Prechádzať zdrojové kódy

Add arm specific syscalls to default seccomp profile

Signed-off-by: Justin Cormack <justin.cormack@unikernel.com>
Justin Cormack 9 rokov pred
rodič
commit
37d35f3c28
1 zmenil súbory, kde vykonal 16 pridanie a 0 odobranie
  1. 16 0
      daemon/execdriver/native/seccomp_default.go

+ 16 - 0
daemon/execdriver/native/seccomp_default.go

@@ -1570,5 +1570,21 @@ var defaultSeccompProfile = &configs.Seccomp{
 			Action: configs.Allow,
 			Args:   []*configs.Arg{},
 		},
+		// arm specific syscalls
+		{
+			Name:   "breakpoint",
+			Action: configs.Allow,
+			Args:   []*configs.Arg{},
+		},
+		{
+			Name:   "cacheflush",
+			Action: configs.Allow,
+			Args:   []*configs.Arg{},
+		},
+		{
+			Name:   "set_tls",
+			Action: configs.Allow,
+			Args:   []*configs.Arg{},
+		},
 	},
 }