Przeglądaj źródła

Add i386 specific modify_ldt syscall to default seccomp filter

This syscall is used by Go on i386 binaries, although not by libc.

Signed-off-by: Justin Cormack <justin.cormack@unikernel.com>
Justin Cormack 9 lat temu
rodzic
commit
13a9d4e899
1 zmienionych plików z 6 dodań i 0 usunięć
  1. 6 0
      daemon/execdriver/native/seccomp_default.go

+ 6 - 0
daemon/execdriver/native/seccomp_default.go

@@ -1564,5 +1564,11 @@ var defaultSeccompProfile = &configs.Seccomp{
 			Action: configs.Allow,
 			Action: configs.Allow,
 			Args:   []*configs.Arg{},
 			Args:   []*configs.Arg{},
 		},
 		},
+		// i386 specific syscalls
+		{
+			Name:   "modify_ldt",
+			Action: configs.Allow,
+			Args:   []*configs.Arg{},
+		},
 	},
 	},
 }
 }