mirror of
https://github.com/cloud-hypervisor/cloud-hypervisor.git
synced 2025-02-22 11:22:26 +00:00
vmm: seccomp: add mprotect to API thread filter
Add mprotect to API thread rules. Prevent the VMM is killed when it is used. Signed-off-by: Jose Carlos Venegas Munoz <jose.carlos.venegas.munoz@intel.com>
This commit is contained in:
parent
743ebe2fa6
commit
90acb01bad
@ -363,6 +363,7 @@ fn api_thread_rules() -> Result<Vec<SyscallRuleSet>, Error> {
|
||||
allow_syscall_if(libc::SYS_ioctl, create_api_ioctl_seccomp_rule()?),
|
||||
allow_syscall(libc::SYS_listen),
|
||||
allow_syscall(libc::SYS_madvise),
|
||||
allow_syscall(libc::SYS_mprotect),
|
||||
allow_syscall(libc::SYS_munmap),
|
||||
allow_syscall(libc::SYS_recvfrom),
|
||||
allow_syscall(libc::SYS_sigaltstack),
|
||||
|
Loading…
x
Reference in New Issue
Block a user