From: Benedikt Neuffer Date: Sat, 27 Nov 2021 16:07:50 +0000 (+0100) Subject: linux: add missing SECCOMP rules X-Git-Tag: 1.0.14~34 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=e57bf5ea66a70ff87bba5c39c0e10c071b4af824;p=thirdparty%2Flldpd.git linux: add missing SECCOMP rules Signed-off-by: Benedikt Neuffer --- diff --git a/NEWS b/NEWS index dbb1b804..6c1a9717 100644 --- a/NEWS +++ b/NEWS @@ -1,3 +1,7 @@ +lldpd (1.0.14) + * Fix: + + Update seccomp rules for newer kernel/libc (#488) + lldpd (1.0.13) * Fix: + Add support for 2.5G, 5G, 25G and 50G based Ethernet (#475) diff --git a/src/daemon/priv-seccomp.c b/src/daemon/priv-seccomp.c index 6d2736af..5608c5f0 100644 --- a/src/daemon/priv-seccomp.c +++ b/src/daemon/priv-seccomp.c @@ -176,6 +176,8 @@ priv_seccomp_init(int remote, int child) (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(sendmmsg), 0)) < 0 || (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(clock_gettime), 0)) < 0 || (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(gettimeofday), 0)) < 0 || + (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(newfstatat), 0)) < 0 || + (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(pread64), 0)) < 0 || /* The following are for resolving addresses */ (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(mmap), 0)) < 0 || (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(munmap), 0)) < 0 ||