freebsd-skq/sys/compat/freebsd32/capabilities.conf
Allan Jude f299c47b52 Allow cpuset_{get,set}affinity in capabilities mode
bhyve was recently sandboxed with capsicum, and needs to be able to
control the CPU sets of its vcpu threads

Reviewed by:	emaste, oshogbo, rwatson
MFC after:	2 weeks
Sponsored by:	ScaleEngine Inc.
Differential Revision:	https://reviews.freebsd.org/D10170
2017-05-24 00:58:30 +00:00

289 lines
5.4 KiB
Plaintext

##
## Copyright (c) 2008-2010 Robert N. M. Watson
## Copyright (c) 2016 The FreeBSD Foundation
## All rights reserved.
##
## This software was developed at the University of Cambridge Computer
## Laboratory with support from a grant from Google, Inc.
##
## Portions of this software were developed by Konstantin Belousov
## under sponsorship from the FreeBSD Foundation.
##
## Redistribution and use in source and binary forms, with or without
## modification, are permitted provided that the following conditions
## are met:
## 1. Redistributions of source code must retain the above copyright
## notice, this list of conditions and the following disclaimer.
## 2. Redistributions in binary form must reproduce the above copyright
## notice, this list of conditions and the following disclaimer in the
## documentation and/or other materials provided with the distribution.
##
## THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
## ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
## IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
## ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
## FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
## DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
## OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
## HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
## LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
## OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
## SUCH DAMAGE.
##
## List of system calls enabled in freebsd32 capability mode, one name
## per line. See the original list in the sys/kern/capabilities.conf.
## Position of the compat syscall in this file must be identical to
## the master, to facilitate comparision and diagnostic.
##
## $FreeBSD$
##
__acl_aclcheck_fd
__acl_delete_fd
__acl_get_fd
__acl_set_fd
__mac_get_fd
#__mac_get_pid
__mac_get_proc
__mac_set_fd
__mac_set_proc
freebsd32_sysctl
freebsd32_umtx_op
abort2
accept
accept4
aio_cancel
freebsd32_aio_error
aio_fsync
freebsd32_aio_read
freebsd32_aio_return
freebsd32_aio_suspend
freebsd32_aio_waitcomplete
freebsd32_aio_write
#audit
bindat
cap_enter
cap_fcntls_get
cap_fcntls_limit
cap_getmode
freebsd32_cap_ioctls_get
freebsd32_cap_ioctls_limit
__cap_rights_get
cap_rights_limit
freebsd32_clock_getres
freebsd32_clock_gettime
close
closefrom
connectat
#cpuset
freebsd32_cpuset_getaffinity
#freebsd32_cpuset_getid
freebsd32_cpuset_setaffinity
#freebsd32_cpuset_setid
dup
dup2
extattr_delete_fd
extattr_get_fd
extattr_list_fd
extattr_set_fd
fchflags
fchmod
fchown
freebsd32_fcntl
freebsd32_fexecve
flock
fork
fpathconf
freebsd11_freebsd32_fstat
freebsd11_freebsd32_fstatat
freebsd11_freebsd32_getdirentries
freebsd11_freebsd32_fstatfs
freebsd11_freebsd32_mknodat
freebsd6_freebsd32_ftruncate
freebsd6_freebsd32_lseek
freebsd6_freebsd32_mmap
freebsd6_freebsd32_pread
freebsd6_freebsd32_pwrite
freebsd32_fstat
fstatfs
fsync
ftruncate
freebsd32_futimens
freebsd32_futimes
getaudit
getaudit_addr
getauid
freebsd32_getcontext
getdents
freebsd32_getdirentries
getdomainname
getdtablesize
getegid
geteuid
gethostid
gethostname
freebsd32_getitimer
getgid
getgroups
getlogin
freebsd32_getpagesize
getpeername
getpgid
getpgrp
getpid
getppid
getpriority
getresgid
getresuid
getrlimit
freebsd32_getrusage
getsid
getsockname
getsockopt
freebsd32_gettimeofday
getuid
freebsd32_ioctl
issetugid
freebsd32_kevent
kill
freebsd32_kmq_notify
freebsd32_kmq_setattr
freebsd32_kmq_timedreceive
freebsd32_kmq_timedsend
kqueue
freebsd32_ktimer_create
ktimer_delete
ktimer_getoverrun
freebsd32_ktimer_gettime
freebsd32_ktimer_settime
#ktrace
freebsd32_lio_listio
listen
freebsd32_lseek
madvise
mincore
minherit
mlock
mlockall
freebsd32_mmap
freebsd32_mprotect
msync
munlock
munlockall
munmap
freebsd32_nanosleep
ntp_gettime
freebsd6_freebsd32_aio_read
freebsd6_freebsd32_aio_write
obreak
freebsd6_freebsd32_lio_listio
chflagsat
faccessat
fchmodat
fchownat
freebsd32_fstatat
freebsd32_futimesat
linkat
mkdirat
mkfifoat
mknodat
openat
readlinkat
renameat
symlinkat
unlinkat
freebsd32_utimensat
pdfork
pdgetpid
pdkill
#pdwait4 # not yet implemented
freebsd32_pipe
pipe2
poll
freebsd32_pread
freebsd32_preadv
profil
#ptrace
freebsd32_pwrite
freebsd32_pwritev
read
freebsd32_readv
freebsd6_freebsd32_recv
freebsd32_recvfrom
freebsd32_recvmsg
rtprio
rtprio_thread
sbrk
sched_get_priority_max
sched_get_priority_min
sched_getparam
sched_getscheduler
sched_rr_get_interval
sched_setparam
sched_setscheduler
sched_yield
sctp_generic_recvmsg
sctp_generic_sendmsg
sctp_generic_sendmsg_iov
sctp_peeloff
freebsd32_pselect
freebsd32_select
freebsd6_freebsd32_send
freebsd32_sendfile
freebsd32_sendmsg
sendto
setaudit
setaudit_addr
setauid
freebsd32_setcontext
setegid
seteuid
setgid
freebsd32_setitimer
setpriority
setregid
setresgid
setresuid
setreuid
setrlimit
setsid
setsockopt
setuid
shm_open
shutdown
freebsd32_sigaction
freebsd32_sigaltstack
freebsd32_sigblock
freebsd32_sigpending
sigprocmask
sigqueue
freebsd32_sigreturn
freebsd32_sigsetmask
ofreebsd32_sigstack
sigsuspend
freebsd32_sigtimedwait
freebsd32_sigvec
freebsd32_sigwaitinfo
sigwait
socket
socketpair
sstk
sync
sys_exit
freebsd32_sysarch
thr_create
thr_exit
thr_kill
#thr_kill2
freebsd32_thr_new
thr_self
thr_set_name
freebsd32_thr_suspend
thr_wake
umask
utrace
uuidgen
write
freebsd32_writev
yield