crosvm/seccomp/x86_64
Takaya Saeki e299f02d3f seccomp: allow clone3 to video_device on x86
Recently, common_device.policy added clone3. It is included by most
devices through include, but the video device missed it since it doesn't
include common_device.policy due to some policy override.

This commit adds clone3 to the policy of the video device to fix that
problem. With this fix, the video device successfully runs in the
sandbox on newer kernels.

BUG=None
TEST=a vm with a video device launches with the sandbox enabled

Change-Id: Idc2dee824e863f3ee43cfd6ce76656e36d6200c0
Reviewed-on: https://chromium-review.googlesource.com/c/crosvm/crosvm/+/4053447
Reviewed-by: Keiichi Watanabe <keiichiw@chromium.org>
Commit-Queue: Takaya Saeki <takayas@chromium.org>
2022-11-24 09:40:27 +00:00
..
9p_device.policy seccomp: add lseek to all devices 2022-10-18 06:39:41 +00:00
balloon_device.policy
battery.policy
block.policy seccomp: add lseek to all devices 2022-10-18 06:39:41 +00:00
block_device.policy
block_device_vhost_user.policy
block_device_vvu.policy
coiommu_device.policy
common_device.frequency
common_device.policy seccomp: add lseek to all devices 2022-10-18 06:39:41 +00:00
constants.json Generate constants.json offline 2022-11-02 00:13:08 +00:00
cras_audio_device.policy seccomp: add lseek to all devices 2022-10-18 06:39:41 +00:00
fs_device.policy seccomp: add lseek to all devices 2022-10-18 06:39:41 +00:00
gpu_common.policy Add clone3 to virtio-gpu device policy too 2022-10-28 16:26:34 +00:00
gpu_device.policy
gpu_render_server.policy
input_device.policy
iommu_device.policy
net_device.policy
null_audio_device.policy seccomp: add lseek to all devices 2022-10-18 06:39:41 +00:00
pmem_device.policy
rng_device.policy
serial.policy
serial_device.policy
serial_device_vhost_user.policy seccomp: add lseek to all devices 2022-10-18 06:39:41 +00:00
serial_device_vvu.policy
snd_cras_device.policy
snd_null_device.policy
tpm_device.policy seccomp: add lseek to all devices 2022-10-18 06:39:41 +00:00
vfio_device.policy
vhost_net_device.policy
vhost_user.policy seccomp: add lseek to all devices 2022-10-18 06:39:41 +00:00
vhost_vsock_device.policy
video_device.policy seccomp: allow clone3 to video_device on x86 2022-11-24 09:40:27 +00:00
vios_audio_device.policy seccomp: add lseek to all devices 2022-10-18 06:39:41 +00:00
vtpm_proxy_device.policy
vvu.policy
vvu_proxy_device.policy
wl_device.policy
xhci_device.policy seccomp: add lseek to all devices 2022-10-18 06:39:41 +00:00