crosvm/seccomp/x86_64
Jordan R Abrahams ff7f1ae9fe seccomp: Add statx to video_device.policy for glibc
With the new glibc 2.33 roll, we're seeing crashes live relating to
statx (syscall 397). The process that's crashing is pcivirtio-video,
so we suspect video_device.policy is the breaking policy.

Crash report: http://shortn/_4EWpF4q77O

This was very recently fixed in arm (where the original crash occured),
however, it's still missing in the amd64/x86_64 policy file. It's
very feasible we'll see a similar case in the future with this arch.

BUG=b:187795909
TEST=CQ

Change-Id: I7b02ccf02d214590aadc37dc53e00ad34e178a4a
Reviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform/crosvm/+/3291890
Auto-Submit: Jordan R Abrahams <ajordanr@google.com>
Commit-Queue: Manoj Gupta <manojgupta@chromium.org>
Tested-by: kokoro <noreply+kokoro@google.com>
Reviewed-by: Chirantan Ekbote <chirantan@chromium.org>
Reviewed-by: Manoj Gupta <manojgupta@chromium.org>
2021-11-19 04:18:27 +00:00
..
9p_device.policy
balloon_device.policy
battery.policy
block_device.policy seccomp: allow newfstatat in more amd64/arm64 policies 2021-10-01 17:09:16 +00:00
common_device.frequency
common_device.policy Allow sched_yield in all devices' seccomp policy 2021-10-28 19:10:45 +00:00
cras_audio_device.policy ac97: Add timerfd operations to accepted list 2021-07-23 18:43:21 +00:00
cras_snd_device.policy seccomp: Add timerfd_* to cras_snd_device.policy 2021-10-11 05:10:11 +00:00
fs_device.policy seccomp: Add unshare to fs device policy 2021-11-11 13:38:11 +00:00
gpu_device.policy Allow sched_yield in all devices' seccomp policy 2021-10-28 19:10:45 +00:00
input_device.policy
iommu_device.policy devices: virtio: iommu: enable virtio IOMMU driver 2021-07-09 05:49:26 +00:00
net_device.policy
null_audio_device.policy
pmem_device.policy
rng_device.policy
serial.policy
tpm_device.policy seccomp: allow newfstatat in more amd64/arm64 policies 2021-10-01 17:09:16 +00:00
vfio_device.policy
vhost_net_device.policy
vhost_vsock_device.policy
video_device.policy seccomp: Add statx to video_device.policy for glibc 2021-11-19 04:18:27 +00:00
vios_audio_device.policy
wl_device.policy wl: add support for host fences 2021-11-04 01:24:37 +00:00
xhci.policy seccomp: allow newfstatat in more amd64/arm64 policies 2021-10-01 17:09:16 +00:00