hughesjr / rpms / docker

Forked from rpms/docker 4 years ago
Clone

Blame SOURCES/seccomp.json

10eb08
{
10eb08
	"defaultAction": "SCMP_ACT_ERRNO",
10eb08
	"archMap": [
10eb08
		{
10eb08
			"architecture": "SCMP_ARCH_X86_64",
10eb08
			"subArchitectures": [
10eb08
				"SCMP_ARCH_X86",
10eb08
				"SCMP_ARCH_X32"
10eb08
			]
10eb08
		},
10eb08
		{
10eb08
			"architecture": "SCMP_ARCH_AARCH64",
10eb08
			"subArchitectures": [
10eb08
				"SCMP_ARCH_ARM"
10eb08
			]
10eb08
		},
10eb08
		{
10eb08
			"architecture": "SCMP_ARCH_MIPS64",
10eb08
			"subArchitectures": [
10eb08
				"SCMP_ARCH_MIPS",
10eb08
				"SCMP_ARCH_MIPS64N32"
10eb08
			]
10eb08
		},
10eb08
		{
10eb08
			"architecture": "SCMP_ARCH_MIPS64N32",
10eb08
			"subArchitectures": [
10eb08
				"SCMP_ARCH_MIPS",
10eb08
				"SCMP_ARCH_MIPS64"
10eb08
			]
10eb08
		},
10eb08
		{
10eb08
			"architecture": "SCMP_ARCH_MIPSEL64",
10eb08
			"subArchitectures": [
10eb08
				"SCMP_ARCH_MIPSEL",
10eb08
				"SCMP_ARCH_MIPSEL64N32"
10eb08
			]
10eb08
		},
10eb08
		{
10eb08
			"architecture": "SCMP_ARCH_MIPSEL64N32",
10eb08
			"subArchitectures": [
10eb08
				"SCMP_ARCH_MIPSEL",
10eb08
				"SCMP_ARCH_MIPSEL64"
10eb08
			]
10eb08
		},
10eb08
		{
10eb08
			"architecture": "SCMP_ARCH_S390X",
10eb08
			"subArchitectures": [
10eb08
				"SCMP_ARCH_S390"
10eb08
			]
10eb08
		}
10eb08
	],
10eb08
	"syscalls": [
10eb08
		{
10eb08
			"names": [
10eb08
				"accept",
10eb08
				"accept4",
10eb08
				"access",
10eb08
				"alarm",
10eb08
				"alarm",
10eb08
				"bind",
10eb08
				"brk",
10eb08
				"capget",
10eb08
				"capset",
10eb08
				"chdir",
10eb08
				"chmod",
10eb08
				"chown",
10eb08
				"chown32",
10eb08
				"clock_getres",
10eb08
				"clock_gettime",
10eb08
				"clock_nanosleep",
10eb08
				"close",
10eb08
				"connect",
10eb08
				"copy_file_range",
10eb08
				"creat",
10eb08
				"dup",
10eb08
				"dup2",
10eb08
				"dup3",
10eb08
				"epoll_create",
10eb08
				"epoll_create1",
10eb08
				"epoll_ctl",
10eb08
				"epoll_ctl_old",
10eb08
				"epoll_pwait",
10eb08
				"epoll_wait",
10eb08
				"epoll_wait_old",
10eb08
				"eventfd",
10eb08
				"eventfd2",
10eb08
				"execve",
10eb08
				"execveat",
10eb08
				"exit",
10eb08
				"exit_group",
10eb08
				"faccessat",
10eb08
				"fadvise64",
10eb08
				"fadvise64_64",
10eb08
				"fallocate",
10eb08
				"fanotify_mark",
10eb08
				"fchdir",
10eb08
				"fchmod",
10eb08
				"fchmodat",
10eb08
				"fchown",
10eb08
				"fchown32",
10eb08
				"fchownat",
10eb08
				"fcntl",
10eb08
				"fcntl64",
10eb08
				"fdatasync",
10eb08
				"fgetxattr",
10eb08
				"flistxattr",
10eb08
				"flock",
10eb08
				"fork",
10eb08
