diff options
author | Alexey Dobriyan <adobriyan@gmail.com> | 2008-09-09 03:01:31 -0400 |
---|---|---|
committer | Ingo Molnar <mingo@elte.hu> | 2008-09-09 03:09:51 -0400 |
commit | 9c0bbee8a6fc14107e9a7af6750bfe1056cbf4bc (patch) | |
tree | 19452ab3def68c249c51452f03f8501b3a74e7c8 /arch/x86 | |
parent | afe73824f52d6767c77e9456f573a76075108279 (diff) |
seccomp: drop now bogus dependency on PROC_FS
seccomp is prctl(2)-driven now.
Signed-off-by: Alexey Dobriyan <adobriyan@gmail.com>
Signed-off-by: Ingo Molnar <mingo@elte.hu>
Diffstat (limited to 'arch/x86')
-rw-r--r-- | arch/x86/Kconfig | 3 |
1 files changed, 1 insertions, 2 deletions
diff --git a/arch/x86/Kconfig b/arch/x86/Kconfig index 68d91c8233f4..1e2afe60ba99 100644 --- a/arch/x86/Kconfig +++ b/arch/x86/Kconfig | |||
@@ -1205,7 +1205,6 @@ config IRQBALANCE | |||
1205 | config SECCOMP | 1205 | config SECCOMP |
1206 | def_bool y | 1206 | def_bool y |
1207 | prompt "Enable seccomp to safely compute untrusted bytecode" | 1207 | prompt "Enable seccomp to safely compute untrusted bytecode" |
1208 | depends on PROC_FS | ||
1209 | help | 1208 | help |
1210 | This kernel feature is useful for number crunching applications | 1209 | This kernel feature is useful for number crunching applications |
1211 | that may need to compute untrusted bytecode during their | 1210 | that may need to compute untrusted bytecode during their |
@@ -1213,7 +1212,7 @@ config SECCOMP | |||
1213 | the process as file descriptors supporting the read/write | 1212 | the process as file descriptors supporting the read/write |
1214 | syscalls, it's possible to isolate those applications in | 1213 | syscalls, it's possible to isolate those applications in |
1215 | their own address space using seccomp. Once seccomp is | 1214 | their own address space using seccomp. Once seccomp is |
1216 | enabled via /proc/<pid>/seccomp, it cannot be disabled | 1215 | enabled via prctl(PR_SET_SECCOMP), it cannot be disabled |
1217 | and the task is only allowed to execute a few safe syscalls | 1216 | and the task is only allowed to execute a few safe syscalls |
1218 | defined by each seccomp mode. | 1217 | defined by each seccomp mode. |
1219 | 1218 | ||