diff --git a/src/main.cpp b/src/main.cpp index f29112e..18727ea 100644 --- a/src/main.cpp +++ b/src/main.cpp @@ -97,6 +97,9 @@ static bool enableSecurity() { seccomp_rule_add(scmp, SCMP_ACT_ALLOW, SCMP_SYS(recvfrom), 0); seccomp_rule_add(scmp, SCMP_ACT_ALLOW, SCMP_SYS(fcntl), 0); seccomp_rule_add(scmp, SCMP_ACT_ALLOW, SCMP_SYS(uname), 0); + seccomp_rule_add(scmp, SCMP_ACT_ALLOW, SCMP_SYS(sigprocmask), 0); + seccomp_rule_add(scmp, SCMP_ACT_ALLOW, SCMP_SYS(rt_sigprocmask), 0); + seccomp_rule_add(scmp, SCMP_ACT_ALLOW, SCMP_SYS(sigprocmask), 0); seccomp_rule_add(scmp, SCMP_ACT_ALLOW, SCMP_SYS(clone), 0); // curl wants to spawn threads seccomp_rule_add(scmp, SCMP_ACT_ALLOW, SCMP_SYS(mmap), 0);