1 |
chutzpah 14/07/08 18:34:25 |
2 |
|
3 |
Added: lldpd-0.7.9-seccomp-add-syscalls.patch |
4 |
Log: |
5 |
Revision bump, add a patch to whitelist some more syscalls in seccomp and remove the pidfile patch. |
6 |
|
7 |
(Portage version: 2.2.10/cvs/Linux x86_64, signed Manifest commit with key 0xE3F69979BB4B8928DA78E3D17CBF44EF) |
8 |
|
9 |
Revision Changes Path |
10 |
1.1 net-misc/lldpd/files/lldpd-0.7.9-seccomp-add-syscalls.patch |
11 |
|
12 |
file : http://sources.gentoo.org/viewvc.cgi/gentoo-x86/net-misc/lldpd/files/lldpd-0.7.9-seccomp-add-syscalls.patch?rev=1.1&view=markup |
13 |
plain: http://sources.gentoo.org/viewvc.cgi/gentoo-x86/net-misc/lldpd/files/lldpd-0.7.9-seccomp-add-syscalls.patch?rev=1.1&content-type=text/plain |
14 |
|
15 |
Index: lldpd-0.7.9-seccomp-add-syscalls.patch |
16 |
=================================================================== |
17 |
diff --git a/src/daemon/priv-seccomp.c b/src/daemon/priv-seccomp.c |
18 |
index 7eb49d6..c69d82a 100644 |
19 |
--- a/src/daemon/priv-seccomp.c |
20 |
+++ b/src/daemon/priv-seccomp.c |
21 |
@@ -160,6 +160,10 @@ priv_seccomp_init(int remote, int child) |
22 |
(rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(stat), 0)) < 0 || |
23 |
(rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(rt_sigreturn), 0)) < 0 || |
24 |
(rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(close), 0)) < 0 || |
25 |
+ (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(sendto), 0)) < 0 || |
26 |
+ (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(poll), 0)) < 0 || |
27 |
+ (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(recvmsg), 0)) < 0 || |
28 |
+ (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(readv), 0)) < 0 || |
29 |
/* The following are for resolving addresses */ |
30 |
(rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(mmap), 0)) < 0 || |
31 |
(rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(munmap), 0)) < 0 || |