File openssh-7.6p1-seccomp_ipc_flock.patch of Package openssh.10662

# HG changeset patch
# Parent  089f89e036e8d906db26a1e538c879ebc9c0f830
Patch from IBM enabling the use of OpenCryptoki, submitted upstreams:

From: Eduardo Barretto <>
Subject: [PATCH 1/3] Allow flock and ipc syscall for s390 architecture
Date: Tue,  9 May 2017 14:27:13 -0300

In order to use the OpenSSL-ibmpkcs11 engine it is needed to allow flock
and ipc calls, because this engine calls OpenCryptoki (a PKCS#11
implementation) which calls the libraries that will communicate with the
crypto cards. OpenCryptoki makes use of flock and ipc and, as of now,
this is only need on s390 architecture.

Signed-off-by: Eduardo Barretto <>

Index: openssh-7.6p1/sandbox-seccomp-filter.c
--- openssh-7.6p1.orig/sandbox-seccomp-filter.c	2019-03-12 14:38:29.332896973 +0100
+++ openssh-7.6p1/sandbox-seccomp-filter.c	2019-03-12 14:38:29.580898369 +0100
@@ -172,6 +172,9 @@ static const struct sock_filter preauth_
 #ifdef __NR_geteuid32
+#if defined(__NR_flock) && defined(__s390__)
+	SC_ALLOW(__NR_flock),
 #ifdef __NR_getpgid
@@ -190,6 +193,9 @@ static const struct sock_filter preauth_
 #ifdef __NR_getuid32
+#if defined(__NR_ipc) && defined(__s390__)
+	SC_ALLOW(__NR_ipc),
 #ifdef __NR_madvise
openSUSE Build Service is sponsored by