Blame SOURCES/seccomp.json

9b8438
{
9b8438
	"defaultAction": "SCMP_ACT_ERRNO",
9b8438
	"archMap": [
9b8438
		{
9b8438
			"architecture": "SCMP_ARCH_X86_64",
9b8438
			"subArchitectures": [
9b8438
				"SCMP_ARCH_X86",
9b8438
				"SCMP_ARCH_X32"
9b8438
			]
9b8438
		},
9b8438
		{
9b8438
			"architecture": "SCMP_ARCH_AARCH64",
9b8438
			"subArchitectures": [
9b8438
				"SCMP_ARCH_ARM"
9b8438
			]
9b8438
		},
9b8438
		{
9b8438
			"architecture": "SCMP_ARCH_MIPS64",
9b8438
			"subArchitectures": [
9b8438
				"SCMP_ARCH_MIPS",
9b8438
				"SCMP_ARCH_MIPS64N32"
9b8438
			]
9b8438
		},
9b8438
		{
9b8438
			"architecture": "SCMP_ARCH_MIPS64N32",
9b8438
			"subArchitectures": [
9b8438
				"SCMP_ARCH_MIPS",
9b8438
				"SCMP_ARCH_MIPS64"
9b8438
			]
9b8438
		},
9b8438
		{
9b8438
			"architecture": "SCMP_ARCH_MIPSEL64",
9b8438
			"subArchitectures": [
9b8438
				"SCMP_ARCH_MIPSEL",
9b8438
				"SCMP_ARCH_MIPSEL64N32"
9b8438
			]
9b8438
		},
9b8438
		{
9b8438
			"architecture": "SCMP_ARCH_MIPSEL64N32",
9b8438
			"subArchitectures": [
9b8438
				"SCMP_ARCH_MIPSEL",
9b8438
				"SCMP_ARCH_MIPSEL64"
9b8438
			]
9b8438
		},
9b8438
		{
9b8438
			"architecture": "SCMP_ARCH_S390X",
9b8438
			"subArchitectures": [
9b8438
				"SCMP_ARCH_S390"
9b8438
			]
9b8438
		}
9b8438
	],
9b8438
	"syscalls": [
9b8438
		{
9b8438
			"names": [
9b8438
				"accept",
9b8438
				"accept4",
9b8438
				"access",
9b8438
				"alarm",
9b8438
				"alarm",
9b8438
				"bind",
9b8438
				"brk",
9b8438
				"capget",
9b8438
				"capset",
9b8438
				"chdir",
9b8438
				"chmod",
9b8438
				"chown",
9b8438
				"chown32",
9b8438
				"clock_getres",
9b8438
				"clock_gettime",
9b8438
				"clock_nanosleep",
9b8438
				"close",
9b8438
				"connect",
9b8438
				"copy_file_range",
9b8438
				"creat",
9b8438
				"dup",
9b8438
				"dup2",
9b8438
				"dup3",
9b8438
				"epoll_create",
9b8438
				"epoll_create1",
9b8438
				"epoll_ctl",
9b8438
				"epoll_ctl_old",
9b8438
				"epoll_pwait",
9b8438
				"epoll_wait",
9b8438
				"epoll_wait_old",
9b8438
				"eventfd",
9b8438
				"eventfd2",
9b8438
				"execve",
9b8438
				"execveat",
9b8438
				"exit",
9b8438
				"exit_group",
9b8438
				"faccessat",
9b8438
				"fadvise64",
9b8438
				"fadvise64_64",
9b8438
				"fallocate",
9b8438
				"fanotify_mark",
9b8438
				"fchdir",
9b8438
				"fchmod",
9b8438
				"fchmodat",
9b8438
				"fchown",
9b8438
				"fchown32",
9b8438
				"fchownat",
9b8438
				"fcntl",
9b8438
				"fcntl64",
9b8438
				"fdatasync",
9b8438
				"fgetxattr",
9b8438
				"flistxattr",
9b8438
				"flock",
9b8438
				"fork",
9b8438
				"fremovexattr",
9b8438
				"fsetxattr",
9b8438
				"fstat",
