Sfoglia il codice sorgente

Merge pull request #41665 from mikroskeem/41664-pidfd-syscalls-support

seccomp: add pidfd syscalls
Justin Cormack 4 anni fa
parent
commit
b6bfff2a62
2 ha cambiato i file con 6 aggiunte e 0 eliminazioni
  1. 3 0
      profiles/seccomp/default.json
  2. 3 0
      profiles/seccomp/default_linux.go

+ 3 - 0
profiles/seccomp/default.json

@@ -232,6 +232,8 @@
 				"openat",
 				"openat2",
 				"pause",
+				"pidfd_open",
+				"pidfd_send_signal",
 				"pipe",
 				"pipe2",
 				"poll",
@@ -721,6 +723,7 @@
 		{
 			"names": [
 				"kcmp",
+				"pidfd_getfd",
 				"process_vm_readv",
 				"process_vm_writev",
 				"ptrace"

+ 3 - 0
profiles/seccomp/default_linux.go

@@ -225,6 +225,8 @@ func DefaultProfile() *Seccomp {
 				"openat",
 				"openat2",
 				"pause",
+				"pidfd_open",
+				"pidfd_send_signal",
 				"pipe",
 				"pipe2",
 				"poll",
@@ -622,6 +624,7 @@ func DefaultProfile() *Seccomp {
 		{
 			Names: []string{
 				"kcmp",
+				"pidfd_getfd",
 				"process_vm_readv",
 				"process_vm_writev",
 				"ptrace",