From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([208.118.235.92]:50564) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1TUIPY-0008WK-6J for qemu-devel@nongnu.org; Fri, 02 Nov 2012 10:39:53 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1TUIPW-00044R-Ib for qemu-devel@nongnu.org; Fri, 02 Nov 2012 10:39:52 -0400 Received: from mx1.redhat.com ([209.132.183.28]:6811) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1TUIPW-00044G-92 for qemu-devel@nongnu.org; Fri, 02 Nov 2012 10:39:50 -0400 From: Paul Moore Date: Fri, 02 Nov 2012 10:38:36 -0400 Message-ID: <71154882.oGSYjfIaYl@sifl> In-Reply-To: <1504387.Ke9l4MHn56@sifl> References: <1350971732-16621-1-git-send-email-otubo@linux.vnet.ibm.com> <5093CF47.9030401@linux.vnet.ibm.com> <1504387.Ke9l4MHn56@sifl> MIME-Version: 1.0 Content-Transfer-Encoding: 7Bit Content-Type: text/plain; charset="us-ascii" Subject: Re: [Qemu-devel] [PATCHv2 1/4] Adding new syscalls (bugzilla 855162) List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Corey Bryant , Eduardo Otubo Cc: aliguori@us.ibm.com, qemu-devel@nongnu.org On Friday, November 02, 2012 10:10:02 AM Paul Moore wrote: > On Friday, November 02, 2012 09:48:55 AM Corey Bryant wrote: > > On 11/01/2012 05:43 PM, Paul Moore wrote: > > > On Tuesday, October 23, 2012 03:55:29 AM Eduardo Otubo wrote: > > >> According to the bug 855162[0] - there's the need of adding new > > >> syscalls > > >> to the whitelist whenn using Qemu with Libvirt. > > >> > > >> [0] - https://bugzilla.redhat.com/show_bug.cgi?id=855162 > > >> > > >> v2: Adding new syscalls to the list: readlink, rt_sigpending, and > > >> > > >> rt_sigtimedwait > > >> > > >> Reported-by: Paul Moore > > >> Signed-off-by: Eduardo Otubo > > >> --- > > >> > > >> qemu-seccomp.c | 13 ++++++++++++- > > >> 1 file changed, 12 insertions(+), 1 deletion(-) > > > > > > I had an opportunity to test this patchset on a F17 machine using QEMU > > > 1.2 > > > and unfortunately it still fails. I'm using a relatively basic guest > > > configuration running F16, the details are documented in the RH BZ that > > > Eduardo mentioned in the patch description. > > > > Paul, Here's the latest diff for the whitelist. We're looking to get > > the patches out in the next few days after a bit more testing. > > Okay, thanks for the updated list ... I'm rebuilding QEMU right now and I'll > report back with the results later today. Sadly, no luck, it still fails. -- paul moore security and virtualization @ redhat