From c527ffbfcc5ea6003cc7062d7766346fd00f34bb Mon Sep 17 00:00:00 2001 From: NobodyOnSE Date: Mon, 26 Feb 2018 21:25:55 +0100 Subject: [PATCH] Whitelist statx syscall for libseccomp-2.3.3 onward Older seccomp versions will ignore this. Signed-off-by: NobodyOnSE Upstream-commit: b2a907c8cab64830c9e424eb1ec71e0429d326ff Component: engine --- components/engine/profiles/seccomp/default.json | 1 + components/engine/profiles/seccomp/seccomp_default.go | 1 + 2 files changed, 2 insertions(+) diff --git a/components/engine/profiles/seccomp/default.json b/components/engine/profiles/seccomp/default.json index 38467c7bed..5717c00cde 100755 --- a/components/engine/profiles/seccomp/default.json +++ b/components/engine/profiles/seccomp/default.json @@ -322,6 +322,7 @@ "stat64", "statfs", "statfs64", + "statx", "symlink", "symlinkat", "sync", diff --git a/components/engine/profiles/seccomp/seccomp_default.go b/components/engine/profiles/seccomp/seccomp_default.go index 9deab38e17..be29aa4f70 100644 --- a/components/engine/profiles/seccomp/seccomp_default.go +++ b/components/engine/profiles/seccomp/seccomp_default.go @@ -315,6 +315,7 @@ func DefaultProfile() *types.Seccomp { "stat64", "statfs", "statfs64", + "statx", "symlink", "symlinkat", "sync",