Merge branch 'bug15221_027' into maint-0.2.7

This commit is contained in:
Andrea Shepard 2016-03-30 12:23:42 +00:00
commit 183d465f0e
2 changed files with 13 additions and 0 deletions

4
changes/bug15221 Normal file
View File

@ -0,0 +1,4 @@
o Minor bugfixes (sandbox):
- Allow the setrlimit syscall, and the prlimit and prlimit64 syscalls,
which some libc implementations
use under the hood. Fixes bug 15221. Bugfix on 0.2.5.1-alpha.

View File

@ -177,11 +177,20 @@ static int filter_nopar_gen[] = {
SCMP_SYS(mmap),
#endif
SCMP_SYS(munmap),
#ifdef __NR_prlimit
SCMP_SYS(prlimit),
#endif
#ifdef __NR_prlimit64
SCMP_SYS(prlimit64),
#endif
SCMP_SYS(read),
SCMP_SYS(rt_sigreturn),
SCMP_SYS(sched_getaffinity),
SCMP_SYS(sendmsg),
SCMP_SYS(set_robust_list),
#ifdef __NR_setrlimit
SCMP_SYS(setrlimit),
#endif
#ifdef __NR_sigreturn
SCMP_SYS(sigreturn),
#endif