seccomp: adding getrusage to the whitelist
getrusage is used in a number of places throughout the qemu codebase (notably, in crypto/pbkdf.c). Without this syscall being whitelisted, qemu ends up getting killed by the kernel whenever you try to connect to a VNC console. Signed-off-by: Brian Rak <brak@gameservers.com> Acked-by: Eduardo Otubo <eduardo.otubo@profitbricks.com>
This commit is contained in:
		
							parent
							
								
									a008535b9f
								
							
						
					
					
						commit
						cf9dc9e480
					
				| 
						 | 
				
			
			@ -65,6 +65,7 @@ static const struct QemuSeccompSyscall seccomp_whitelist[] = {
 | 
			
		|||
    { SCMP_SYS(prctl), 245 },
 | 
			
		||||
    { SCMP_SYS(signalfd), 245 },
 | 
			
		||||
    { SCMP_SYS(getrlimit), 245 },
 | 
			
		||||
    { SCMP_SYS(getrusage), 245 },
 | 
			
		||||
    { SCMP_SYS(set_tid_address), 245 },
 | 
			
		||||
    { SCMP_SYS(statfs), 245 },
 | 
			
		||||
    { SCMP_SYS(unlink), 245 },
 | 
			
		||||
| 
						 | 
				
			
			
 | 
			
		|||
		Loading…
	
		Reference in New Issue