				"fremovexattr",
10eb08
				"fsetxattr",
10eb08
				"fstat",
10eb08
				"fstat64",
10eb08
				"fstatat64",
10eb08
				"fstatfs",
10eb08
				"fstatfs64",
10eb08
				"fsync",
10eb08
				"ftruncate",
10eb08
				"ftruncate64",
10eb08
				"futex",
10eb08
				"futimesat",
10eb08
				"getcpu",
10eb08
				"getcwd",
10eb08
				"getdents",
10eb08
				"getdents64",
10eb08
				"getegid",
10eb08
				"getegid32",
10eb08
				"geteuid",
10eb08
				"geteuid32",
10eb08
				"getgid",
10eb08
				"getgid32",
10eb08
				"getgroups",
10eb08
				"getgroups32",
10eb08
				"getitimer",
10eb08
				"getpeername",
10eb08
				"getpgid",
10eb08
				"getpgrp",
10eb08
				"getpid",
10eb08
				"getppid",
10eb08
				"getpriority",
10eb08
				"getrandom",
10eb08
				"getresgid",
10eb08
				"getresgid32",
10eb08
				"getresuid",
10eb08
				"getresuid32",
10eb08
				"getrlimit",
10eb08
				"get_robust_list",
10eb08
				"getrusage",
10eb08
				"getsid",
10eb08
				"getsockname",
10eb08
				"getsockopt",
10eb08
				"get_thread_area",
10eb08
				"gettid",
10eb08
				"gettimeofday",
10eb08
				"getuid",
10eb08
				"getuid32",
10eb08
				"getxattr",
10eb08
				"inotify_add_watch",
10eb08
				"inotify_init",
10eb08
				"inotify_init1",
10eb08
				"inotify_rm_watch",
10eb08
				"io_cancel",
10eb08
				"ioctl",
10eb08
				"io_destroy",
10eb08
				"io_getevents",
10eb08
				"ioprio_get",
10eb08
				"ioprio_set",
10eb08
				"io_setup",
10eb08
				"io_submit",
10eb08
				"ipc",
10eb08
				"kill",
10eb08
				"lchown",
10eb08
				"lchown32",
10eb08
				"lgetxattr",
10eb08
				"link",
10eb08
				"linkat",
10eb08
				"listen",
10eb08
				"listxattr",
10eb08
				"llistxattr",
10eb08
				"_llseek",
10eb08
				"lremovexattr",
10eb08
				"lseek",
10eb08
				"lsetxattr",
10eb08
				"lstat",
10eb08
				"lstat64",
10eb08
				"madvise",
10eb08
				"memfd_create",
10eb08
				"mincore",
10eb08
				"mkdir",
10eb08
				"mkdirat",
10eb08
				"mknod",
10eb08
				"mknodat",
10eb08
				"mlock",
10eb08
				"mlock2",
10eb08
				"mlockall",
10eb08
				"mmap",
10eb08
				"mmap2",
10eb08
				"mprotect",
10eb08
				"mq_getsetattr",
10eb08
				"mq_notify",
10eb08
				"mq_open",
10eb08
				"mq_timedreceive",
10eb08
				"mq_timedsend",
10eb08
				"mq_unlink",
10eb08
				"mremap",
10eb08
				"msgctl",
10eb08
				"msgget",
10eb08
				"msgrcv",
10eb08
				"msgsnd",
10eb08
				"msync",
10eb08
				"munlock",
10eb08
				"munlockall",
10eb08
				"munmap",
10eb08
				"nanosleep",
10eb08
				"newfstatat",
10eb08
				"_newselect",
10eb08
				"open",
10eb08
				"openat",
10eb08
				"pause",
10eb08
				"pipe",
10eb08
				"pipe2",
10eb08
				"poll",
10eb08
				"ppoll",
10eb08
				"prctl",
