diff mbox

seccomp: add mlockall to whitelist

Message ID 1421760753-2678-1-git-send-email-pbonzini@redhat.com
State New
Headers show

Commit Message

Paolo Bonzini Jan. 20, 2015, 1:32 p.m. UTC
This is used by "-realtime mlock=on".

Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
---
 qemu-seccomp.c | 1 +
 1 file changed, 1 insertion(+)

Comments

Amit Shah Jan. 21, 2015, 7:43 a.m. UTC | #1
On (Tue) 20 Jan 2015 [14:32:33], Paolo Bonzini wrote:
> This is used by "-realtime mlock=on".
> 
> Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>

Reviewed-by: Amit Shah <amit.shah@redhat.com>

		Amit
Eduardo Otubo Jan. 21, 2015, 2:16 p.m. UTC | #2
On Tue, Jan 20, 2015 at 02:32:33PM +0100, Paolo Bonzini wrote:
> This is used by "-realtime mlock=on".
> 
> Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
> ---
>  qemu-seccomp.c | 1 +
>  1 file changed, 1 insertion(+)
> 
> diff --git a/qemu-seccomp.c b/qemu-seccomp.c
> index b0c6269..f9de0d3 100644
> --- a/qemu-seccomp.c
> +++ b/qemu-seccomp.c
> @@ -229,6 +229,7 @@ static const struct QemuSeccompSyscall seccomp_whitelist[] = {
>      { SCMP_SYS(shmdt), 240 },
>      { SCMP_SYS(timerfd_create), 240 },
>      { SCMP_SYS(shmctl), 240 },
> +    { SCMP_SYS(mlockall), 240 },
>      { SCMP_SYS(mlock), 240 },
>      { SCMP_SYS(munlock), 240 },
>      { SCMP_SYS(semctl), 240 },
> -- 
> 2.1.0
> 

Signed-off-by: Eduardo Otubo <eduardo.otubo@profitbricks.com>
Acked-by: Eduardo Otubo <eduardo.otubo@profitbricks.com>

I'll make a pull request by Friday at the end of the day. Thanks for the
patch.
Eduardo Habkost Jan. 21, 2015, 3:03 p.m. UTC | #3
On Tue, Jan 20, 2015 at 02:32:33PM +0100, Paolo Bonzini wrote:
> This is used by "-realtime mlock=on".
> 
> Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>

Reviewed-by: Eduardo Habkost <ehabkost@redhat.com>
Tested-by: Eduardo Habkost <ehabkost@redhat.com>
diff mbox

Patch

diff --git a/qemu-seccomp.c b/qemu-seccomp.c
index b0c6269..f9de0d3 100644
--- a/qemu-seccomp.c
+++ b/qemu-seccomp.c
@@ -229,6 +229,7 @@  static const struct QemuSeccompSyscall seccomp_whitelist[] = {
     { SCMP_SYS(shmdt), 240 },
     { SCMP_SYS(timerfd_create), 240 },
     { SCMP_SYS(shmctl), 240 },
+    { SCMP_SYS(mlockall), 240 },
     { SCMP_SYS(mlock), 240 },
     { SCMP_SYS(munlock), 240 },
     { SCMP_SYS(semctl), 240 },