msm8974-common: Add seccomp policy

Change-Id: I1d5017228a4a9318f8a77ef4036532d64718ecbb
This commit is contained in:
Ethan Chen 2017-09-14 01:01:28 -07:00 committed by Kevin F. Haggerty
parent 9e14a9cbdf
commit 84b97c9d61
3 changed files with 16 additions and 0 deletions

View File

@ -142,6 +142,11 @@ PRODUCT_PACKAGES += \
PRODUCT_PACKAGES += \ PRODUCT_PACKAGES += \
android.hardware.renderscript@1.0-impl android.hardware.renderscript@1.0-impl
# Seccomp
PRODUCT_COPY_FILES += \
$(LOCAL_PATH)/seccomp/mediacodec.policy:system/vendor/etc/seccomp_policy/mediacodec.policy \
$(LOCAL_PATH)/seccomp/mediaextractor.policy:system/vendor/etc/seccomp_policy/mediaextractor.policy
# Sensors # Sensors
PRODUCT_PACKAGES += \ PRODUCT_PACKAGES += \
android.hardware.sensors@1.0-impl android.hardware.sensors@1.0-impl

View File

@ -0,0 +1,7 @@
# device specific syscalls
# extension of services/mediacodec/minijail/seccomp_policy/mediacodec-seccomp-arm.policy
pselect6: 1
eventfd2: 1
sendto: 1
recvfrom: 1
_llseek: 1

View File

@ -0,0 +1,4 @@
# device specific syscalls.
# extension of services/mediaextractor/minijail/seccomp_policy/mediaextractor-seccomp-arm.policy
readlinkat: 1
pread64: 1