Re: [PATCH v5 net-next 2/3] [RFC] seccomp: convert seccomp to use extended BPF

2014-03-05 Thread Alexei Starovoitov
On Wed, Mar 5, 2014 at 1:42 PM, Kees Cook wrote: > On Tue, Mar 4, 2014 at 7:11 PM, Alexei Starovoitov wrote: >> On Tue, Mar 4, 2014 at 2:17 PM, Alexei Starovoitov wrote: >>> use sk_convert_filter() to convert seccomp BPF into extended BPF >>> >>> 05-sim-long_jumps.c of libseccomp was used as mic

Re: [PATCH v5 net-next 2/3] [RFC] seccomp: convert seccomp to use extended BPF

2014-03-05 Thread Kees Cook
On Tue, Mar 4, 2014 at 7:11 PM, Alexei Starovoitov wrote: > On Tue, Mar 4, 2014 at 2:17 PM, Alexei Starovoitov wrote: >> use sk_convert_filter() to convert seccomp BPF into extended BPF >> >> 05-sim-long_jumps.c of libseccomp was used as micro-benchmark: >> seccomp_rule_add_exact(ctx,... >> s

Re: [PATCH v5 net-next 2/3] [RFC] seccomp: convert seccomp to use extended BPF

2014-03-04 Thread Alexei Starovoitov
On Tue, Mar 4, 2014 at 2:17 PM, Alexei Starovoitov wrote: > use sk_convert_filter() to convert seccomp BPF into extended BPF > > 05-sim-long_jumps.c of libseccomp was used as micro-benchmark: > seccomp_rule_add_exact(ctx,... > seccomp_rule_add_exact(ctx,... > rc = seccomp_load(ctx); > for

[PATCH v5 net-next 2/3] [RFC] seccomp: convert seccomp to use extended BPF

2014-03-04 Thread Alexei Starovoitov
use sk_convert_filter() to convert seccomp BPF into extended BPF 05-sim-long_jumps.c of libseccomp was used as micro-benchmark: seccomp_rule_add_exact(ctx,... seccomp_rule_add_exact(ctx,... rc = seccomp_load(ctx); for (i = 0; i < 1000; i++) syscall(199, 100); --x86_64-- old BPF: