446e146ff1
seccomp_bpf.c uses unshare(CLONE_NEWPID), which requires CONFIG_PID_NS to be set. Cc: Kees Cook <keescook@chromium.org> Cc: Shuah Khan <shuah@kernel.org> Fixes:6a21cc50f0("seccomp: add a return code to trap to userspace") Signed-off-by: Mickaël Salaün <mic@linux.microsoft.com> Acked-by: Tycho Andersen <tycho@tycho.pizza> Signed-off-by: Kees Cook <keescook@chromium.org> Link: https://lore.kernel.org/r/20201202162643.249276-1-mic@digikod.net (cherry picked from commit2c07343abd) Signed-off-by: Jeff Vander Stoep <jeffv@google.com> Bug: 176068146 Change-Id: Ia7724fdb085c964dd8255fbd2457dc0cfc1d4900
5 lines
74 B
Plaintext
5 lines
74 B
Plaintext
CONFIG_PID_NS=y
|
|
CONFIG_SECCOMP=y
|
|
CONFIG_SECCOMP_FILTER=y
|
|
CONFIG_USER_NS=y
|