libminijail,minijail0: add seccomp filter support
This change adds support for installing seccomp filters via libminijail
or by using minijail0 with an arch-specific filters file.
Support for LD_PRELOAD marshalling is still missing and will come in a new change.
BUG=chromium-os:19459
TEST=minijail0 -r -S dash-cat.policy -u chronos -- /bin/dash -c '/bin/cat /proc/self/seccomp_filter'
dash-cat.policy can be found in the bug.
Change-Id: Id3f52ae9ce7bf49c257b2cfb9ba66b38b8be8094
Reviewed-on: http://gerrit.chromium.org/gerrit/6789
Reviewed-by: Elly Jones <[email protected]>
Tested-by: Will Drewry <[email protected]>
7 files changed