From dd80f04cfce4dc4f3aa9233ebb38227aa57713d9 Mon Sep 17 00:00:00 2001 From: Astrako Date: Tue, 10 Mar 2020 16:43:34 +0100 Subject: [PATCH] universal7870: update seccomp --- seccomp/mediacodec-seccomp.policy | 20 ++------------------ seccomp/mediaextractor-seccomp.policy | 7 +++---- seccomp/mediaswcodec.policy | 2 ++ 3 files changed, 7 insertions(+), 22 deletions(-) create mode 100644 seccomp/mediaswcodec.policy diff --git a/seccomp/mediacodec-seccomp.policy b/seccomp/mediacodec-seccomp.policy index 3bf11a3..16e2644 100644 --- a/seccomp/mediacodec-seccomp.policy +++ b/seccomp/mediacodec-seccomp.policy @@ -1,19 +1,3 @@ -# device specific syscalls -# extension of services/mediacodec/minijail/seccomp_policy/mediacodec-seccomp-arm.policy -pselect6: 1 -eventfd2: 1 -sendto: 1 -recvfrom: 1 -_llseek: 1 -sysinfo: 1 -getcwd: 1 -getdents64: 1 -ARM_cacheflush: 1 -inotify_init1: 1 -inotify_add_watch: 1 -inotify_rm_watch: 1 +# for H/W Codec uname: 1 -ueventd: 1 -timer_create: 1 -timer_settime: 1 -rt_sigtimedwait: 1 +getdents64: 1 \ No newline at end of file diff --git a/seccomp/mediaextractor-seccomp.policy b/seccomp/mediaextractor-seccomp.policy index 0fcf604..63716c3 100644 --- a/seccomp/mediaextractor-seccomp.policy +++ b/seccomp/mediaextractor-seccomp.policy @@ -1,5 +1,4 @@ -# device specific syscalls. -# extension of services/mediaextractor/minijail/seccomp_policy/mediaextractor-seccomp-arm.policy -readlinkat: 1 +nanosleep: 1 +_llseek: 1 pread64: 1 -mremap: 1 +readlinkat: 1 \ No newline at end of file diff --git a/seccomp/mediaswcodec.policy b/seccomp/mediaswcodec.policy new file mode 100644 index 0000000..2a0edca --- /dev/null +++ b/seccomp/mediaswcodec.policy @@ -0,0 +1,2 @@ +madvise :1 +