diff --git a/profiles/seccomp/default.json b/profiles/seccomp/default.json index ee5e04f781..6aa28eedd0 100644 --- a/profiles/seccomp/default.json +++ b/profiles/seccomp/default.json @@ -182,6 +182,9 @@ "io_uring_setup", "ipc", "kill", + "landlock_add_rule", + "landlock_create_ruleset", + "landlock_restrict_self", "lchown", "lchown32", "lgetxattr", diff --git a/profiles/seccomp/default_linux.go b/profiles/seccomp/default_linux.go index f75ab7f5d1..33b9796322 100644 --- a/profiles/seccomp/default_linux.go +++ b/profiles/seccomp/default_linux.go @@ -177,6 +177,9 @@ func DefaultProfile() *Seccomp { "io_uring_setup", "ipc", "kill", + "landlock_add_rule", + "landlock_create_ruleset", + "landlock_restrict_self", "lchown", "lchown32", "lgetxattr",