]> git.ipfire.org Git - thirdparty/systemd.git/commitdiff
seccomp: add rseq() to default list of syscalls to whitelist
authorLennart Poettering <lennart@poettering.net>
Thu, 28 Mar 2019 09:01:09 +0000 (10:01 +0100)
committerLennart Poettering <lennart@poettering.net>
Thu, 28 Mar 2019 11:09:38 +0000 (12:09 +0100)
Apparently glibc is going to call this implicitly soon, hence let's
whitelist this by default.

Fixes: #12127
src/shared/seccomp-util.c

index 905be0f6a917f7d266ccefa4649c547d4fe68f54..ba3f433106bd20ee3c43467df8322e418de14f20 100644 (file)
@@ -291,6 +291,7 @@ const SyscallFilterSet syscall_filter_sets[_SYSCALL_FILTER_SET_MAX] = {
                 "pause\0"
                 "prlimit64\0"
                 "restart_syscall\0"
+                "rseq\0"
                 "rt_sigreturn\0"
                 "sched_yield\0"
                 "set_robust_list\0"