From 78ff88e7bca018539829f37a2131a55c98b30fa9 Mon Sep 17 00:00:00 2001 From: Dennis Kempin Date: Tue, 21 Dec 2021 19:37:12 +0000 Subject: [PATCH] Revert "gpu_render_server: allow syslog and signalfd" This reverts commit 7a4e207896ac087041eff755c489ed05ff5df780. Reason for revert: Fails on aarch64, the send syscall does not exist. See http://go/bbid/8827215539398029665 Original change's description: > gpu_render_server: allow syslog and signalfd > > BUG=b:211008411 > BUG=b:210908665 > TEST=venus on kukui-arc-r > > Change-Id: I541277b0be64a96a26ee6745ea759679e6dc5230 > Reviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform/crosvm/+/3344109 > Tested-by: kokoro > Reviewed-by: Daniel Verkamp > Reviewed-by: Chia-I Wu > Commit-Queue: Yiwei Zhang Bug: b:211008411 Bug: b:210908665 Change-Id: Ia838bde85c5e5f7c70a051b55735bb18b75c3d77 Reviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform/crosvm/+/3352488 Bot-Commit: Rubber Stamper --- seccomp/aarch64/gpu_render_server.policy | 5 ----- seccomp/arm/gpu_render_server.policy | 5 ----- seccomp/x86_64/gpu_render_server.policy | 3 --- 3 files changed, 13 deletions(-) diff --git a/seccomp/aarch64/gpu_render_server.policy b/seccomp/aarch64/gpu_render_server.policy index c2a602a6fd..007c45bc67 100644 --- a/seccomp/aarch64/gpu_render_server.policy +++ b/seccomp/aarch64/gpu_render_server.policy @@ -8,13 +8,8 @@ clone: 1 waitid: 1 -# allow vsyslog -send: 1 # allow SOCK_STREAM and SOCK_DGRAM (syslog) socket: arg0 == AF_UNIX && arg2 == 0 # allow socketpair(AF_UNIX, SOCK_SEQPACKET | SOCK_CLOEXEC) socketpair: arg0 == AF_UNIX && arg1 == SOCK_SEQPACKET|SOCK_CLOEXEC && arg2 == 0 - -# allow signalfd() -signalfd4: 1 diff --git a/seccomp/arm/gpu_render_server.policy b/seccomp/arm/gpu_render_server.policy index c2a602a6fd..007c45bc67 100644 --- a/seccomp/arm/gpu_render_server.policy +++ b/seccomp/arm/gpu_render_server.policy @@ -8,13 +8,8 @@ clone: 1 waitid: 1 -# allow vsyslog -send: 1 # allow SOCK_STREAM and SOCK_DGRAM (syslog) socket: arg0 == AF_UNIX && arg2 == 0 # allow socketpair(AF_UNIX, SOCK_SEQPACKET | SOCK_CLOEXEC) socketpair: arg0 == AF_UNIX && arg1 == SOCK_SEQPACKET|SOCK_CLOEXEC && arg2 == 0 - -# allow signalfd() -signalfd4: 1 diff --git a/seccomp/x86_64/gpu_render_server.policy b/seccomp/x86_64/gpu_render_server.policy index 536d43dd4f..007c45bc67 100644 --- a/seccomp/x86_64/gpu_render_server.policy +++ b/seccomp/x86_64/gpu_render_server.policy @@ -13,6 +13,3 @@ socket: arg0 == AF_UNIX && arg2 == 0 # allow socketpair(AF_UNIX, SOCK_SEQPACKET | SOCK_CLOEXEC) socketpair: arg0 == AF_UNIX && arg1 == SOCK_SEQPACKET|SOCK_CLOEXEC && arg2 == 0 - -# allow signalfd() -signalfd4: 1