New issue
Advanced search Search tips

Issue 691025 link

Starred by 1 user

Issue metadata

Status: Archived
Owner:
Closed: Feb 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 2
Type: Bug



Sign in to add a comment

mtpd terminated by minijail when making madvise syscall

Project Member Reported by benchan@chromium.org, Feb 10 2017

Issue description

mtpd terminated by minijail when making madvise syscall as madvise isn't whitelisted in the mtpd seccomp filter policy:

Thread 0 CRASHED [SIGSYS @ 0x00000000 ] MAGIC SIGNATURE THREAD
0x00007acef639eb87	(libc-2.23.so + 0x000f1b87 )	madvise
0x00007acef576c819	(libpthread-2.23.so -pthread_create.c:432 )	start_thread
0x00007acef63a36dc	(libc-2.23.so + 0x000f66dc )	clone
 
It should be fine to add madvise to the whitelist. Just took a look at the manpage and there's nothing too scary there.
Status: Started (was: Untriaged)
Project Member

Comment 3 by bugdroid1@chromium.org, Feb 11 2017

The following revision refers to this bug:
  https://chromium.googlesource.com/chromiumos/platform/mtpd/+/6797704c18ca431a7d7f52641fcb8eb8c04c18b8

commit 6797704c18ca431a7d7f52641fcb8eb8c04c18b8
Author: Ben Chan <benchan@chromium.org>
Date: Sat Feb 11 08:35:22 2017

mtpd: whitelist 'madvise' syscall in seccomp-bpf filter

BUG= chromium:691025 
TEST=Verified that mtpd is no longer terminated by minijail0.

Change-Id: I8011cb859ff502e1a133384bbb993588b98d5533
Reviewed-on: https://chromium-review.googlesource.com/440653
Commit-Ready: Ben Chan <benchan@chromium.org>
Tested-by: Ben Chan <benchan@chromium.org>
Reviewed-by: Jorge Lucangeli Obes <jorgelo@chromium.org>

[modify] https://crrev.com/6797704c18ca431a7d7f52641fcb8eb8c04c18b8/mtpd-seccomp-x86.policy
[modify] https://crrev.com/6797704c18ca431a7d7f52641fcb8eb8c04c18b8/mtpd-seccomp-arm.policy
[modify] https://crrev.com/6797704c18ca431a7d7f52641fcb8eb8c04c18b8/mtpd-seccomp-amd64.policy

Status: Fixed (was: Started)

Comment 5 by dchan@google.com, Apr 17 2017

Labels: VerifyIn-59

Comment 6 by dchan@google.com, May 30 2017

Labels: VerifyIn-60

Comment 7 by dchan@chromium.org, Aug 1 2017

Labels: VerifyIn-61

Comment 8 by dchan@chromium.org, Oct 14 2017

Status: Archived (was: Fixed)

Sign in to add a comment