seccomp: changing from whitelist to blacklist
authorEduardo Otubo <otubo@redhat.com>
Tue, 28 Feb 2017 20:13:12 +0000 (21:13 +0100)
committerEduardo Otubo <otubo@redhat.com>
Fri, 15 Sep 2017 08:13:35 +0000 (10:13 +0200)
commit1bd6152ae23549032ef4aca0d3d350512f012f05
treef3f5a4509e206f1e529953b48232b50e5099f8e8
parent3dabde1128b671f36ac6cb36b97b273139964420
seccomp: changing from whitelist to blacklist

This patch changes the default behavior of the seccomp filter from
whitelist to blacklist. By default now all system calls are allowed and
a small black list of definitely forbidden ones was created.

Signed-off-by: Eduardo Otubo <otubo@redhat.com>
include/sysemu/seccomp.h
qemu-seccomp.c
vl.c