10eb08
				"pread64",
10eb08
				"preadv",
10eb08
				"prlimit64",
10eb08
				"pselect6",
10eb08
				"pwrite64",
10eb08
				"pwritev",
10eb08
				"read",
10eb08
				"readahead",
10eb08
				"readlink",
10eb08
				"readlinkat",
10eb08
				"readv",
10eb08
				"recv",
10eb08
				"recvfrom",
10eb08
				"recvmmsg",
10eb08
				"recvmsg",
10eb08
				"remap_file_pages",
10eb08
				"removexattr",
10eb08
				"rename",
10eb08
				"renameat",
10eb08
				"renameat2",
10eb08
				"restart_syscall",
10eb08
				"rmdir",
10eb08
				"rt_sigaction",
10eb08
				"rt_sigpending",
10eb08
				"rt_sigprocmask",
10eb08
				"rt_sigqueueinfo",
10eb08
				"rt_sigreturn",
10eb08
				"rt_sigsuspend",
10eb08
				"rt_sigtimedwait",
10eb08
				"rt_tgsigqueueinfo",
10eb08
				"sched_getaffinity",
10eb08
				"sched_getattr",
10eb08
				"sched_getparam",
10eb08
				"sched_get_priority_max",
10eb08
				"sched_get_priority_min",
10eb08
				"sched_getscheduler",
10eb08
				"sched_rr_get_interval",
10eb08
				"sched_setaffinity",
10eb08
				"sched_setattr",
10eb08
				"sched_setparam",
10eb08
				"sched_setscheduler",
10eb08
				"sched_yield",
10eb08
				"seccomp",
10eb08
				"select",
10eb08
				"semctl",
10eb08
				"semget",
10eb08
				"semop",
10eb08
				"semtimedop",
10eb08
				"send",
10eb08
				"sendfile",
10eb08
				"sendfile64",
10eb08
				"sendmmsg",
10eb08
				"sendmsg",
10eb08
				"sendto",
10eb08
				"setfsgid",
10eb08
				"setfsgid32",
10eb08
				"setfsuid",
10eb08
				"setfsuid32",
10eb08
				"setgid",
10eb08
				"setgid32",
10eb08
				"setgroups",
10eb08
				"setgroups32",
10eb08
				"setitimer",
10eb08
				"setpgid",
10eb08
				"setpriority",
10eb08
				"setregid",
10eb08
				"setregid32",
10eb08
				"setresgid",
10eb08
				"setresgid32",
10eb08
				"setresuid",
10eb08
				"setresuid32",
10eb08
				"setreuid",
10eb08
				"setreuid32",
10eb08
				"setrlimit",
10eb08
				"set_robust_list",
10eb08
				"setsid",
10eb08
				"setsockopt",
10eb08
				"set_thread_area",
10eb08
				"set_tid_address",
10eb08
				"setuid",
10eb08
				"setuid32",
10eb08
				"setxattr",
10eb08
				"shmat",
10eb08
				"shmctl",
10eb08
				"shmdt",
10eb08
				"shmget",
10eb08
				"shutdown",
10eb08
				"sigaltstack",
10eb08
				"signalfd",
10eb08
				"signalfd4",
10eb08
				"sigreturn",
10eb08
				"socket",
10eb08
				"socketcall",
10eb08
				"socketpair",
10eb08
				"splice",
10eb08
				"stat",
10eb08
				"stat64",
10eb08
				"statfs",
10eb08
				"statfs64",
10eb08
				"symlink",
10eb08
				"symlinkat",
10eb08
				"sync",
10eb08
				"sync_file_range",
10eb08
				"syncfs",
10eb08
				"sysinfo",
10eb08
				"syslog",
10eb08
				"tee",
10eb08
				"tgkill",
