瀏覽代碼

Merge pull request #19217 from justincormack/arm_syscalls

Add arm specific syscalls to default seccomp profile
Jess Frazelle 9 年之前
父節點
當前提交
a96a0b3781
共有 1 個文件被更改,包括 16 次插入0 次删除
  1. 16 0
      daemon/execdriver/native/seccomp_default.go

+ 16 - 0
daemon/execdriver/native/seccomp_default.go

@@ -1570,5 +1570,21 @@ var defaultSeccompProfile = &configs.Seccomp{
 			Action: configs.Allow,
 			Args:   []*configs.Arg{},
 		},
+		// arm specific syscalls
+		{
+			Name:   "breakpoint",
+			Action: configs.Allow,
+			Args:   []*configs.Arg{},
+		},
+		{
+			Name:   "cacheflush",
+			Action: configs.Allow,
+			Args:   []*configs.Arg{},
+		},
+		{
+			Name:   "set_tls",
+			Action: configs.Allow,
+			Args:   []*configs.Arg{},
+		},
 	},
 }