New comment by sgn on void-packages repository https://github.com/void-linux/void-packages/pull/24578#issuecomment-684177274 Comment: We'll need something like this https://gitlab.alpinelinux.org/alpine/aports/-/commit/6158b4c59fee5d9dee4cbe8e311cb48717dff583 for musl 1.2.1. We haven't shipped musl 1.2.1 yet, just FYI --- The main change is: ```diff +diff --git a/services/service_manager/sandbox/linux/bpf_renderer_policy_linux.cc ./services/service_manager/sandbox/linux/bpf_renderer_policy_linux.cc +index a85c0ea..715aa1e 100644 +--- a/services/service_manager/sandbox/linux/bpf_renderer_policy_linux.cc +++ ./services/service_manager/sandbox/linux/bpf_renderer_policy_linux.cc -@@ -88,10 +88,10 @@ +@@ -93,11 +93,11 @@ ResultExpr RendererProcessPolicy::EvaluateSyscall(int sysno) const { case __NR_sysinfo: case __NR_times: case __NR_uname: @@ -139,20 +167,9 @@ - case __NR_sched_getaffinity: case __NR_sched_getparam: case __NR_sched_getscheduler: + case __NR_sched_setscheduler: + return Allow(); + case __NR_sched_getaffinity: - case __NR_sched_setscheduler: return sandbox::RestrictSchedTarget(GetPolicyPid(), sysno); case __NR_prlimit64: ```