seccomp: add mlockall to whitelist
authorPaolo Bonzini <pbonzini@redhat.com>
Tue, 20 Jan 2015 13:32:33 +0000 (14:32 +0100)
committerEduardo Otubo <eduardo.otubo@profitbricks.com>
Fri, 23 Jan 2015 13:07:08 +0000 (14:07 +0100)
This is used by "-realtime mlock=on".

Signed-off-by: Eduardo Otubo <eduardo.otubo@profitbricks.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Reviewed-by: Amit Shah <amit.shah@redhat.com>
Reviewed-by: Eduardo Habkost <ehabkost@redhat.com>
Tested-by: Eduardo Habkost <ehabkost@redhat.com>
Acked-by: Eduardo Otubo <eduardo.otubo@profitbricks.com>
qemu-seccomp.c

index b0c626984f78ed2bbd8e07cc708152f37f0c3621..f9de0d3390feb3aaf76a9db3b461c2c7869691a1 100644 (file)
@@ -229,6 +229,7 @@ static const struct QemuSeccompSyscall seccomp_whitelist[] = {
     { SCMP_SYS(shmdt), 240 },
     { SCMP_SYS(timerfd_create), 240 },
     { SCMP_SYS(shmctl), 240 },
+    { SCMP_SYS(mlockall), 240 },
     { SCMP_SYS(mlock), 240 },
     { SCMP_SYS(munlock), 240 },
     { SCMP_SYS(semctl), 240 },