From 3ab8ebbc6e068728c6b4123cea0c6e5316e221ee Mon Sep 17 00:00:00 2001 From: Patrick McLean Date: Mon, 27 Apr 2020 20:37:56 +0200 Subject: [PATCH] v0.9.5: seccomp - add socket ops Signed-off-by: Lars Wendler --- src/daemon/priv-seccomp.c | 1 + 1 file changed, 1 insertion(+) diff --git a/src/daemon/priv-seccomp.c b/src/daemon/priv-seccomp.c index 5a6e2ae8..19689fe2 100644 --- a/src/daemon/priv-seccomp.c +++ b/src/daemon/priv-seccomp.c @@ -172,6 +172,7 @@ priv_seccomp_init(int remote, int child) (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(recvfrom), 0)) < 0 || (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(readv), 0)) < 0 || (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(mprotect), 0)) < 0 || + (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(sendmmsg), 0)) < 0 || /* The following are for resolving addresses */ (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(mmap), 0)) < 0 || (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(munmap), 0)) < 0 || -- 2.39.5