mirror of
git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-03-22 07:27:12 +08:00
landlock: Improve erratum documentation
Improve description about scoped signal handling. Reported-by: Günther Noack <gnoack3000@gmail.com> Link: https://lore.kernel.org/r/20251219193855.825889-2-mic@digikod.net Reviewed-by: Günther Noack <gnoack3000@gmail.com> Signed-off-by: Mickaël Salaün <mic@digikod.net>
This commit is contained in:
@@ -9,7 +9,7 @@
|
||||
* This fix addresses an issue where signal scoping was overly restrictive,
|
||||
* preventing sandboxed threads from signaling other threads within the same
|
||||
* process if they belonged to different domains. Because threads are not
|
||||
* security boundaries, user space might assume that any thread within the same
|
||||
* security boundaries, user space might assume that all threads within the same
|
||||
* process can send signals between themselves (see :manpage:`nptl(7)` and
|
||||
* :manpage:`libpsx(3)`). Consistent with :manpage:`ptrace(2)` behavior, direct
|
||||
* interaction between threads of the same process should always be allowed.
|
||||
|
||||
Reference in New Issue
Block a user