Skip to content

Commit e698470

Browse files
committed
working profile
1 parent 18ada33 commit e698470

File tree

1 file changed

+26
-52
lines changed

1 file changed

+26
-52
lines changed

strace/profiles/seccomp-profile.json

Lines changed: 26 additions & 52 deletions
Original file line numberDiff line numberDiff line change
@@ -3,96 +3,70 @@
33
"architectures": ["SCMP_ARCH_X86_64", "SCMP_ARCH_X86", "SCMP_ARCH_X32"],
44
"syscalls": [
55
{
6-
"action": "SCMP_ACT_ALLOW",
76
"names": [
8-
"accept",
97
"accept4",
108
"arch_prctl",
119
"bind",
12-
"brk",
13-
"chdir",
1410
"clock_gettime",
1511
"clone",
1612
"close",
17-
"dup2",
18-
"dup3",
13+
"connect",
14+
"epoll_create1",
15+
"epoll_ctl",
16+
"epoll_pwait",
17+
"eventfd2",
1918
"execve",
2019
"exit_group",
21-
"fchown",
2220
"fcntl",
2321
"fstat",
2422
"fstatfs",
25-
"fork",
2623
"futex",
24+
"getdents",
2725
"getdents64",
26+
"getpeername",
2827
"getpid",
29-
"getppid",
30-
"getuid",
31-
"getgid",
32-
"geteuid",
33-
"getegid",
34-
"getcwd",
3528
"getrandom",
36-
"gettimeofday",
29+
"getsockname",
30+
"getsockopt",
3731
"gettid",
38-
"ioctl",
3932
"listen",
40-
"lstat",
33+
"madvise",
4134
"mmap",
4235
"mprotect",
4336
"munmap",
44-
"madvise",
4537
"nanosleep",
4638
"openat",
4739
"openat2",
48-
"pselect6",
4940
"prctl",
41+
"pread64",
5042
"prlimit64",
5143
"read",
52-
"readlinkat",
53-
"readlink",
54-
"access",
44+
"readdirent",
5545
"rt_sigaction",
5646
"rt_sigprocmask",
5747
"rt_sigreturn",
5848
"sched_getaffinity",
5949
"sched_yield",
60-
"select",
61-
"epoll_create",
62-
"epoll_create1",
63-
"epoll_ctl",
64-
"epoll_wait",
65-
"epoll_pwait",
66-
"pipe",
67-
"pipe2",
68-
"capget",
69-
"capset",
70-
"setgid",
71-
"setgroups",
7250
"setsockopt",
73-
"set_tid_address",
74-
"setuid",
7551
"sigaltstack",
7652
"socket",
77-
"recvfrom",
78-
"sendto",
79-
"sendmsg",
80-
"recvmsg",
81-
"connect",
82-
"shutdown",
83-
"getsockopt",
84-
"getpeername",
85-
"getsockname",
86-
"stat",
8753
"statx",
88-
"newfstatat",
8954
"tgkill",
90-
"time",
9155
"uname",
92-
"wait4",
9356
"write",
94-
"writev"
95-
]
57+
"set_tid_address",
58+
"poll",
59+
"brk",
60+
"ioctl",
61+
"open",
62+
"recvfrom",
63+
"sendto",
64+
"sendmsg",
65+
"sendmmsg",
66+
"recvmsg",
67+
"recvmmsg"
68+
],
69+
"action": "SCMP_ACT_ALLOW"
9670
}
9771
]
98-
}
72+
}

0 commit comments

Comments
 (0)