mirror of
https://chromium.googlesource.com/crosvm/crosvm
synced 2025-01-19 13:44:22 +00:00
1f77a0daa6
By using libc's openlog, we can ensure that the internal state of the libc syslogger is consistent with the syslog module. Minijail will be able to print to stderr and the syslog in the same way the logging macros in crosvm do. The FD the syslog module uses is shared with libc and via `syslog::get_fds`, jailed processes can inherit the needed FDs to continue logging. Now that `sys_log::init()` must be called in single threaded process, this moves its tests to the list of the serially run ones in build_test.py. TEST=./build_test BUG=None Change-Id: I8dbc8ebf9d97ef670185259eceac5f6d3d6824ea Reviewed-on: https://chromium-review.googlesource.com/649951 Commit-Ready: Zach Reizner <zachr@chromium.org> Tested-by: Zach Reizner <zachr@chromium.org> Reviewed-by: Jason Clinton <jclinton@chromium.org> Reviewed-by: Dylan Reid <dgreid@chromium.org>
40 lines
1.4 KiB
Text
40 lines
1.4 KiB
Text
# Copyright 2017 The Chromium OS Authors. All rights reserved.
|
|
# Use of this source code is governed by a BSD-style license that can be
|
|
# found in the LICENSE file.
|
|
|
|
close: 1
|
|
exit_group: 1
|
|
futex: 1
|
|
# Whitelist vhost_net ioctls only.
|
|
# arg1 == VHOST_GET_FEATURES ||
|
|
# arg1 == VHOST_SET_FEATURES ||
|
|
# arg1 == VHOST_SET_OWNER ||
|
|
# arg1 == VHOST_RESET_OWNER ||
|
|
# arg1 == VHOST_SET_MEM_TABLE ||
|
|
# arg1 == VHOST_SET_LOG_BASE ||
|
|
# arg1 == VHOST_SET_LOG_FD ||
|
|
# arg1 == VHOST_SET_VRING_NUM ||
|
|
# arg1 == VHOST_SET_VRING_ADDR ||
|
|
# arg1 == VHOST_SET_VRING_BASE ||
|
|
# arg1 == VHOST_GET_VRING_BASE ||
|
|
# arg1 == VHOST_SET_VRING_KICK ||
|
|
# arg1 == VHOST_SET_VRING_CALL ||
|
|
# arg1 == VHOST_SET_VRING_ERR ||
|
|
# arg1 == VHOST_NET_SET_BACKEND
|
|
ioctl: arg1 == 0x8008af00 || arg1 == 0x4008af00 || arg1 == 0x0000af01 || arg1 == 0x0000af02 || arg1 == 0x4008af03 || arg1 == 0x4008af04 || arg1 == 0x4004af07 || arg1 == 0x4008af10 || arg1 == 0x4028af11 || arg1 == 0x4008af12 || arg1 == 0xc008af12 || arg1 == 0x4008af20 || arg1 == 0x4008af21 || arg1 == 0x4008af22 || arg1 == 0x4008af30
|
|
# Disallow mmap with PROT_EXEC set. The syntax here doesn't allow bit
|
|
# negation, thus the manually negated mask constant.
|
|
mmap: arg2 in 0xfffffffb
|
|
mprotect: arg2 in 0xfffffffb
|
|
munmap: 1
|
|
poll: 1
|
|
read: 1
|
|
recvfrom: 1
|
|
sched_getaffinity: 1
|
|
set_robust_list: 1
|
|
sigaltstack: 1
|
|
# Disallow clone's other than new threads.
|
|
# arg0 is flags. Because kernel.
|
|
clone: arg0 & 0x00010000
|
|
write: 1
|
|
getpid: 1
|