Index: sandbox/linux/seccomp-bpf/sandbox_bpf_compatibility_policy.h |
diff --git a/sandbox/linux/seccomp-bpf/sandbox_bpf_compatibility_policy.h b/sandbox/linux/seccomp-bpf/sandbox_bpf_compatibility_policy.h |
index bd947ad52122ac849664fc0fab2ab4e709a28a30..d4b8ab8b15abf489d31e71df3d4ee9a0a3929a58 100644 |
--- a/sandbox/linux/seccomp-bpf/sandbox_bpf_compatibility_policy.h |
+++ b/sandbox/linux/seccomp-bpf/sandbox_bpf_compatibility_policy.h |
@@ -28,6 +28,7 @@ class CompatibilityPolicy : public SandboxBPFPolicy { |
virtual ErrorCode EvaluateSyscall(SandboxBPF* sandbox_compiler, |
int system_call_number) const OVERRIDE { |
+ DCHECK(SandboxBPF::IsValidSyscallNumber(system_call_number)); |
return syscall_evaluator_(sandbox_compiler, system_call_number, aux_); |
} |