From 6f1304d55901852116b1a1c46debfa26e4bc3e60 Mon Sep 17 00:00:00 2001 From: mrbesen Date: Mon, 4 Oct 2021 17:51:54 +0200 Subject: [PATCH] added set/get robust list to seccomp --- src/main.cpp | 2 ++ 1 file changed, 2 insertions(+) diff --git a/src/main.cpp b/src/main.cpp index 34aac59..039aa3a 100644 --- a/src/main.cpp +++ b/src/main.cpp @@ -80,6 +80,8 @@ static bool enableSecurity() { seccomp_rule_add(scmp, SCMP_ACT_ALLOW, SCMP_SYS(restart_syscall), 0); seccomp_rule_add(scmp, SCMP_ACT_ALLOW, SCMP_SYS(futex), 0); seccomp_rule_add(scmp, SCMP_ACT_ALLOW, SCMP_SYS(socketpair), 0); // what? + seccomp_rule_add(scmp, SCMP_ACT_ALLOW, SCMP_SYS(set_robust_list), 1, SCMP_A0(SCMP_CMP_EQ, 0)); + seccomp_rule_add(scmp, SCMP_ACT_ALLOW, SCMP_SYS(get_robust_list), 1, SCMP_A0(SCMP_CMP_EQ, 0)); seccomp_rule_add(scmp, SCMP_ACT_ALLOW, SCMP_SYS(clone), 0); // curl wants to spawn threads seccomp_rule_add(scmp, SCMP_ACT_ALLOW, SCMP_SYS(mmap), 0);