de7ddf
{
de7ddf
	"defaultAction": "SCMP_ACT_ERRNO",
de7ddf
	"defaultErrnoRet": 38,
de7ddf
	"archMap": [
de7ddf
		{
de7ddf
			"architecture": "SCMP_ARCH_X86_64",
de7ddf
			"subArchitectures": [
de7ddf
				"SCMP_ARCH_X86",
de7ddf
				"SCMP_ARCH_X32"
de7ddf
			]
de7ddf
		},
de7ddf
		{
de7ddf
			"architecture": "SCMP_ARCH_AARCH64",
de7ddf
			"subArchitectures": [
de7ddf
				"SCMP_ARCH_ARM"
de7ddf
			]
de7ddf
		},
de7ddf
		{
de7ddf
			"architecture": "SCMP_ARCH_MIPS64",
de7ddf
			"subArchitectures": [
de7ddf
				"SCMP_ARCH_MIPS",
de7ddf
				"SCMP_ARCH_MIPS64N32"
de7ddf
			]
de7ddf
		},
de7ddf
		{
de7ddf
			"architecture": "SCMP_ARCH_MIPS64N32",
de7ddf
			"subArchitectures": [
de7ddf
				"SCMP_ARCH_MIPS",
de7ddf
				"SCMP_ARCH_MIPS64"
de7ddf
			]
de7ddf
		},
de7ddf
		{
de7ddf
			"architecture": "SCMP_ARCH_MIPSEL64",
de7ddf
			"subArchitectures": [
de7ddf
				"SCMP_ARCH_MIPSEL",
de7ddf
				"SCMP_ARCH_MIPSEL64N32"
de7ddf
			]
de7ddf
		},
de7ddf
		{
de7ddf
			"architecture": "SCMP_ARCH_MIPSEL64N32",
de7ddf
			"subArchitectures": [
de7ddf
				"SCMP_ARCH_MIPSEL",
de7ddf
				"SCMP_ARCH_MIPSEL64"
de7ddf
			]
de7ddf
		},
de7ddf
		{
de7ddf
			"architecture": "SCMP_ARCH_S390X",
de7ddf
			"subArchitectures": [
de7ddf
				"SCMP_ARCH_S390"
de7ddf
			]
de7ddf
		}
de7ddf
	],
de7ddf
	"syscalls": [
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"bdflush",
de7ddf
				"io_pgetevents",
de7ddf
				"kexec_file_load",
de7ddf
				"kexec_load",
de7ddf
				"migrate_pages",
de7ddf
				"move_pages",
de7ddf
				"nfsservctl",
de7ddf
				"nice",
de7ddf
				"oldfstat",
de7ddf
				"oldlstat",
de7ddf
				"oldolduname",
de7ddf
				"oldstat",
de7ddf
				"olduname",
de7ddf
				"pciconfig_iobase",
de7ddf
				"pciconfig_read",
de7ddf
				"pciconfig_write",
de7ddf
				"sgetmask",
de7ddf
				"ssetmask",
de7ddf
				"swapcontext",
de7ddf
				"swapoff",
de7ddf
				"swapon",
de7ddf
				"sysfs",
de7ddf
				"uselib",
de7ddf
				"userfaultfd",
de7ddf
				"ustat",
de7ddf
				"vm86",
de7ddf
				"vm86old",
de7ddf
				"vmsplice"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ERRNO",
de7ddf
			"args": [],
de7ddf
			"comment": "",
de7ddf
			"includes": {},
de7ddf
			"excludes": {},
de7ddf
			"errnoRet": 1
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"_llseek",
de7ddf
				"_newselect",
de7ddf
				"accept",
de7ddf
				"accept4",
de7ddf
				"access",
de7ddf
				"adjtimex",
de7ddf
				"alarm",
de7ddf
				"bind",
de7ddf
				"brk",
de7ddf
				"capget",
de7ddf
				"capset",
de7ddf
				"chdir",
de7ddf
				"chmod",
de7ddf
				"chown",
de7ddf
				"chown32",
de7ddf
				"clock_adjtime",
de7ddf
				"clock_adjtime64",
de7ddf
				"clock_getres",
de7ddf
				"clock_getres_time64",
de7ddf
				"clock_gettime",
de7ddf
				"clock_gettime64",
de7ddf
				"clock_nanosleep",
de7ddf
				"clock_nanosleep_time64",
de7ddf
				"clone",
de7ddf
				"clone3",
de7ddf
				"close",
de7ddf
				"close_range",
de7ddf
				"connect",
de7ddf
				"copy_file_range",
de7ddf
				"creat",
de7ddf
				"dup",
de7ddf
				"dup2",
de7ddf
				"dup3",
de7ddf
				"epoll_create",
de7ddf
				"epoll_create1",
de7ddf
				"epoll_ctl",
de7ddf
				"epoll_ctl_old",
de7ddf
				"epoll_pwait",
de7ddf
				"epoll_pwait2",
de7ddf
				"epoll_wait",
de7ddf
				"epoll_wait_old",
de7ddf
				"eventfd",
de7ddf
				"eventfd2",
de7ddf
				"execve",
de7ddf
				"execveat",
de7ddf
				"exit",
de7ddf
				"exit_group",
de7ddf
				"faccessat",
de7ddf
