Bug 1268579 - Add inotify_rm_watch to the seccomp-bpf whitelist. r?jld
MozReview-Commit-ID: DvaHjOa5GOv
--- a/security/sandbox/linux/SandboxFilter.cpp
+++ b/security/sandbox/linux/SandboxFilter.cpp
@@ -611,16 +611,17 @@ public:
#ifdef __NR_arch_prctl
case __NR_arch_prctl:
#endif
return Allow();
case __NR_eventfd2:
case __NR_inotify_init1:
case __NR_inotify_add_watch:
+ case __NR_inotify_rm_watch:
return Allow();
#endif
// nsSystemInfo uses uname (and we cache an instance, so
// the info remains present even if we block the syscall)
case __NR_uname:
#ifdef DESKTOP
case __NR_sysinfo: