From 3ffdc230177aeff36d3ce5cc41fa63a85e30ebc1 Mon Sep 17 00:00:00 2001 From: Vachounet Date: Mon, 20 Nov 2017 13:21:50 +0100 Subject: [PATCH] sanders: update seccomp_policy * add mediaextractor policy --- seccomp_policy/mediacodec.policy | 7 +++++++ seccomp_policy/mediaextractor.policy | 4 ++++ 2 files changed, 11 insertions(+) create mode 100644 seccomp_policy/mediaextractor.policy diff --git a/seccomp_policy/mediacodec.policy b/seccomp_policy/mediacodec.policy index f94036d..81d042b 100644 --- a/seccomp_policy/mediacodec.policy +++ b/seccomp_policy/mediacodec.policy @@ -1,5 +1,12 @@ # device specific syscalls +# extension of services/mediacodec/minijail/seccomp_policy/mediacodec-seccomp-arm.policy pselect6: 1 eventfd2: 1 sendto: 1 recvfrom: 1 +_llseek: 1 +sysinfo: 1 +getcwd: 1 +getdents64: 1 +inotify_init1: 1 +inotify_add_watch: 1 diff --git a/seccomp_policy/mediaextractor.policy b/seccomp_policy/mediaextractor.policy new file mode 100644 index 0000000..77c1e2a --- /dev/null +++ b/seccomp_policy/mediaextractor.policy @@ -0,0 +1,4 @@ +# device specific syscalls. +# extension of services/mediaextractor/minijail/seccomp_policy/mediaextractor-seccomp-arm.policy +readlinkat: 1 +pread64: 1