seccomp: adding getrusage to the whitelist
getrusage is used in a number of places throughout the qemu codebase (notably, in crypto/pbkdf.c). Without this syscall being whitelisted, qemu ends up getting killed by the kernel whenever you try to connect to a VNC console. Signed-off-by: Brian Rak <brak@gameservers.com> Acked-by: Eduardo Otubo <eduardo.otubo@profitbricks.com>
This commit is contained in:
		
							parent
							
								
									a008535b9f
								
							
						
					
					
						commit
						cf9dc9e480
					
				| @ -65,6 +65,7 @@ static const struct QemuSeccompSyscall seccomp_whitelist[] = { | ||||
|     { SCMP_SYS(prctl), 245 }, | ||||
|     { SCMP_SYS(signalfd), 245 }, | ||||
|     { SCMP_SYS(getrlimit), 245 }, | ||||
|     { SCMP_SYS(getrusage), 245 }, | ||||
|     { SCMP_SYS(set_tid_address), 245 }, | ||||
|     { SCMP_SYS(statfs), 245 }, | ||||
|     { SCMP_SYS(unlink), 245 }, | ||||
|  | ||||
		Loading…
	
	
			
			x
			
			
		
	
		Reference in New Issue
	
	Block a user
	 Eduardo Otubo
						Eduardo Otubo