Conversation
Contributor
There was a problem hiding this comment.
Pull request overview
This PR implements a SIGSYS signal handler in ksud to gracefully handle system calls blocked by seccomp filters. When a syscall is blocked, instead of terminating, the handler catches the signal and returns -EPERM to the caller.
Key changes:
- Added a SIGSYS signal handler function that modifies CPU context to return EPERM for blocked syscalls
- Implemented architecture-specific register handling for aarch64 and x86_64
- Integrated handler setup into the application initialization in the
run()function
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Added null checks for info and ctx in sigsys_handler.
Improved signal handling by adding logging for invalid signals and updating context casting.
Contributor
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 1 out of 1 changed files in this pull request and generated 4 comments.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Updated the sigsys_handler function to include a context parameter.
f99db52 to
b3d034d
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Prevent crash if there is no root access.