Received: by 10.192.165.148 with SMTP id m20csp795602imm; Wed, 2 May 2018 08:56:43 -0700 (PDT) X-Google-Smtp-Source: AB8JxZrkPw42Y7QAIZj9pMSyavHgO8qiVef1gbjOisDEqBLfiT+FMb62+U9jUg2jsUeSui7SmrFd X-Received: by 2002:a63:6ac6:: with SMTP id f189-v6mr15181441pgc.308.1525276603817; Wed, 02 May 2018 08:56:43 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1525276603; cv=none; d=google.com; s=arc-20160816; b=TdjTckLX8Q3l63YuG47rNEZRQ5qnmoAQVTDruY0gYmoi0yCbFZ5AnFneaxwltsbmIa jAXL8C5iU6K2YUwmYicwJ+qKy6c7z9hMFwtk1iRDRd7U6/gC/dem419RYcck0NsQGGB7 KovkfTJ1w2gePF+GBPlK+fmWX7dVcnV9rzU2yzy25URINzGCTFRnLrDotAwx8Z6fvcG5 B52bXho7KdGJyMBH7VoLKBbhshyArotI7SbHXxMNaxSnKlIFgUxa9isgIlmKEAVVT33X 9fu/ZMxq1RI0CJ0xfGgKo1aHUB9nge3ZIrkShS7vcqt1eq7YjF7EJNqePkgWMm69kaB5 OVuA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:references:in-reply-to:message-id:date :subject:cc:to:from:arc-authentication-results; bh=PQxaEdJ5JUm0kNvbKiyNltEEw8/5oOacQsiBrHf+1HM=; b=OoFq7Ew8dHbhTd7SfxyvTrnjSHO6bmpRn0UshgsWzi9CHT8TXa39kXKlrWc+rX+NDF 1Ad1vkUtM0ulwTpUKJ21ocQQlDq9VfVQ9fRjlpLPuD5yTZekVdlZqeJkPINROLTdCM7f /qB+vRs6BUuhOT005JxtpqGlKa+S0/sZprEZTBULULyEVVJORyabcpvpE5+5kpsAxYRY +aN1OaInTotEFGFJcoDNA/mmJdygOf2OqG4V8eP+kQhC+1GivmMV2u7UruiHT8LTvhE7 pWhytC+pWsx19Db1X9LFOvj1KqzMrOCuSf4bM8jdLPkFLkx/mJKes9IlquSdKb4V847U dH0w== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=canonical.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id j7si10815536pfh.3.2018.05.02.08.56.29; Wed, 02 May 2018 08:56:43 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=canonical.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751891AbeEBPyd (ORCPT + 99 others); Wed, 2 May 2018 11:54:33 -0400 Received: from youngberry.canonical.com ([91.189.89.112]:54876 "EHLO youngberry.canonical.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751100AbeEBPy3 (ORCPT ); Wed, 2 May 2018 11:54:29 -0400 Received: from 2.general.tyhicks.us.vpn ([10.172.64.53] helo=sec.l.tihix.com) by youngberry.canonical.com with esmtpsa (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.76) (envelope-from ) id 1fDu5M-0007uo-C8; Wed, 02 May 2018 15:54:28 +0000 From: Tyler Hicks To: linux-kernel@vger.kernel.org Cc: Kees Cook , Andy Lutomirski , Will Drewry , Paul Moore , Eric Paris , Steve Grubb , Jonathan Corbet , linux-audit@redhat.com, linux-security-module@vger.kernel.org, linux-doc@vger.kernel.org Subject: [PATCH v2 2/4] seccomp: Configurable separator for the actions_logged string Date: Wed, 2 May 2018 15:53:18 +0000 Message-Id: <1525276400-7161-3-git-send-email-tyhicks@canonical.com> X-Mailer: git-send-email 2.7.4 In-Reply-To: <1525276400-7161-1-git-send-email-tyhicks@canonical.com> References: <1525276400-7161-1-git-send-email-tyhicks@canonical.com> Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org The function that converts a bitmask of seccomp actions that are allowed to be logged is currently only used for constructing the display string for the kernel.seccomp.actions_logged sysctl. That string wants a space character to be used for the separator between actions. A future patch will make use of the same function for building a string that will be sent to the audit subsystem for tracking modifications to the kernel.seccomp.actions_logged sysctl. That string will need to use a comma as a separator. This patch allows the separator character to be configurable to meet both needs. Signed-off-by: Tyler Hicks --- kernel/seccomp.c | 13 +++++++------ 1 file changed, 7 insertions(+), 6 deletions(-) diff --git a/kernel/seccomp.c b/kernel/seccomp.c index f4afe67..b36ac1e 100644 --- a/kernel/seccomp.c +++ b/kernel/seccomp.c @@ -1135,10 +1135,11 @@ static const struct seccomp_log_name seccomp_log_names[] = { }; static bool seccomp_names_from_actions_logged(char *names, size_t size, - u32 actions_logged) + u32 actions_logged, + const char *sep) { const struct seccomp_log_name *cur; - bool append_space = false; + bool append_sep = false; for (cur = seccomp_log_names; cur->name && size; cur++) { ssize_t ret; @@ -1146,15 +1147,15 @@ static bool seccomp_names_from_actions_logged(char *names, size_t size, if (!(actions_logged & cur->log)) continue; - if (append_space) { - ret = strscpy(names, " ", size); + if (append_sep) { + ret = strscpy(names, sep, size); if (ret < 0) return false; names += ret; size -= ret; } else - append_space = true; + append_sep = true; ret = strscpy(names, cur->name, size); if (ret < 0) @@ -1208,7 +1209,7 @@ static int read_actions_logged(struct ctl_table *ro_table, void __user *buffer, memset(names, 0, sizeof(names)); if (!seccomp_names_from_actions_logged(names, sizeof(names), - seccomp_actions_logged)) + seccomp_actions_logged, " ")) return -EINVAL; table = *ro_table; -- 2.7.4