seccomp: add rseq() to default list of syscalls to whitelist
authorLennart Poettering <lennart@poettering.net>
Thu, 28 Mar 2019 09:01:09 +0000 (10:01 +0100)
committerLennart Poettering <lennart@poettering.net>
Thu, 28 Mar 2019 11:09:38 +0000 (12:09 +0100)
Apparently glibc is going to call this implicitly soon, hence let's
whitelist this by default.

Fixes: #12127

src/shared/seccomp-util.c

index 905be0f..ba3f433 100644 (file)
@@ -291,6 +291,7 @@ const SyscallFilterSet syscall_filter_sets[_SYSCALL_FILTER_SET_MAX] = {
                 "pause\0"
                 "prlimit64\0"
                 "restart_syscall\0"
+                "rseq\0"
                 "rt_sigreturn\0"
                 "sched_yield\0"
                 "set_robust_list\0"