فهرست منبع

Merge pull request #34445 from pmoust/f-seccomp-quotacl

seccomp: whitelist quotactl with CAP_SYS_ADMIN
Yong Tang 8 سال پیش
والد
کامیت
bbb401de87
2فایلهای تغییر یافته به همراه2 افزوده شده و 0 حذف شده
  1. 1 0
      profiles/seccomp/default.json
  2. 1 0
      profiles/seccomp/seccomp_default.go

+ 1 - 0
profiles/seccomp/default.json

@@ -557,6 +557,7 @@
 				"mount",
 				"mount",
 				"name_to_handle_at",
 				"name_to_handle_at",
 				"perf_event_open",
 				"perf_event_open",
+				"quotactl",
 				"setdomainname",
 				"setdomainname",
 				"sethostname",
 				"sethostname",
 				"setns",
 				"setns",

+ 1 - 0
profiles/seccomp/seccomp_default.go

@@ -488,6 +488,7 @@ func DefaultProfile() *types.Seccomp {
 				"mount",
 				"mount",
 				"name_to_handle_at",
 				"name_to_handle_at",
 				"perf_event_open",
 				"perf_event_open",
+				"quotactl",
 				"setdomainname",
 				"setdomainname",
 				"sethostname",
 				"sethostname",
 				"setns",
 				"setns",