10eb08
				"time",
10eb08
				"timer_create",
10eb08
				"timer_delete",
10eb08
				"timerfd_create",
10eb08
				"timerfd_gettime",
10eb08
				"timerfd_settime",
10eb08
				"timer_getoverrun",
10eb08
				"timer_gettime",
10eb08
				"timer_settime",
10eb08
				"times",
10eb08
				"tkill",
10eb08
				"truncate",
10eb08
				"truncate64",
10eb08
				"ugetrlimit",
10eb08
				"umask",
10eb08
				"uname",
10eb08
				"unlink",
10eb08
				"unlinkat",
10eb08
				"utime",
10eb08
				"utimensat",
10eb08
				"utimes",
10eb08
				"vfork",
10eb08
				"vmsplice",
10eb08
				"wait4",
10eb08
				"waitid",
10eb08
				"waitpid",
10eb08
				"write",
10eb08
				"writev",
10eb08
				"mount",
10eb08
				"umount2",
10eb08
				"reboot",
10eb08
				"name_to_handle_at",
10eb08
				"unshare"
10eb08
			],
10eb08
			"action": "SCMP_ACT_ALLOW",
10eb08
			"args": [],
10eb08
			"comment": "",
10eb08
			"includes": {},
10eb08
			"excludes": {}
10eb08
		},
10eb08
		{
10eb08
			"names": [
10eb08
				"personality"
10eb08
			],
10eb08
			"action": "SCMP_ACT_ALLOW",
10eb08
			"args": [
10eb08
				{
10eb08
					"index": 0,
10eb08
					"value": 0,
10eb08
					"valueTwo": 0,
10eb08
					"op": "SCMP_CMP_EQ"
10eb08
				}
10eb08
			],
10eb08
			"comment": "",
10eb08
			"includes": {},
10eb08
			"excludes": {}
10eb08
		},
10eb08
		{
10eb08
			"names": [
10eb08
				"personality"
10eb08
			],
10eb08
			"action": "SCMP_ACT_ALLOW",
10eb08
			"args": [
10eb08
				{
10eb08
					"index": 0,
10eb08
					"value": 8,
10eb08
					"valueTwo": 0,
10eb08
					"op": "SCMP_CMP_EQ"
10eb08
				}
10eb08
			],
10eb08
			"comment": "",
10eb08
			"includes": {},
10eb08
			"excludes": {}
10eb08
		},
10eb08
		{
10eb08
			"names": [
10eb08
				"personality"
10eb08
			],
10eb08
			"action": "SCMP_ACT_ALLOW",
10eb08
			"args": [
10eb08
				{
10eb08
					"index": 0,
10eb08
					"value": 4294967295,
10eb08
					"valueTwo": 0,
10eb08
					"op": "SCMP_CMP_EQ"
10eb08
				}
10eb08
			],
10eb08
			"comment": "",
10eb08
			"includes": {},
10eb08
			"excludes": {}
10eb08
		},
10eb08
		{
10eb08
			"names": [
10eb08
				"breakpoint",
10eb08
				"cacheflush",
10eb08
				"set_tls"
10eb08
			],
10eb08
			"action": "SCMP_ACT_ALLOW",
10eb08
			"args": [],
10eb08
			"comment": "",
10eb08
			"includes": {
10eb08
				"arches": [
10eb08
					"arm",
10eb08
					"arm64"
10eb08
				]
10eb08
			},
10eb08
			"excludes": {}
10eb08
		},
10eb08
		{
10eb08
			"names": [
10eb08
				"arch_prctl"
10eb08
			],
10eb08
			"action": "SCMP_ACT_ALLOW",
10eb08
			"args": [],
10eb08
			"comment": "",
10eb08
			"includes": {
10eb08
				"arches": [
10eb08
					"amd64",
10eb08
					"x32"
10eb08
				]
