From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:56410) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1VOCBz-0006iT-Lk for qemu-devel@nongnu.org; Mon, 23 Sep 2013 15:53:17 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1VOCBt-0003jl-MR for qemu-devel@nongnu.org; Mon, 23 Sep 2013 15:53:11 -0400 Received: from mx1.redhat.com ([209.132.183.28]:59552) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1VOCBt-0003jd-Es for qemu-devel@nongnu.org; Mon, 23 Sep 2013 15:53:05 -0400 From: Paul Moore Date: Mon, 23 Sep 2013 15:53 -0400 Message-ID: <4499280.frTC6rkUMv@sifl> In-Reply-To: <1530529.70Yh7p4t0h@sifl> References: <1378297508-7242-1-git-send-email-otubo@linux.vnet.ibm.com> <1530529.70Yh7p4t0h@sifl> MIME-Version: 1.0 Content-Transfer-Encoding: 7Bit Content-Type: text/plain; charset="us-ascii" Subject: Re: [Qemu-devel] [PATCH] seccomp: adding times() to the whitelist List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Eduardo Otubo Cc: coreyb@linux.vnet.ibm.com, qemu-devel@nongnu.org On Wednesday, September 04, 2013 10:11:10 AM Paul Moore wrote: > On Wednesday, September 04, 2013 09:25:08 AM Eduardo Otubo wrote: > > This was causing Qemu process to hang when using -sandbox on. > > > > Related RHBZ: https://bugzilla.redhat.com/show_bug.cgi?id=1004175 > > > > Signed-off-by: Eduardo Otubo > > Works for me. > > Tested-by: Paul Moore Eduardo, perhaps you should just merge this into your tree and send a pull request? This fix should also go into -stable. Acked-by: Paul Moore > > --- > > > > qemu-seccomp.c | 1 + > > 1 files changed, 1 insertions(+), 0 deletions(-) > > > > diff --git a/qemu-seccomp.c b/qemu-seccomp.c > > index 37d38f8..69cee44 100644 > > --- a/qemu-seccomp.c > > +++ b/qemu-seccomp.c > > @@ -90,6 +90,7 @@ static const struct QemuSeccompSyscall > > seccomp_whitelist[] = { { SCMP_SYS(getuid), 245 }, > > > > { SCMP_SYS(geteuid), 245 }, > > { SCMP_SYS(timer_create), 245 }, > > > > + { SCMP_SYS(times), 245 }, > > > > { SCMP_SYS(exit), 245 }, > > { SCMP_SYS(clock_gettime), 245 }, > > { SCMP_SYS(time), 245 }, -- paul moore security and virtualization @ redhat