summary refs log tree commit diff
path: root/seccomp
diff options
context:
space:
mode:
authorDaniel Verkamp <dverkamp@chromium.org>2018-09-18 10:27:34 -0700
committerchrome-bot <chrome-bot@chromium.org>2018-09-19 15:40:06 -0700
commit616a093d9197cbca23d3fa585520c674e19d917a (patch)
tree3c5d379a20240f697e2a266135708b67dbfc8237 /seccomp
parentcd9f86b2994a20347e1855e112369e5052f5a8cb (diff)
downloadcrosvm-616a093d9197cbca23d3fa585520c674e19d917a.tar
crosvm-616a093d9197cbca23d3fa585520c674e19d917a.tar.gz
crosvm-616a093d9197cbca23d3fa585520c674e19d917a.tar.bz2
crosvm-616a093d9197cbca23d3fa585520c674e19d917a.tar.lz
crosvm-616a093d9197cbca23d3fa585520c674e19d917a.tar.xz
crosvm-616a093d9197cbca23d3fa585520c674e19d917a.tar.zst
crosvm-616a093d9197cbca23d3fa585520c674e19d917a.zip
devices: block: allow timerfd syscalls in seccomp
"devices: block: Flush a minute after a write" introduced new timerfd_
syscalls into the block device but did not add them to the seccomp
whitelist.

BUG=chromium:885238
TEST=Run crosvm in multiprocess mode and verify that it boots

Change-Id: I1568946c64d86ab7dba535a430a8cbe235f64454
Signed-off-by: Daniel Verkamp <dverkamp@chromium.org>
Reviewed-on: https://chromium-review.googlesource.com/1231513
Commit-Ready: Dylan Reid <dgreid@chromium.org>
Tested-by: Dylan Reid <dgreid@chromium.org>
Reviewed-by: Dylan Reid <dgreid@chromium.org>
Diffstat (limited to 'seccomp')
-rw-r--r--seccomp/arm/block_device.policy3
-rw-r--r--seccomp/x86_64/block_device.policy3
2 files changed, 6 insertions, 0 deletions
diff --git a/seccomp/arm/block_device.policy b/seccomp/arm/block_device.policy
index 81c94f4..2054d35 100644
--- a/seccomp/arm/block_device.policy
+++ b/seccomp/arm/block_device.policy
@@ -37,3 +37,6 @@ restart_syscall: 1
 epoll_create1: 1
 epoll_ctl: 1
 epoll_wait: 1
+timerfd_create: 1
+timerfd_gettime: 1
+timerfd_settime: 1
diff --git a/seccomp/x86_64/block_device.policy b/seccomp/x86_64/block_device.policy
index fc47fa5..0c7ef63 100644
--- a/seccomp/x86_64/block_device.policy
+++ b/seccomp/x86_64/block_device.policy
@@ -38,3 +38,6 @@ restart_syscall: 1
 epoll_create1: 1
 epoll_ctl: 1
 epoll_wait: 1
+timerfd_create: 1
+timerfd_gettime: 1
+timerfd_settime: 1