From a6f9ffd4becffac99adf7368b26dde537c721f6f Mon Sep 17 00:00:00 2001 From: Daniel Golle Date: Fri, 25 Sep 2026 15:53:05 +0100 Subject: [PATCH] jail/seccomp: complete the pre-main syscall allowlists The loader and pre-main allowlists name the syscalls a 64-bit libc issues before the workload reaches its entry point. A 32-bit libc sets its thread pointer with set_tls on ARM and set_thread_area on MIPS and i386, and maps and inspects its objects with mmap2, fstat64, fstatat64, statx, fcntl64 and the 64-suffixed statfs calls; glibc and bionic also read the stack limit with ugetrlimit or getrlimit there. None of these are in the lists, so the first syscall of ld.so already hits the profile's default action and a SCMP_ACT_KILL_PROCESS profile kills the jailed process before the entry breakpoint, which is how umdns dies on every 32-bit target. A static glibc binary further resolves its origin in _dl_non_dynamic_init(), reading the /proc/self/exe link with readlinkat before main, which the static pre-main list omits as well. Add the names to the lists so the grants and the deltas that revoke them stay in step; find_syscall() skips a name the target does not have. Fixes: f15d0c407c09 ("jail: apply OCI seccomp filters via ptrace syscall injection") Fixes: openwrt/openwrt#25392 Signed-off-by: Daniel Golle --- jail/seccomp-oci.c | 25 +++++++++++++++---------- 1 file changed, 15 insertions(+), 10 deletions(-) diff --git a/jail/seccomp-oci.c b/jail/seccomp-oci.c index 67ae566..8dae57b 100644 --- a/jail/seccomp-oci.c +++ b/jail/seccomp-oci.c @@ -297,23 +297,28 @@ static uint32_t resolve_architecture(char *archname) } const char * const seccomp_linker_base[] = { - "access", "arch_prctl", "brk", "close", "faccessat", "fcntl", "fstat", - "fstatfs", "futex", "getrandom", "mmap", "mprotect", "munmap", + "access", "arch_prctl", "brk", "close", "faccessat", "fcntl", "fcntl64", + "fstat", "fstat64", "fstatat64", "fstatfs", "fstatfs64", "futex", + "getrandom", "getrlimit", "mmap", "mmap2", "mprotect", "munmap", "newfstatat", "open", "openat", "pread64", "prctl", "prlimit64", "read", - "readlinkat", "rseq", "rt_sigaction", "sched_getscheduler", - "set_robust_list", "set_tid_address", "sigaltstack", "statfs", NULL, + "readlink", "readlinkat", "rseq", "rt_sigaction", "sched_getscheduler", + "set_robust_list", "set_thread_area", "set_tid_address", "set_tls", + "sigaltstack", "statfs", "statfs64", "statx", "ugetrlimit", NULL, }; const char * const seccomp_init_base[] = { - "arch_prctl", "brk", "futex", "getrandom", "mmap", "mprotect", "munmap", - "prctl", "prlimit64", "rseq", "rt_sigaction", "sched_getscheduler", - "set_robust_list", "set_tid_address", "sigaltstack", NULL, + "arch_prctl", "brk", "futex", "getrandom", "getrlimit", "mmap", "mmap2", + "mprotect", "munmap", "prctl", "prlimit64", "readlinkat", "rseq", + "rt_sigaction", "sched_getscheduler", "set_robust_list", + "set_thread_area", "set_tid_address", "set_tls", "sigaltstack", + "ugetrlimit", NULL, }; const char * const seccomp_loader_files[] = { - "access", "close", "faccessat", "fcntl", "fstat", "fstatfs", - "newfstatat", "open", "openat", "pread64", "read", "readlinkat", - "statfs", NULL, + "access", "close", "faccessat", "fcntl", "fcntl64", "fstat", "fstat64", + "fstatat64", "fstatfs", "fstatfs64", "newfstatat", "open", "openat", + "pread64", "read", "readlink", "readlinkat", "statfs", "statfs64", + "statx", NULL, }; enum {