From e742c70edcbb0275d02fd592612b32958dfc9197 Mon Sep 17 00:00:00 2001 From: Douglas Anderson Date: Fri, 6 May 2022 13:44:59 -0700 Subject: [PATCH] seccomp: Add io_uring_setup / io_uring_enter to gpu_common.policy The top part of gpu_common.policy is supposed to match common_device.policy. In https://crrev.com/c/1993163 we added io_uring_setup and io_uring_enter to common_device.policy. Even though there's nothing known to be broken, add these to the gpu_common.policy to keep things matching. BUG=None TEST=kokoro Change-Id: Ifd4c53c50ec12eb7e1e14f7eb80d2c9b8f0fbe46 Reviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform/crosvm/+/3631411 Reviewed-by: Daniel Verkamp Tested-by: kokoro Commit-Queue: Douglas Anderson --- seccomp/aarch64/gpu_common.policy | 2 ++ seccomp/arm/gpu_common.policy | 2 ++ seccomp/x86_64/gpu_common.policy | 2 ++ 3 files changed, 6 insertions(+) diff --git a/seccomp/aarch64/gpu_common.policy b/seccomp/aarch64/gpu_common.policy index c20045dac5..1798ebd367 100644 --- a/seccomp/aarch64/gpu_common.policy +++ b/seccomp/aarch64/gpu_common.policy @@ -20,6 +20,8 @@ getcwd: 1 getpid: 1 gettid: 1 gettimeofday: 1 +io_uring_setup: 1 +io_uring_enter: 1 kill: 1 madvise: arg2 == MADV_DONTNEED || arg2 == MADV_DONTDUMP || arg2 == MADV_REMOVE mremap: 1 diff --git a/seccomp/arm/gpu_common.policy b/seccomp/arm/gpu_common.policy index ed9a6c5b55..c4e7628435 100644 --- a/seccomp/arm/gpu_common.policy +++ b/seccomp/arm/gpu_common.policy @@ -20,6 +20,8 @@ getcwd: 1 getpid: 1 gettid: 1 gettimeofday: 1 +io_uring_setup: 1 +io_uring_enter: 1 kill: 1 madvise: arg2 == MADV_DONTNEED || arg2 == MADV_DONTDUMP || arg2 == MADV_REMOVE mremap: 1 diff --git a/seccomp/x86_64/gpu_common.policy b/seccomp/x86_64/gpu_common.policy index f02ed9547b..a8ca3f18e3 100644 --- a/seccomp/x86_64/gpu_common.policy +++ b/seccomp/x86_64/gpu_common.policy @@ -20,6 +20,8 @@ getcwd: 1 getpid: 1 gettid: 1 gettimeofday: 1 +io_uring_setup: 1 +io_uring_enter: 1 kill: 1 madvise: arg2 == MADV_DONTNEED || arg2 == MADV_DONTDUMP || arg2 == MADV_REMOVE mremap: 1