9b8438
				"fstat64",
9b8438
				"fstatat64",
9b8438
				"fstatfs",
9b8438
				"fstatfs64",
9b8438
				"fsync",
9b8438
				"ftruncate",
9b8438
				"ftruncate64",
9b8438
				"futex",
9b8438
				"futimesat",
9b8438
				"getcpu",
9b8438
				"getcwd",
9b8438
				"getdents",
9b8438
				"getdents64",
9b8438
				"getegid",
9b8438
				"getegid32",
9b8438
				"geteuid",
9b8438
				"geteuid32",
9b8438
				"getgid",
9b8438
				"getgid32",
9b8438
				"getgroups",
9b8438
				"getgroups32",
9b8438
				"getitimer",
9b8438
				"getpeername",
9b8438
				"getpgid",
9b8438
				"getpgrp",
9b8438
				"getpid",
9b8438
				"getppid",
9b8438
				"getpriority",
9b8438
				"getrandom",
9b8438
				"getresgid",
9b8438
				"getresgid32",
9b8438
				"getresuid",
9b8438
				"getresuid32",
9b8438
				"getrlimit",
9b8438
				"get_robust_list",
9b8438
				"getrusage",
9b8438
				"getsid",
9b8438
				"getsockname",
9b8438
				"getsockopt",
9b8438
				"get_thread_area",
9b8438
				"gettid",
9b8438
				"gettimeofday",
9b8438
				"getuid",
9b8438
				"getuid32",
9b8438
				"getxattr",
9b8438
				"inotify_add_watch",
9b8438
				"inotify_init",
9b8438
				"inotify_init1",
9b8438
				"inotify_rm_watch",
9b8438
				"io_cancel",
9b8438
				"ioctl",
9b8438
				"io_destroy",
9b8438
				"io_getevents",
9b8438
				"ioprio_get",
9b8438
				"ioprio_set",
9b8438
				"io_setup",
9b8438
				"io_submit",
9b8438
				"ipc",
9b8438
				"kill",
9b8438
				"lchown",
9b8438
				"lchown32",
9b8438
				"lgetxattr",
9b8438
				"link",
9b8438
				"linkat",
9b8438
				"listen",
9b8438
				"listxattr",
9b8438
				"llistxattr",
9b8438
				"_llseek",
9b8438
				"lremovexattr",
9b8438
				"lseek",
9b8438
				"lsetxattr",
9b8438
				"lstat",
9b8438
				"lstat64",
9b8438
				"madvise",
9b8438
				"memfd_create",
9b8438
				"mincore",
9b8438
				"mkdir",
9b8438
				"mkdirat",
9b8438
				"mknod",
9b8438
				"mknodat",
9b8438
				"mlock",
9b8438
				"mlock2",
9b8438
				"mlockall",
9b8438
				"mmap",
9b8438
				"mmap2",
9b8438
				"mprotect",
9b8438
				"mq_getsetattr",
9b8438
				"mq_notify",
9b8438
				"mq_open",
9b8438
				"mq_timedreceive",
9b8438
				"mq_timedsend",
9b8438
				"mq_unlink",
9b8438
				"mremap",
9b8438
				"msgctl",
9b8438
				"msgget",
9b8438
				"msgrcv",
9b8438
				"msgsnd",
9b8438
				"msync",
9b8438
				"munlock",
9b8438
				"munlockall",
9b8438
				"munmap",
9b8438
				"nanosleep",
9b8438
				"newfstatat",
9b8438
				"_newselect",
9b8438
				"open",
9b8438
				"openat",
9b8438
				"pause",
9b8438
				"pipe",
9b8438
				"pipe2",
9b8438
				"poll",
9b8438
				"ppoll",
9b8438
				"prctl",
9b8438
				"pread64",
9b8438
				"preadv",
