Bug 1286185 - Add sys_fadvise64 to seccomp whitelist. r=gcp MozReview-Commit-ID: CkX1txdLAMg
--- a/security/sandbox/linux/SandboxFilter.cpp
+++ b/security/sandbox/linux/SandboxFilter.cpp
@@ -664,16 +664,21 @@ public:
       // the child would inherit the seccomp-bpf policy and almost
       // certainly die from an unexpected SIGSYS.  We also can't have
       // fork() crash, currently, because there are too many system
       // libraries/plugins that try to run commands.  But they can
       // usually do something reasonable on error.
     case __NR_clone:
       return ClonePolicy(Error(EPERM));
+#ifdef __NR_fadvise64
+    case __NR_fadvise64:
+      return Allow();
 #endif // DESKTOP
 #ifdef __NR_getrandom
     case __NR_getrandom:
       return Allow();
       // nsSystemInfo uses uname (and we cache an instance, so