From: Szabolcs Nagy <Szabolcs.Nagy@arm.com> To: Adhemerval Zanella <firstname.lastname@example.org>, "email@example.com" <firstname.lastname@example.org> Cc: nd <email@example.com>, linux-man <firstname.lastname@example.org> Subject: Re: glibc in master is incompatible with systemd-nspawn Date: Fri, 8 Nov 2019 16:01:58 +0000 Message-ID: <email@example.com> (raw) In-Reply-To: <firstname.lastname@example.org> On 08/11/2019 15:33, Adhemerval Zanella wrote: > Since when systemd-nspawn has this behaviour? What was the rationale to > use EPERM instead of ENOSYS? IMHO ENOSYS it the expected error in this > case, since filtering is essentially blocking the syscall usage altogether. docker does the same, but at least you can disable it with --security-opt seccomp:unconfined i think the original sin was committed by chromium which uses EPERM in its sandbox. it's of course broken whenever the application is run on a newer kernel+libc than what was used for creating the filter, may be the seccomp manual should warn against the use of EPERM (there is already a caveats section)?
next parent reply index Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top [not found] <email@example.com> [not found] ` <20191108141149.GB20533@altlinux.org> [not found] ` <firstname.lastname@example.org> [not found] ` <email@example.com> 2019-11-08 16:01 ` Szabolcs Nagy [this message] 2019-11-08 16:19 ` Florian Weimer 2019-11-08 16:23 ` Christian Brauner
Reply instructions: You may reply publically to this message via plain-text email using any one of the following methods: * Save the following mbox file, import it into your mail client, and reply-to-all from there: mbox Avoid top-posting and favor interleaved quoting: https://en.wikipedia.org/wiki/Posting_style#Interleaved_style * Reply using the --to, --cc, and --in-reply-to switches of git-send-email(1): git send-email \ --firstname.lastname@example.org \ --email@example.com \ --firstname.lastname@example.org \ --email@example.com \ --firstname.lastname@example.org \ --email@example.com \ /path/to/YOUR_REPLY https://kernel.org/pub/software/scm/git/docs/git-send-email.html * If your mail client supports setting the In-Reply-To header via mailto: links, try the mailto: link
Linux-man Archive on lore.kernel.org Archives are clonable: git clone --mirror https://lore.kernel.org/linux-man/0 linux-man/git/0.git # If you have public-inbox 1.1+ installed, you may # initialize and index your mirror using the following commands: public-inbox-init -V2 linux-man linux-man/ https://lore.kernel.org/linux-man \ firstname.lastname@example.org public-inbox-index linux-man Example config snippet for mirrors Newsgroup available over NNTP: nntp://nntp.lore.kernel.org/org.kernel.vger.linux-man AGPL code for this site: git clone https://public-inbox.org/public-inbox.git