9b8438
				"prlimit64",
9b8438
				"pselect6",
9b8438
				"pwrite64",
9b8438
				"pwritev",
9b8438
				"read",
9b8438
				"readahead",
9b8438
				"readlink",
9b8438
				"readlinkat",
9b8438
				"readv",
9b8438
				"recv",
9b8438
				"recvfrom",
9b8438
				"recvmmsg",
9b8438
				"recvmsg",
9b8438
				"remap_file_pages",
9b8438
				"removexattr",
9b8438
				"rename",
9b8438
				"renameat",
9b8438
				"renameat2",
9b8438
				"restart_syscall",
9b8438
				"rmdir",
9b8438
				"rt_sigaction",
9b8438
				"rt_sigpending",
9b8438
				"rt_sigprocmask",
9b8438
				"rt_sigqueueinfo",
9b8438
				"rt_sigreturn",
9b8438
				"rt_sigsuspend",
9b8438
				"rt_sigtimedwait",
9b8438
				"rt_tgsigqueueinfo",
9b8438
				"sched_getaffinity",
9b8438
				"sched_getattr",
9b8438
				"sched_getparam",
9b8438
				"sched_get_priority_max",
9b8438
				"sched_get_priority_min",
9b8438
				"sched_getscheduler",
9b8438
				"sched_rr_get_interval",
9b8438
				"sched_setaffinity",
9b8438
				"sched_setattr",
9b8438
				"sched_setparam",
9b8438
				"sched_setscheduler",
9b8438
				"sched_yield",
9b8438
				"seccomp",
9b8438
				"select",
9b8438
				"semctl",
9b8438
				"semget",
9b8438
				"semop",
9b8438
				"semtimedop",
9b8438
				"send",
9b8438
				"sendfile",
9b8438
				"sendfile64",
9b8438
				"sendmmsg",
9b8438
				"sendmsg",
9b8438
				"sendto",
9b8438
				"setfsgid",
9b8438
				"setfsgid32",
9b8438
				"setfsuid",
9b8438
				"setfsuid32",
9b8438
				"setgid",
9b8438
				"setgid32",
9b8438
				"setgroups",
9b8438
				"setgroups32",
9b8438
				"setitimer",
9b8438
				"setpgid",
9b8438
				"setpriority",
9b8438
				"setregid",
9b8438
				"setregid32",
9b8438
				"setresgid",
9b8438
				"setresgid32",
9b8438
				"setresuid",
9b8438
				"setresuid32",
9b8438
				"setreuid",
9b8438
				"setreuid32",
9b8438
				"setrlimit",
9b8438
				"set_robust_list",
9b8438
				"setsid",
9b8438
				"setsockopt",
9b8438
				"set_thread_area",
9b8438
				"set_tid_address",
9b8438
				"setuid",
9b8438
				"setuid32",
9b8438
				"setxattr",
9b8438
				"shmat",
9b8438
				"shmctl",
9b8438
				"shmdt",
9b8438
				"shmget",
9b8438
				"shutdown",
9b8438
				"sigaltstack",
9b8438
				"signalfd",
9b8438
				"signalfd4",
9b8438
				"sigreturn",
9b8438
				"socket",
9b8438
				"socketcall",
9b8438
				"socketpair",
9b8438
				"splice",
9b8438
				"stat",
9b8438
				"stat64",
9b8438
				"statfs",
9b8438
				"statfs64",
9b8438
				"symlink",
9b8438
				"symlinkat",
9b8438
				"sync",
9b8438
				"sync_file_range",
9b8438
				"syncfs",
9b8438
				"sysinfo",
9b8438
				"syslog",
9b8438
				"tee",
9b8438
				"tgkill",
9b8438
				"time",
9b8438
