From: Tycho Andersen Date: Sat, 26 Sep 2020 13:29:47 +0000 (+0200) Subject: seccomp.2: Document SECCOMP_RET_USER_NOTIF X-Git-Tag: man-pages-5.12~90 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=c734bbd265f4ea53cc80fb6a83e96502be9d1bce;p=thirdparty%2Fman-pages.git seccomp.2: Document SECCOMP_RET_USER_NOTIF Signed-off-by: Michael Kerrisk --- diff --git a/man2/seccomp.2 b/man2/seccomp.2 index 0019b5a9bd..5ead163b78 100644 --- a/man2/seccomp.2 +++ b/man2/seccomp.2 @@ -600,6 +600,17 @@ portion of the filter's return value being passed to user space as the .IR errno value without executing the system call. .TP +.BR SECCOMP_RET_USER_NOTIF " (since Linux 4.21)" +Forwards the syscall to an attached listener in userspace to allow userspace to +decide what to do with the syscall. If there is no attached listener (either +because the filter was not installed with the +.BR SECCOMP_FILTER_FLAG_NEW_LISTENER +or because the fd was closed), the filter returns +.BR ENOSYS +similar to what happens when a filter returns +.BR SECCOMP_RET_TRACE +and there is no tracer. See "Userspace Notification" below for more details. +.TP .BR SECCOMP_RET_TRACE When returned, this value will cause the kernel to attempt to notify a .BR ptrace (2)-based