diff --git a/seccomp/aarch64/gpu_render_server.policy b/seccomp/aarch64/gpu_render_server.policy index 007c45bc67..c2a602a6fd 100644 --- a/seccomp/aarch64/gpu_render_server.policy +++ b/seccomp/aarch64/gpu_render_server.policy @@ -8,8 +8,13 @@ clone: 1 waitid: 1 +# allow vsyslog +send: 1 # allow SOCK_STREAM and SOCK_DGRAM (syslog) socket: arg0 == AF_UNIX && arg2 == 0 # allow socketpair(AF_UNIX, SOCK_SEQPACKET | SOCK_CLOEXEC) socketpair: arg0 == AF_UNIX && arg1 == SOCK_SEQPACKET|SOCK_CLOEXEC && arg2 == 0 + +# allow signalfd() +signalfd4: 1 diff --git a/seccomp/arm/gpu_render_server.policy b/seccomp/arm/gpu_render_server.policy index 007c45bc67..c2a602a6fd 100644 --- a/seccomp/arm/gpu_render_server.policy +++ b/seccomp/arm/gpu_render_server.policy @@ -8,8 +8,13 @@ clone: 1 waitid: 1 +# allow vsyslog +send: 1 # allow SOCK_STREAM and SOCK_DGRAM (syslog) socket: arg0 == AF_UNIX && arg2 == 0 # allow socketpair(AF_UNIX, SOCK_SEQPACKET | SOCK_CLOEXEC) socketpair: arg0 == AF_UNIX && arg1 == SOCK_SEQPACKET|SOCK_CLOEXEC && arg2 == 0 + +# allow signalfd() +signalfd4: 1 diff --git a/seccomp/x86_64/gpu_render_server.policy b/seccomp/x86_64/gpu_render_server.policy index 007c45bc67..536d43dd4f 100644 --- a/seccomp/x86_64/gpu_render_server.policy +++ b/seccomp/x86_64/gpu_render_server.policy @@ -13,3 +13,6 @@ socket: arg0 == AF_UNIX && arg2 == 0 # allow socketpair(AF_UNIX, SOCK_SEQPACKET | SOCK_CLOEXEC) socketpair: arg0 == AF_UNIX && arg1 == SOCK_SEQPACKET|SOCK_CLOEXEC && arg2 == 0 + +# allow signalfd() +signalfd4: 1