瀏覽代碼

Merge pull request #41665 from mikroskeem/41664-pidfd-syscalls-support

seccomp: add pidfd syscalls
Justin Cormack 4 年之前
父節點
當前提交
b6bfff2a62
共有 2 個文件被更改,包括 6 次插入0 次删除
  1. 3 0
      profiles/seccomp/default.json
  2. 3 0
      profiles/seccomp/default_linux.go

+ 3 - 0
profiles/seccomp/default.json

@@ -232,6 +232,8 @@
 				"openat",
 				"openat",
 				"openat2",
 				"openat2",
 				"pause",
 				"pause",
+				"pidfd_open",
+				"pidfd_send_signal",
 				"pipe",
 				"pipe",
 				"pipe2",
 				"pipe2",
 				"poll",
 				"poll",
@@ -721,6 +723,7 @@
 		{
 		{
 			"names": [
 			"names": [
 				"kcmp",
 				"kcmp",
+				"pidfd_getfd",
 				"process_vm_readv",
 				"process_vm_readv",
 				"process_vm_writev",
 				"process_vm_writev",
 				"ptrace"
 				"ptrace"

+ 3 - 0
profiles/seccomp/default_linux.go

@@ -225,6 +225,8 @@ func DefaultProfile() *Seccomp {
 				"openat",
 				"openat",
 				"openat2",
 				"openat2",
 				"pause",
 				"pause",
+				"pidfd_open",
+				"pidfd_send_signal",
 				"pipe",
 				"pipe",
 				"pipe2",
 				"pipe2",
 				"poll",
 				"poll",
@@ -622,6 +624,7 @@ func DefaultProfile() *Seccomp {
 		{
 		{
 			Names: []string{
 			Names: []string{
 				"kcmp",
 				"kcmp",
+				"pidfd_getfd",
 				"process_vm_readv",
 				"process_vm_readv",
 				"process_vm_writev",
 				"process_vm_writev",
 				"ptrace",
 				"ptrace",