Whitelist clock_gettime() for seccomp. Not necessary so long as vdso

is enabled, but otherwise...
This commit is contained in:
Nicholas J. Kain 2012-07-21 19:46:50 -04:00
parent b53b8585d5
commit 7d5b6ddc7e

View File

@ -134,6 +134,7 @@ static int enforce_seccomp(void)
ALLOW_SYSCALL(sendto), // used for glibc syslog routines ALLOW_SYSCALL(sendto), // used for glibc syslog routines
ALLOW_SYSCALL(epoll_wait), ALLOW_SYSCALL(epoll_wait),
ALLOW_SYSCALL(epoll_ctl), ALLOW_SYSCALL(epoll_ctl),
ALLOW_SYSCALL(clock_gettime),
ALLOW_SYSCALL(close), ALLOW_SYSCALL(close),
ALLOW_SYSCALL(socket), ALLOW_SYSCALL(socket),
ALLOW_SYSCALL(getsockopt), ALLOW_SYSCALL(getsockopt),