10eb08
			},
10eb08
			"excludes": {}
10eb08
		},
10eb08
		{
10eb08
			"names": [
10eb08
				"modify_ldt"
10eb08
			],
10eb08
			"action": "SCMP_ACT_ALLOW",
10eb08
			"args": [],
10eb08
			"comment": "",
10eb08
			"includes": {
10eb08
				"arches": [
10eb08
					"amd64",
10eb08
					"x32",
10eb08
					"x86"
10eb08
				]
10eb08
			},
10eb08
			"excludes": {}
10eb08
		},
10eb08
		{
10eb08
			"names": [
10eb08
				"s390_pci_mmio_read",
10eb08
				"s390_pci_mmio_write",
10eb08
				"s390_runtime_instr"
10eb08
			],
10eb08
			"action": "SCMP_ACT_ALLOW",
10eb08
			"args": [],
10eb08
			"comment": "",
10eb08
			"includes": {
10eb08
				"arches": [
10eb08
					"s390",
10eb08
					"s390x"
10eb08
				]
10eb08
			},
10eb08
			"excludes": {}
10eb08
		},
10eb08
		{
10eb08
			"names": [
10eb08
				"open_by_handle_at"
10eb08
			],
10eb08
			"action": "SCMP_ACT_ALLOW",
10eb08
			"args": [],
10eb08
			"comment": "",
10eb08
			"includes": {
10eb08
				"caps": [
10eb08
					"CAP_DAC_READ_SEARCH"
10eb08
				]
10eb08
			},
10eb08
			"excludes": {}
10eb08
		},
10eb08
		{
10eb08
			"names": [
10eb08
				"bpf",
10eb08
				"clone",
10eb08
				"fanotify_init",
10eb08
				"lookup_dcookie",
10eb08
				"mount",
10eb08
				"name_to_handle_at",
10eb08
				"perf_event_open",
10eb08
				"setdomainname",
10eb08
				"sethostname",
10eb08
				"setns",
10eb08
				"umount",
10eb08
				"umount2",
10eb08
				"unshare"
10eb08
			],
10eb08
			"action": "SCMP_ACT_ALLOW",
10eb08
			"args": [],
10eb08
			"comment": "",
10eb08
			"includes": {
10eb08
				"caps": [
10eb08
					"CAP_SYS_ADMIN"
10eb08
				]
10eb08
			},
10eb08
			"excludes": {}
10eb08
		},
10eb08
		{
10eb08
			"names": [
10eb08
				"clone"
10eb08
			],
10eb08
			"action": "SCMP_ACT_ALLOW",
10eb08
			"args": [
10eb08
				{
10eb08
					"index": 0,
10eb08
					"value": 2080505856,
10eb08
					"valueTwo": 0,
10eb08
					"op": "SCMP_CMP_MASKED_EQ"
10eb08
				}
10eb08
			],
10eb08
			"comment": "",
10eb08
			"includes": {},
10eb08
			"excludes": {
10eb08
				"caps": [
10eb08
					"CAP_SYS_ADMIN"
10eb08
				],
10eb08
				"arches": [
10eb08
					"s390",
10eb08
					"s390x"
10eb08
				]
10eb08
			}
10eb08
		},
10eb08
		{
10eb08
			"names": [
10eb08
				"clone"
10eb08
			],
10eb08
			"action": "SCMP_ACT_ALLOW",
10eb08
			"args": [
10eb08
				{
10eb08
					"index": 1,
10eb08
					"value": 2080505856,
10eb08
					"valueTwo": 0,
10eb08
					"op": "SCMP_CMP_MASKED_EQ"
10eb08
				}
10eb08
			],
10eb08
			"comment": "s390 parameter ordering for clone is different",
10eb08
			"includes": {
10eb08
				"arches": [
10eb08
					"s390",
10eb08
					"s390x"
10eb08
				]
10eb08
			},
10eb08
			"excludes": {
