From 546bf8fe865dc9c1d188b3a8cf426d68dc34a436 Mon Sep 17 00:00:00 2001 From: Patrick McLean Date: Mon, 27 Apr 2020 20:38:42 +0200 Subject: [PATCH] v1.0.1: seccomp - add brk Signed-off-by: Lars Wendler --- src/daemon/priv-seccomp.c | 1 + 1 file changed, 1 insertion(+) diff --git a/src/daemon/priv-seccomp.c b/src/daemon/priv-seccomp.c index 19689fe2..d3058565 100644 --- a/src/daemon/priv-seccomp.c +++ b/src/daemon/priv-seccomp.c @@ -163,6 +163,7 @@ priv_seccomp_init(int remote, int child) (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(sendmmsg), 0)) < 0 || (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(wait4), 0)) < 0 || (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(stat), 0)) < 0 || + (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(brk), 0)) < 0 || /* brk needed for newer libc */ (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(getpid), 0)) < 0 || (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(rt_sigreturn), 0)) < 0 || (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(close), 0)) < 0 || -- 2.39.5