From c44bc6612fc4554d0aa4e484a46cd1f6b6a7b5c5 Mon Sep 17 00:00:00 2001 From: Fabricio Voznika Date: Tue, 11 Sep 2018 11:04:06 -0700 Subject: Allow fstatat back in syscall filters PiperOrigin-RevId: 212483372 Change-Id: If95f32a8e41126cf3dc8bd6c8b2fb0fcfefedc6d --- runsc/boot/filter/config.go | 15 ++++++++------- 1 file changed, 8 insertions(+), 7 deletions(-) diff --git a/runsc/boot/filter/config.go b/runsc/boot/filter/config.go index 1a0c426ab..8cdf56963 100644 --- a/runsc/boot/filter/config.go +++ b/runsc/boot/filter/config.go @@ -205,13 +205,14 @@ var allowedSyscalls = seccomp.SyscallRules{ seccomp.AllowValue(syscall.MAP_PRIVATE | syscall.MAP_ANONYMOUS | syscall.MAP_FIXED), }, }, - syscall.SYS_MPROTECT: {}, - syscall.SYS_MUNMAP: {}, - syscall.SYS_NANOSLEEP: {}, - syscall.SYS_POLL: {}, - syscall.SYS_PREAD64: {}, - syscall.SYS_PWRITE64: {}, - syscall.SYS_READ: {}, + syscall.SYS_MPROTECT: {}, + syscall.SYS_MUNMAP: {}, + syscall.SYS_NANOSLEEP: {}, + syscall.SYS_NEWFSTATAT: {}, + syscall.SYS_POLL: {}, + syscall.SYS_PREAD64: {}, + syscall.SYS_PWRITE64: {}, + syscall.SYS_READ: {}, syscall.SYS_READV: []seccomp.Rule{ { seccomp.AllowAny{}, -- cgit v1.2.3