<html><head><meta name="color-scheme" content="light dark"></head><body><pre style="word-wrap: break-word; white-space: pre-wrap;">From e9a31d3e36f51de5e70ce8ce26d344bdc21a7981 Mon Sep 17 00:00:00 2001
Message-Id: &lt;e9a31d3e36f51de5e70ce8ce26d344bdc21a7981.1422041080.git.jen@redhat.com&gt;
From: Paolo Bonzini &lt;pbonzini@redhat.com&gt;
Date: Wed, 21 Jan 2015 14:37:16 -0500
Subject: [CHANGE 1/4] seccomp: add mlockall to whitelist
To: rhvirt-patches@redhat.com,
    jen@redhat.com

RH-Author: Paolo Bonzini &lt;pbonzini@redhat.com&gt;
Message-id: &lt;1421851036-1282-1-git-send-email-pbonzini@redhat.com&gt;
Patchwork-id: 63440
O-Subject: [RHEL7.1 qemu-kvm-rhev PATCH] seccomp: add mlockall to whitelist
Bugzilla: 1182494
RH-Acked-by: Amit Shah &lt;amit.shah@redhat.com&gt;
RH-Acked-by: Laszlo Ersek &lt;lersek@redhat.com&gt;
RH-Acked-by: Bandan Das &lt;bsd@redhat.com&gt;

Upstream status: posted, acked

This is used by "-realtime mlock=on".

Signed-off-by: Paolo Bonzini &lt;pbonzini@redhat.com&gt;
Signed-off-by: Jeff E. Nelson &lt;jen@redhat.com&gt;
---
 qemu-seccomp.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/qemu-seccomp.c b/qemu-seccomp.c
index 0503764..2ccbcb2 100644
--- a/qemu-seccomp.c
+++ b/qemu-seccomp.c
@@ -229,6 +229,7 @@ static const struct QemuSeccompSyscall seccomp_whitelist[] = {
     { SCMP_SYS(shmdt), 240 },
     { SCMP_SYS(timerfd_create), 240 },
     { SCMP_SYS(shmctl), 240 },
+    { SCMP_SYS(mlockall), 240 },
     { SCMP_SYS(mlock), 240 },
     { SCMP_SYS(munlock), 240 },
     { SCMP_SYS(semctl), 240 }
-- 
2.1.0

</pre></body></html>