summary refs log tree commit diff
path: root/seccomp
diff options
context:
space:
mode:
authorJakub Staron <jstaron@google.com>2019-06-10 14:00:07 -0700
committerCommit Bot <commit-bot@chromium.org>2019-06-21 21:47:58 +0000
commitcc91fc825241a3ac5b00693e0be79c50a9528dab (patch)
treeb1d757946c3790b58b0713bf18b07e0f9376a4c1 /seccomp
parentb38bde9bd122aefa01fcc73442b3cd92f18086e9 (diff)
downloadcrosvm-cc91fc825241a3ac5b00693e0be79c50a9528dab.tar
crosvm-cc91fc825241a3ac5b00693e0be79c50a9528dab.tar.gz
crosvm-cc91fc825241a3ac5b00693e0be79c50a9528dab.tar.bz2
crosvm-cc91fc825241a3ac5b00693e0be79c50a9528dab.tar.lz
crosvm-cc91fc825241a3ac5b00693e0be79c50a9528dab.tar.xz
crosvm-cc91fc825241a3ac5b00693e0be79c50a9528dab.tar.zst
crosvm-cc91fc825241a3ac5b00693e0be79c50a9528dab.zip
devices: Add separate seccomp policy for pmem device
This change adds separate seccomp policy for pmem device. Previously,
pmem device was using block device seccomp policy.

BUG=None
TEST=Boot VM and run xfstests on pmem device

Change-Id: I3f25d64d4da6ad8f0ff22b285e1a7e958f545c55
Reviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform/crosvm/+/1652441
Reviewed-by: Stephen Barber <smbarber@chromium.org>
Reviewed-by: Zach Reizner <zachr@chromium.org>
Tested-by: kokoro <noreply+kokoro@google.com>
Commit-Queue: Jakub StaroĊ„ <jstaron@google.com>
Diffstat (limited to 'seccomp')
-rw-r--r--seccomp/arm/pmem_device.policy8
-rw-r--r--seccomp/x86_64/pmem_device.policy8
2 files changed, 16 insertions, 0 deletions
diff --git a/seccomp/arm/pmem_device.policy b/seccomp/arm/pmem_device.policy
new file mode 100644
index 0000000..b3cd64d
--- /dev/null
+++ b/seccomp/arm/pmem_device.policy
@@ -0,0 +1,8 @@
+# Copyright 2019 The Chromium OS Authors. All rights reserved.
+# Use of this source code is governed by a BSD-style license that can be
+# found in the LICENSE file.
+
+@include /usr/share/policy/crosvm/common_device.policy
+
+fdatasync: 1
+fsync: 1
diff --git a/seccomp/x86_64/pmem_device.policy b/seccomp/x86_64/pmem_device.policy
new file mode 100644
index 0000000..b3cd64d
--- /dev/null
+++ b/seccomp/x86_64/pmem_device.policy
@@ -0,0 +1,8 @@
+# Copyright 2019 The Chromium OS Authors. All rights reserved.
+# Use of this source code is governed by a BSD-style license that can be
+# found in the LICENSE file.
+
+@include /usr/share/policy/crosvm/common_device.policy
+
+fdatasync: 1
+fsync: 1