				"timer_create",
9b8438
				"timer_delete",
9b8438
				"timerfd_create",
9b8438
				"timerfd_gettime",
9b8438
				"timerfd_settime",
9b8438
				"timer_getoverrun",
9b8438
				"timer_gettime",
9b8438
				"timer_settime",
9b8438
				"times",
9b8438
				"tkill",
9b8438
				"truncate",
9b8438
				"truncate64",
9b8438
				"ugetrlimit",
9b8438
				"umask",
9b8438
				"uname",
9b8438
				"unlink",
9b8438
				"unlinkat",
9b8438
				"utime",
9b8438
				"utimensat",
9b8438
				"utimes",
9b8438
				"vfork",
9b8438
				"vmsplice",
9b8438
				"wait4",
9b8438
				"waitid",
9b8438
				"waitpid",
9b8438
				"write",
9b8438
				"writev",
9b8438
				"mount",
9b8438
				"umount2",
9b8438
				"reboot",
9b8438
				"name_to_handle_at",
9b8438
				"unshare"
9b8438
			],
9b8438
			"action": "SCMP_ACT_ALLOW",
9b8438
			"args": [],
9b8438
			"comment": "",
9b8438
			"includes": {},
9b8438
			"excludes": {}
9b8438
		},
9b8438
		{
9b8438
			"names": [
9b8438
				"personality"
9b8438
			],
9b8438
			"action": "SCMP_ACT_ALLOW",
9b8438
			"args": [
9b8438
				{
9b8438
					"index": 0,
9b8438
					"value": 0,
9b8438
					"valueTwo": 0,
9b8438
					"op": "SCMP_CMP_EQ"
9b8438
				}
9b8438
			],
9b8438
			"comment": "",
9b8438
			"includes": {},
9b8438
			"excludes": {}
9b8438
		},
9b8438
		{
9b8438
			"names": [
9b8438
				"personality"
9b8438
			],
9b8438
			"action": "SCMP_ACT_ALLOW",
9b8438
			"args": [
9b8438
				{
9b8438
					"index": 0,
9b8438
					"value": 8,
9b8438
					"valueTwo": 0,
9b8438
					"op": "SCMP_CMP_EQ"
9b8438
				}
9b8438
			],
9b8438
			"comment": "",
9b8438
			"includes": {},
9b8438
			"excludes": {}
9b8438
		},
9b8438
		{
9b8438
			"names": [
9b8438
				"personality"
9b8438
			],
9b8438
			"action": "SCMP_ACT_ALLOW",
9b8438
			"args": [
9b8438
				{
9b8438
					"index": 0,
9b8438
					"value": 4294967295,
9b8438
					"valueTwo": 0,
9b8438
					"op": "SCMP_CMP_EQ"
9b8438
				}
9b8438
			],
9b8438
			"comment": "",
9b8438
			"includes": {},
9b8438
			"excludes": {}
9b8438
		},
9b8438
		{
9b8438
			"names": [
9b8438
				"breakpoint",
9b8438
				"cacheflush",
9b8438
				"set_tls"
9b8438
			],
9b8438
			"action": "SCMP_ACT_ALLOW",
9b8438
			"args": [],
9b8438
			"comment": "",
9b8438
			"includes": {
9b8438
				"arches": [
9b8438
					"arm",
9b8438
					"arm64"
9b8438
				]
9b8438
			},
9b8438
			"excludes": {}
9b8438
		},
9b8438
		{
9b8438
			"names": [
9b8438
				"arch_prctl"
9b8438
			],
9b8438
			"action": "SCMP_ACT_ALLOW",
9b8438
			"args": [],
9b8438
			"comment": "",
9b8438
			"includes": {
9b8438
				"arches": [
9b8438
					"amd64",
9b8438
					"x32"
9b8438
				]
9b8438
			},
9b8438
