allow new syscalls

This commit is contained in:
mrbesen 2021-11-03 15:53:52 +01:00
parent 1522b760cb
commit 83a0a17d7d
Signed by: MrBesen
GPG Key ID: 596B2350DCD67504
1 changed files with 3 additions and 0 deletions

View File

@ -88,6 +88,9 @@ static bool enableSecurity() {
seccomp_rule_add(scmp, SCMP_ACT_ALLOW, SCMP_SYS(get_robust_list), 0);
seccomp_rule_add(scmp, SCMP_ACT_ALLOW, SCMP_SYS(sendmmsg), 0);
seccomp_rule_add(scmp, SCMP_ACT_ALLOW, SCMP_SYS(sendmsg), 0);
seccomp_rule_add(scmp, SCMP_ACT_ALLOW, SCMP_SYS(sendto), 0);
seccomp_rule_add(scmp, SCMP_ACT_ALLOW, SCMP_SYS(recvfrom), 0);
seccomp_rule_add(scmp, SCMP_ACT_ALLOW, SCMP_SYS(fcntl), 0);
seccomp_rule_add(scmp, SCMP_ACT_ALLOW, SCMP_SYS(uname), 0);
seccomp_rule_add(scmp, SCMP_ACT_ALLOW, SCMP_SYS(clone), 0); // curl wants to spawn threads