Chromium Code Reviews| Index: content/common/sandbox_linux/bpf_renderer_policy_linux.cc |
| diff --git a/content/common/sandbox_linux/bpf_renderer_policy_linux.cc b/content/common/sandbox_linux/bpf_renderer_policy_linux.cc |
| index a3e74389425729b4762cb22e7d5acddd717a3281..7c5a62a883931b865e3b151d6f2d833dec1c12dd 100644 |
| --- a/content/common/sandbox_linux/bpf_renderer_policy_linux.cc |
| +++ b/content/common/sandbox_linux/bpf_renderer_policy_linux.cc |
| @@ -5,6 +5,7 @@ |
| #include "content/common/sandbox_linux/bpf_renderer_policy_linux.h" |
| #include <errno.h> |
| +#include <linux/dma-buf.h> |
| #include <sys/ioctl.h> |
| #include "build/build_config.h" |
| @@ -30,6 +31,8 @@ ResultExpr RestrictIoctl() { |
| return Switch(request) |
| .SANDBOX_BPF_DSL_CASES((static_cast<unsigned long>(TCGETS), FIONREAD), |
| Allow()) |
| + .SANDBOX_BPF_DSL_CASES((static_cast<unsigned long>(DMA_BUF_IOCTL_SYNC)), |
| + Allow()) |
|
spang
2016/03/30 00:19:00
I'm fairly certain this is going to cause compile
vignatti (out of this project)
2016/03/30 14:58:37
yeah, I was thinking the same. Did you read what I
|
| .Default(sandbox::CrashSIGSYSIoctl()); |
| } |