seccomp: whitelist quotactl with CAP_SYS_ADMIN
The quotactl syscall is being whitelisted in default seccomp profile, gated by CAP_SYS_ADMIN. Signed-off-by: Panagiotis Moustafellos <pmoust@elastic.co>
This commit is contained in:
parent
526fc40145
commit
cf6e1c5dfd
2 changed files with 2 additions and 0 deletions
|
@ -557,6 +557,7 @@
|
|||
"mount",
|
||||
"name_to_handle_at",
|
||||
"perf_event_open",
|
||||
"quotactl",
|
||||
"setdomainname",
|
||||
"sethostname",
|
||||
"setns",
|
||||
|
|
|
@ -488,6 +488,7 @@ func DefaultProfile() *types.Seccomp {
|
|||
"mount",
|
||||
"name_to_handle_at",
|
||||
"perf_event_open",
|
||||
"quotactl",
|
||||
"setdomainname",
|
||||
"sethostname",
|
||||
"setns",
|
||||
|
|
Loading…
Add table
Reference in a new issue