			"excludes": {}
9b8438
		},
9b8438
		{
9b8438
			"names": [
9b8438
				"modify_ldt"
9b8438
			],
9b8438
			"action": "SCMP_ACT_ALLOW",
9b8438
			"args": [],
9b8438
			"comment": "",
9b8438
			"includes": {
9b8438
				"arches": [
9b8438
					"amd64",
9b8438
					"x32",
9b8438
					"x86"
9b8438
				]
9b8438
			},
9b8438
			"excludes": {}
9b8438
		},
9b8438
		{
9b8438
			"names": [
9b8438
				"s390_pci_mmio_read",
9b8438
				"s390_pci_mmio_write",
9b8438
				"s390_runtime_instr"
9b8438
			],
9b8438
			"action": "SCMP_ACT_ALLOW",
9b8438
			"args": [],
9b8438
			"comment": "",
9b8438
			"includes": {
9b8438
				"arches": [
9b8438
					"s390",
9b8438
					"s390x"
9b8438
				]
9b8438
			},
9b8438
			"excludes": {}
9b8438
		},
9b8438
		{
9b8438
			"names": [
9b8438
				"open_by_handle_at"
9b8438
			],
9b8438
			"action": "SCMP_ACT_ALLOW",
9b8438
			"args": [],
9b8438
			"comment": "",
9b8438
			"includes": {
9b8438
				"caps": [
9b8438
					"CAP_DAC_READ_SEARCH"
9b8438
				]
9b8438
			},
9b8438
			"excludes": {}
9b8438
		},
9b8438
		{
9b8438
			"names": [
9b8438
				"bpf",
9b8438
				"clone",
9b8438
				"fanotify_init",
9b8438
				"lookup_dcookie",
9b8438
				"mount",
9b8438
				"name_to_handle_at",
9b8438
				"perf_event_open",
9b8438
				"setdomainname",
9b8438
				"sethostname",
9b8438
				"setns",
9b8438
				"umount",
9b8438
				"umount2",
9b8438
				"unshare"
9b8438
			],
9b8438
			"action": "SCMP_ACT_ALLOW",
9b8438
			"args": [],
9b8438
			"comment": "",
9b8438
			"includes": {
9b8438
				"caps": [
9b8438
					"CAP_SYS_ADMIN"
9b8438
				]
9b8438
			},
9b8438
			"excludes": {}
9b8438
		},
9b8438
		{
9b8438
			"names": [
9b8438
				"clone"
9b8438
			],
9b8438
			"action": "SCMP_ACT_ALLOW",
9b8438
			"args": [
9b8438
				{
9b8438
					"index": 0,
9b8438
					"value": 2080505856,
9b8438
					"valueTwo": 0,
9b8438
					"op": "SCMP_CMP_MASKED_EQ"
9b8438
				}
9b8438
			],
9b8438
			"comment": "",
9b8438
			"includes": {},
9b8438
			"excludes": {
9b8438
				"caps": [
9b8438
					"CAP_SYS_ADMIN"
9b8438
				],
9b8438
				"arches": [
9b8438
					"s390",
9b8438
					"s390x"
9b8438
				]
9b8438
			}
9b8438
		},
9b8438
		{
9b8438
			"names": [
9b8438
				"clone"
9b8438
			],
9b8438
			"action": "SCMP_ACT_ALLOW",
9b8438
			"args": [
9b8438
				{
9b8438
					"index": 1,
9b8438
					"value": 2080505856,
9b8438
					"valueTwo": 0,
9b8438
					"op": "SCMP_CMP_MASKED_EQ"
9b8438
				}
9b8438
			],
9b8438
			"comment": "s390 parameter ordering for clone is different",
9b8438
			"includes": {
9b8438
				"arches": [
9b8438
					"s390",
9b8438
					"s390x"
9b8438
				]
9b8438
			},
9b8438
			"excludes": {
9b8438
