-seccomp.c > +++ b/system/qemu-seccomp.c > @@ -249,10 +249,13 @@ static const struct QemuSeccompSyscall denylist[] = { > 0, NULL, SCMP_ACT_ERRNO(ENOSYS) }, > #endif > #ifdef __SNR_execveat > - { SCMP_SYS(execveat), QEMU_SECCOMP_SET_SPAWN }, > + { SCMP_SYS(execveat), QEMU_SECCOMP_SET_SPAWN, > + ARRAY_SIZE(clone_arg_none), clone_arg_none, SCMP_ACT_ERRNO(EPERM) }, > #endif > - { SCMP_SYS(setns), QEMU_SECCOMP_SET_SPAWN }, > - { SCMP_SYS(unshare), QEMU_SECCOMP_SET_SPAWN }, > + { SCMP_SYS(setns), QEMU_SECCOMP_SET_SPAWN, > + ARRAY_SIZE(clone_arg_none), clone_arg_none, SCMP_ACT_ERRNO(EPERM) }, > + { SCMP_SYS(unshare), QEMU_SECCOMP_SET_SPAWN, > + ARRAY_SIZE(clone_arg_none), clone_arg_none, SCMP_ACT_ERRNO(EPERM) }, > /* resource control */ > { SCMP_SYS(setpriority), QEMU_SECCOMP_SET_RESOURCECTL, > 0, NULL, SCMP_ACT_ERRNO(EPERM) }, > @@ -337,6 +340,12 @@ static int seccomp_start(uint32_t seccomp_opts, Error > **errp) > if (!(seccomp_opts & denylist[i].set)) { > continue; > } > + /* > + * action == 0 is SCMP_ACT_KILL_THREAD which is not > + * something we ever want to use. Validate it to protect > + * against missing struct field initializers > + */ > + assert(denylist[i].action); > > action = qemu_seccomp_update_action(denylist[i].action); > rc = seccomp_rule_add_array(ctx, action, denylist[i].num, > -- > 2.55.0 > > -- Marc-André Lureau
