crosvm/seccomp/x86_64
Yusuke Sato 1617c21918 seccomp: Allow 9p device to use open/openat
This allows us to use export a directory to a VM with the
'--shared-dir tag:/dir' crosvm command line flag without relying
on seneschal. The fs device's policy already does the same.

BUG=b:123309049
TEST=Start tot ARCVM, run 'mkdir /var/run/arc/arcvm && mount -t 9p
  -o "trans=virtio,version=9p2000.L,cache=none,access=any"
  host_generated /var/run/arc/arcvm && ls /var/run/arc/arcvm',
  verify ls prints files.

Change-Id: I8f8b265fc8a7de159508afbee5114b6a3f084d01
Reviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform/crosvm/+/1995319
Tested-by: Yusuke Sato <yusukes@chromium.org>
Tested-by: kokoro <noreply+kokoro@google.com>
Reviewed-by: Lepton Wu <lepton@chromium.org>
Reviewed-by: Chirantan Ekbote <chirantan@chromium.org>
Commit-Queue: Yusuke Sato <yusukes@chromium.org>
2020-01-13 21:26:19 +00:00
..
9p_device.policy seccomp: Allow 9p device to use open/openat 2020-01-13 21:26:19 +00:00
balloon_device.policy
block_device.policy sys_util: add WriteZeroesAt trait 2019-11-27 21:22:37 +00:00
common_device.policy seccomp: move gettid to common_device.policy 2019-12-06 03:21:11 +00:00
cras_audio_device.policy seccomp: Allow clock_gettime for audio device 2019-12-07 02:51:17 +00:00
fs_device.policy devices: fs: Support fs crypto ioctls 2019-12-10 03:10:57 +00:00
gpu_device.policy
input_device.policy
net_device.policy devices: net: add control queue for enabling/disabling offloads 2020-01-08 23:10:13 +00:00
null_audio_device.policy
pmem_device.policy
rng_device.policy
serial.policy devices: jail serial device 2019-10-10 02:09:13 +00:00
tpm_device.policy
vfio_device.policy
vhost_net_device.policy
vhost_vsock_device.policy
wl_device.policy
xhci.policy seccomp: move gettid to common_device.policy 2019-12-06 03:21:11 +00:00