Browse Source

Merge pull request #46762 from akerouanton/seccomp-io_uring

seccomp: block io_uring_* syscalls in default profile
Sebastiaan van Stijn 1 year ago
parent
commit
ec32f0db82
2 changed files with 0 additions and 6 deletions
  1. 0 3
      profiles/seccomp/default.json
  2. 0 3
      profiles/seccomp/default_linux.go

+ 0 - 3
profiles/seccomp/default.json

@@ -183,9 +183,6 @@
 				"ioprio_set",
 				"io_setup",
 				"io_submit",
-				"io_uring_enter",
-				"io_uring_register",
-				"io_uring_setup",
 				"ipc",
 				"kill",
 				"landlock_add_rule",

+ 0 - 3
profiles/seccomp/default_linux.go

@@ -175,9 +175,6 @@ func DefaultProfile() *Seccomp {
 					"ioprio_set",
 					"io_setup",
 					"io_submit",
-					"io_uring_enter",
-					"io_uring_register",
-					"io_uring_setup",
 					"ipc",
 					"kill",
 					"landlock_add_rule",