]> git.ipfire.org Git - thirdparty/openssh-portable.git/commitdiff
Add __NR_futex_time64 to seccomp sandbox.
authorDarren Tucker <dtucker@dtucker.net>
Wed, 10 Feb 2021 23:18:05 +0000 (10:18 +1100)
committerDarren Tucker <dtucker@dtucker.net>
Wed, 10 Feb 2021 23:18:05 +0000 (10:18 +1100)
This is apparently needed for (some) 32 bit platforms with glibc 2.33.
Patch from nix at esperi.org.uk and jjelen at redhat.com via bz#3260.

sandbox-seccomp-filter.c

index d942b5e167afc2f476f651299a59a8def32fed50..d8dc7120bdd42f56bab21d7f2e2a3683293e7183 100644 (file)
@@ -207,6 +207,9 @@ static const struct sock_filter preauth_insns[] = {
 #ifdef __NR_futex
        SC_ALLOW(__NR_futex),
 #endif
+#ifdef __NR_futex_time64
+       SC_ALLOW(__NR_futex_time64),
+#endif
 #ifdef __NR_geteuid
        SC_ALLOW(__NR_geteuid),
 #endif