* Florian Weimer (fwei...@redhat.com) wrote: > * David Alan Gilbert: > > > +static const int syscall_whitelist[] = { > > + /* TODO ireg sem*() syscalls */ > > + SCMP_SYS(brk), > > + SCMP_SYS(capget), /* For CAP_FSETID */ > > + SCMP_SYS(capset), > > + SCMP_SYS(clock_gettime), > > > + SCMP_SYS(gettimeofday), > > Is this to suppose to work on 32-bit architectures? Then you need to > add the time64 system call variants as well.
I've build tested on 32 but not tried running it; I'd added time(2) after hitting it on a static build but didn't know of time64 (not that it has a manpage!). I'll do a follow up to fix it. Dave > Thanks, > Florian -- Dr. David Alan Gilbert / dgilb...@redhat.com / Manchester, UK