From 37a293d33333e38aacac4c7fc16426cccca19291 Mon Sep 17 00:00:00 2001 From: Vincent Bernat Date: Wed, 13 Sep 2017 19:07:43 +0200 Subject: [PATCH] priv: add getpid() to seccomp filter --- src/daemon/priv-seccomp.c | 1 + 1 file changed, 1 insertion(+) diff --git a/src/daemon/priv-seccomp.c b/src/daemon/priv-seccomp.c index 19052367..7d911bc0 100644 --- a/src/daemon/priv-seccomp.c +++ b/src/daemon/priv-seccomp.c @@ -161,6 +161,7 @@ priv_seccomp_init(int remote, int child) (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(sendmmsg), 0)) < 0 || (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(wait4), 0)) < 0 || (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(stat), 0)) < 0 || + (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(getpid), 0)) < 0 || (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(rt_sigreturn), 0)) < 0 || (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(close), 0)) < 0 || (rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(sendto), 0)) < 0 || -- 2.39.2