From 8bf87717a5b91c32032e91ae61448a78acf1c240 Mon Sep 17 00:00:00 2001 From: Albert S Date: Mon, 28 Mar 2022 19:14:00 +0200 Subject: [PATCH] vows: ioctl: Make TIOCSTI illegal even when IOCTL vow is set --- exile.c | 1 + 1 file changed, 1 insertion(+) diff --git a/exile.c b/exile.c index 0cfc5d7..07a5d47 100644 --- a/exile.c +++ b/exile.c @@ -430,6 +430,7 @@ int get_vow_argfilter(long syscall, uint64_t vow_promises, struct sock_filter *f struct exile_syscall_filter ioctl_filter[] = { EXILE_SYSCALL_FILTER_LOAD_ARG(1), + { EXILE_SYSCALL_VOW_IOCTL, EXILE_BPF_NO_MATCH_SET(TIOCSTI), 1 }, { EXILE_SYSCALL_VOW_IOCTL, EXILE_BPF_RETURN_MATCHING, 1 }, { EXILE_SYSCALL_VOW_STDIO, EXILE_BPF_MATCH(FIONREAD), 1}, { EXILE_SYSCALL_VOW_STDIO, EXILE_BPF_MATCH(FIONBIO), 1},