Minijail: add better error reporting when including an invalid syscall.
BUG=None
TEST=syscall_filter_unittest
Change-Id: I8aa5963d8b0c2392865027bde5948fd746a07da8
Reviewed-on: https://gerrit.chromium.org/gerrit/31620
Tested-by: Jorge Lucangeli Obes <jorgelo@chromium.org>
Reviewed-by: Kees Cook <keescook@chromium.org>
Commit-Ready: Jorge Lucangeli Obes <jorgelo@chromium.org>
diff --git a/syscall_filter.c b/syscall_filter.c
index b7dfb77..a1f65d6 100644
--- a/syscall_filter.c
+++ b/syscall_filter.c
@@ -393,8 +393,11 @@
return -1;
nr = lookup_syscall(syscall_name);
- if (nr < 0)
+ if (nr < 0) {
+ warn("compile_filter: nonexistent syscall '%s'",
+ syscall_name);
return -1;
+ }
policy = strip(policy);