				"caps": [
9b8438
					"CAP_SYS_ADMIN"
9b8438
				]
9b8438
			}
9b8438
		},
9b8438
		{
9b8438
			"names": [
9b8438
				"reboot"
9b8438
			],
9b8438
			"action": "SCMP_ACT_ALLOW",
9b8438
			"args": [],
9b8438
			"comment": "",
9b8438
			"includes": {
9b8438
				"caps": [
9b8438
					"CAP_SYS_BOOT"
9b8438
				]
9b8438
			},
9b8438
			"excludes": {}
9b8438
		},
9b8438
		{
9b8438
			"names": [
9b8438
				"chroot"
9b8438
			],
9b8438
			"action": "SCMP_ACT_ALLOW",
9b8438
			"args": [],
9b8438
			"comment": "",
9b8438
			"includes": {
9b8438
				"caps": [
9b8438
					"CAP_SYS_CHROOT"
9b8438
				]
9b8438
			},
9b8438
			"excludes": {}
9b8438
		},
9b8438
		{
9b8438
			"names": [
9b8438
				"delete_module",
9b8438
				"init_module",
9b8438
				"finit_module",
9b8438
				"query_module"
9b8438
			],
9b8438
			"action": "SCMP_ACT_ALLOW",
9b8438
			"args": [],
9b8438
			"comment": "",
9b8438
			"includes": {
9b8438
				"caps": [
9b8438
					"CAP_SYS_MODULE"
9b8438
				]
9b8438
			},
9b8438
			"excludes": {}
9b8438
		},
9b8438
		{
9b8438
			"names": [
9b8438
				"acct"
9b8438
			],
9b8438
			"action": "SCMP_ACT_ALLOW",
9b8438
			"args": [],
9b8438
			"comment": "",
9b8438
			"includes": {
9b8438
				"caps": [
9b8438
					"CAP_SYS_PACCT"
9b8438
				]
9b8438
			},
9b8438
			"excludes": {}
9b8438
		},
9b8438
		{
9b8438
			"names": [
9b8438
				"kcmp",
9b8438
				"process_vm_readv",
9b8438
				"process_vm_writev",
9b8438
				"ptrace"
9b8438
			],
9b8438
			"action": "SCMP_ACT_ALLOW",
9b8438
			"args": [],
9b8438
			"comment": "",
9b8438
			"includes": {
9b8438
				"caps": [
9b8438
					"CAP_SYS_PTRACE"
9b8438
				]
9b8438
			},
9b8438
			"excludes": {}
9b8438
		},
9b8438
		{
9b8438
			"names": [
9b8438
				"iopl",
9b8438
				"ioperm"
9b8438
			],
9b8438
			"action": "SCMP_ACT_ALLOW",
9b8438
			"args": [],
9b8438
			"comment": "",
9b8438
			"includes": {
9b8438
				"caps": [
9b8438
					"CAP_SYS_RAWIO"
9b8438
				]
9b8438
			},
9b8438
			"excludes": {}
9b8438
		},
9b8438
		{
9b8438
			"names": [
9b8438
				"settimeofday",
9b8438
				"stime",
9b8438
				"adjtimex"
9b8438
			],
9b8438
			"action": "SCMP_ACT_ALLOW",
9b8438
			"args": [],
9b8438
			"comment": "",
9b8438
			"includes": {
9b8438
				"caps": [
9b8438
					"CAP_SYS_TIME"
9b8438
				]
9b8438
			},
9b8438
			"excludes": {}
9b8438
		},
9b8438
		{
9b8438
			"names": [
9b8438
				"vhangup"
9b8438
			],
9b8438
			"action": "SCMP_ACT_ALLOW",
9b8438
			"args": [],
9b8438
			"comment": "",
9b8438
			"includes": {
9b8438
				"caps": [
9b8438
					"CAP_SYS_TTY_CONFIG"
9b8438
				]
9b8438
			},
9b8438
			"excludes": {}
9b8438
		}
9b8438
	]
9b8438
}