This patch adds [,resourcecontrol=deny] to `-sandbox on' option. It blacklists all process affinity and scheduler priority system calls to avoid any bigger of the process. Signed-off-by: Eduardo Otubo <otubo@redhat.com> |
||
|---|---|---|
| .. | ||
| accel.h | ||
| arch_init.h | ||
| balloon.h | ||
| block-backend.h | ||
| blockdev.h | ||
| bt.h | ||
| cpus.h | ||
| cryptodev.h | ||
| device_tree.h | ||
| dma.h | ||
| dump-arch.h | ||
| dump.h | ||
| hax.h | ||
| hostmem.h | ||
| hw_accel.h | ||
| iothread.h | ||
| kvm.h | ||
| kvm_int.h | ||
| memory_mapping.h | ||
| numa.h | ||
| os-posix.h | ||
| os-win32.h | ||
| qtest.h | ||
| replay.h | ||
| reset.h | ||
| rng-random.h | ||
| rng.h | ||
| seccomp.h | ||
| sysemu.h | ||
| tpm.h | ||
| tpm_backend.h | ||
| tpm_backend_int.h | ||
| watchdog.h | ||
| xen-mapcache.h | ||