seccomp: seccomp: add syscalls related to PKU in default policy
Add pkey_alloc(2), pkey_free(2) and pkey_mprotect(2) in seccomp default profile. pkey_alloc(2), pkey_free(2) and pkey_mprotect(2) can only configure the calling process's own memory, so they are existing "safe for everyone" syscalls. Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
This commit is contained in:
		| @@ -249,6 +249,9 @@ func DefaultProfile(sp *specs.Spec) *specs.LinuxSeccomp { | |||||||
| 				"pidfd_send_signal", | 				"pidfd_send_signal", | ||||||
| 				"pipe", | 				"pipe", | ||||||
| 				"pipe2", | 				"pipe2", | ||||||
|  | 				"pkey_alloc", | ||||||
|  | 				"pkey_free", | ||||||
|  | 				"pkey_mprotect", | ||||||
| 				"poll", | 				"poll", | ||||||
| 				"ppoll", | 				"ppoll", | ||||||
| 				"ppoll_time64", | 				"ppoll_time64", | ||||||
|   | |||||||
		Reference in New Issue
	
	Block a user
	 Sebastiaan van Stijn
					Sebastiaan van Stijn