crosvm/seccomp/aarch64
Douglas Anderson 3df2a8db60 seccomp: Add memfd_create: arg1 == 3 for arm64
With testing, we're seeing secomp violations on aarch64. We need to
give access to "memfd_create" just like we did for arm32. Copy the
snippet from there.

BUG=b:223410173, b:230609113
TEST=Start arcvm; start android-sh; run tast arc.VMConfig

Change-Id: I4922e6decd67c3bc23fb090987b0318c384e0d68
Reviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform/crosvm/+/3626017
Auto-Submit: Douglas Anderson <dianders@chromium.org>
Reviewed-by: Rob Clark <robdclark@chromium.org>
Tested-by: kokoro <noreply+kokoro@google.com>
Reviewed-by: Daniel Verkamp <dverkamp@chromium.org>
Commit-Queue: Daniel Verkamp <dverkamp@chromium.org>
Reviewed-by: Dennis Kempin <denniskempin@google.com>
2022-05-04 00:22:28 +00:00
..
9p_device.policy
balloon_device.policy
battery.policy
block_device.policy
coiommu.policy coiommu: add LRU unpin policy 2022-01-22 06:47:41 +00:00
common_device.policy seccomp: Fixes needed for aarch64 to allow arcvm to start 2022-04-29 00:05:48 +00:00
cras_audio_device.policy seccomp: allow clock_gettime in all devices 2022-02-22 23:15:48 +00:00
cras_snd_device.policy
fs_device.policy seccomp: add getcwd and readlink to common policy for panic 2021-12-02 23:18:03 +00:00
gpu_common.policy seccomp: Add memfd_create: arg1 == 3 for arm64 2022-05-04 00:22:28 +00:00
gpu_device.policy gpu: allow syslog from the render server 2021-12-14 16:54:22 +00:00
gpu_render_server.policy gpu_render_server: allow syslog and signalfd again 2021-12-22 06:01:25 +00:00
input_device.policy
net_device.policy
null_audio_device.policy seccomp: allow clock_gettime in all devices 2022-02-22 23:15:48 +00:00
pmem_device.policy
rng_device.policy
serial.policy
tpm_device.policy seccomp: use common_device.policy in tpm_device.policy 2022-02-23 19:23:31 +00:00
vhost_net_device.policy
vhost_vsock_device.policy
video_device.policy seccomp: Fixes needed for aarch64 to allow arcvm to start 2022-04-29 00:05:48 +00:00
vios_audio_device.policy seccomp: allow clock_gettime in all devices 2022-02-22 23:15:48 +00:00
wl_device.policy wl: update seccomp policies for SYNC_IOC_FILE_INFO on arm 2021-11-11 19:31:37 +00:00
xhci.policy seccomp: Fixes needed for aarch64 to allow arcvm to start 2022-04-29 00:05:48 +00:00