10eb08
				"caps": [
10eb08
					"CAP_SYS_ADMIN"
10eb08
				]
10eb08
			}
10eb08
		},
10eb08
		{
10eb08
			"names": [
10eb08
				"reboot"
10eb08
			],
10eb08
			"action": "SCMP_ACT_ALLOW",
10eb08
			"args": [],
10eb08
			"comment": "",
10eb08
			"includes": {
10eb08
				"caps": [
10eb08
					"CAP_SYS_BOOT"
10eb08
				]
10eb08
			},
10eb08
			"excludes": {}
10eb08
		},
10eb08
		{
10eb08
			"names": [
10eb08
				"chroot"
10eb08
			],
10eb08
			"action": "SCMP_ACT_ALLOW",
10eb08
			"args": [],
10eb08
			"comment": "",
10eb08
			"includes": {
10eb08
				"caps": [
10eb08
					"CAP_SYS_CHROOT"
10eb08
				]
10eb08
			},
10eb08
			"excludes": {}
10eb08
		},
10eb08
		{
10eb08
			"names": [
10eb08
				"delete_module",
10eb08
				"init_module",
10eb08
				"finit_module",
10eb08
				"query_module"
10eb08
			],
10eb08
			"action": "SCMP_ACT_ALLOW",
10eb08
			"args": [],
10eb08
			"comment": "",
10eb08
			"includes": {
10eb08
				"caps": [
10eb08
					"CAP_SYS_MODULE"
10eb08
				]
10eb08
			},
10eb08
			"excludes": {}
10eb08
		},
10eb08
		{
10eb08
			"names": [
10eb08
				"acct"
10eb08
			],
10eb08
			"action": "SCMP_ACT_ALLOW",
10eb08
			"args": [],
10eb08
			"comment": "",
10eb08
			"includes": {
10eb08
				"caps": [
10eb08
					"CAP_SYS_PACCT"
10eb08
				]
10eb08
			},
10eb08
			"excludes": {}
10eb08
		},
10eb08
		{
10eb08
			"names": [
10eb08
				"kcmp",
10eb08
				"process_vm_readv",
10eb08
				"process_vm_writev",
10eb08
				"ptrace"
10eb08
			],
10eb08
			"action": "SCMP_ACT_ALLOW",
10eb08
			"args": [],
10eb08
			"comment": "",
10eb08
			"includes": {
10eb08
				"caps": [
10eb08
					"CAP_SYS_PTRACE"
10eb08
				]
10eb08
			},
10eb08
			"excludes": {}
10eb08
		},
10eb08
		{
10eb08
			"names": [
10eb08
				"iopl",
10eb08
				"ioperm"
10eb08
			],
10eb08
			"action": "SCMP_ACT_ALLOW",
10eb08
			"args": [],
10eb08
			"comment": "",
10eb08
			"includes": {
10eb08
				"caps": [
10eb08
					"CAP_SYS_RAWIO"
10eb08
				]
10eb08
			},
10eb08
			"excludes": {}
10eb08
		},
10eb08
		{
10eb08
			"names": [
10eb08
				"settimeofday",
10eb08
				"stime",
10eb08
				"adjtimex"
10eb08
			],
10eb08
			"action": "SCMP_ACT_ALLOW",
10eb08
			"args": [],
10eb08
			"comment": "",
10eb08
			"includes": {
10eb08
				"caps": [
10eb08
					"CAP_SYS_TIME"
10eb08
				]
10eb08
			},
10eb08
			"excludes": {}
10eb08
		},
10eb08
		{
10eb08
			"names": [
10eb08
				"vhangup"
10eb08
			],
10eb08
			"action": "SCMP_ACT_ALLOW",
10eb08
			"args": [],
10eb08
			"comment": "",
10eb08
			"includes": {
10eb08
				"caps": [
10eb08
					"CAP_SYS_TTY_CONFIG"
10eb08
				]
10eb08
			},
10eb08
			"excludes": {}
10eb08
		}
10eb08
	]
10eb08
}