s390/ptrace: run seccomp after ptrace
authorKees Cook <keescook@chromium.org>
Thu, 2 Jun 2016 20:19:36 +0000 (13:19 -0700)
committerKees Cook <keescook@chromium.org>
Tue, 14 Jun 2016 17:54:45 +0000 (10:54 -0700)
commit0208b9445bc031791e589c334a93365cbad008fe
tree588be3a0aa79df5cca66c6bbcf870bf874489e3e
parent375f0183047109b98658d539db6ff22a6ac24abc
s390/ptrace: run seccomp after ptrace

Close the hole where ptrace can change a syscall out from under seccomp.

Signed-off-by: Kees Cook <keescook@chromium.org>
Cc: Heiko Carstens <heiko.carstens@de.ibm.com>
Cc: Martin Schwidefsky <schwidefsky@de.ibm.com>
Cc: linux-s390@vger.kernel.org
arch/s390/kernel/ptrace.c