				"faccessat2",
de7ddf
				"fadvise64",
de7ddf
				"fadvise64_64",
de7ddf
				"fallocate",
de7ddf
				"fanotify_mark",
de7ddf
				"fchdir",
de7ddf
				"fchmod",
de7ddf
				"fchmodat",
de7ddf
				"fchown",
de7ddf
				"fchown32",
de7ddf
				"fchownat",
de7ddf
				"fcntl",
de7ddf
				"fcntl64",
de7ddf
				"fdatasync",
de7ddf
				"fgetxattr",
de7ddf
				"flistxattr",
de7ddf
				"flock",
de7ddf
				"fork",
de7ddf
				"fremovexattr",
de7ddf
				"fsconfig",
de7ddf
				"fsetxattr",
de7ddf
				"fsmount",
de7ddf
				"fsopen",
de7ddf
				"fspick",
de7ddf
				"fstat",
de7ddf
				"fstat64",
de7ddf
				"fstatat64",
de7ddf
				"fstatfs",
de7ddf
				"fstatfs64",
de7ddf
				"fsync",
de7ddf
				"ftruncate",
de7ddf
				"ftruncate64",
de7ddf
				"futex",
de7ddf
				"futex_time64",
de7ddf
				"futimesat",
de7ddf
				"get_robust_list",
de7ddf
				"get_thread_area",
de7ddf
				"getcpu",
de7ddf
				"getcwd",
de7ddf
				"getdents",
de7ddf
				"getdents64",
de7ddf
				"getegid",
de7ddf
				"getegid32",
de7ddf
				"geteuid",
de7ddf
				"geteuid32",
de7ddf
				"getgid",
de7ddf
				"getgid32",
de7ddf
				"getgroups",
de7ddf
				"getgroups32",
de7ddf
				"getitimer",
de7ddf
				"get_mempolicy",
de7ddf
				"getpeername",
de7ddf
				"getpgid",
de7ddf
				"getpgrp",
de7ddf
				"getpid",
de7ddf
				"getppid",
de7ddf
				"getpriority",
de7ddf
				"getrandom",
de7ddf
				"getresgid",
de7ddf
				"getresgid32",
de7ddf
				"getresuid",
de7ddf
				"getresuid32",
de7ddf
				"getrlimit",
de7ddf
				"getrusage",
de7ddf
				"getsid",
de7ddf
				"getsockname",
de7ddf
				"getsockopt",
de7ddf
				"gettid",
de7ddf
				"gettimeofday",
de7ddf
				"getuid",
de7ddf
				"getuid32",
de7ddf
				"getxattr",
de7ddf
				"inotify_add_watch",
de7ddf
				"inotify_init",
de7ddf
				"inotify_init1",
de7ddf
				"inotify_rm_watch",
de7ddf
				"io_cancel",
de7ddf
				"io_destroy",
de7ddf
				"io_getevents",
de7ddf
				"io_setup",
de7ddf
				"io_submit",
de7ddf
				"ioctl",
de7ddf
				"ioprio_get",
de7ddf
				"ioprio_set",
de7ddf
				"ipc",
de7ddf
				"keyctl",
de7ddf
				"kill",
de7ddf
				"lchown",
de7ddf
				"lchown32",
de7ddf
				"lgetxattr",
de7ddf
				"link",
de7ddf
				"linkat",
de7ddf
				"listen",
de7ddf
				"listxattr",
de7ddf
				"llistxattr",
de7ddf
				"lremovexattr",
de7ddf
				"lseek",
de7ddf
				"lsetxattr",
de7ddf
				"lstat",
de7ddf
				"lstat64",
de7ddf
				"madvise",
de7ddf
				"mbind",
de7ddf
				"memfd_create",
de7ddf
				"mincore",
de7ddf
				"mkdir",
de7ddf
				"mkdirat",
de7ddf
				"mknod",
de7ddf
				"mknodat",
de7ddf
				"mlock",
de7ddf
				"mlock2",
de7ddf
				"mlockall",
de7ddf
				"mmap",
de7ddf
				"mmap2",
de7ddf
				"mount",
de7ddf
				"move_mount",
de7ddf
				"mprotect",
de7ddf
				"mq_getsetattr",
de7ddf
				"mq_notify",
de7ddf
				"mq_open",
de7ddf
				"mq_timedreceive",
de7ddf
				"mq_timedreceive_time64",
de7ddf
				"mq_timedsend",
de7ddf
				"mq_timedsend_time64",
de7ddf
				"mq_unlink",
de7ddf
				"mremap",
de7ddf
				"msgctl",
de7ddf
				"msgget",
de7ddf
				"msgrcv",
de7ddf
				"msgsnd",
de7ddf
				"msync",
de7ddf
				"munlock",
de7ddf
				"munlockall",
de7ddf
				"munmap",
de7ddf
				"name_to_handle_at",
de7ddf
				"nanosleep",
de7ddf
				"newfstatat",
de7ddf
				"open",
de7ddf
				"openat",
de7ddf
				"openat2",
de7ddf
				"open_tree",
de7ddf
				"pause",
de7ddf
				"pidfd_getfd",
de7ddf
				"pidfd_open",
de7ddf
				"pidfd_send_signal",
de7ddf
				"pipe",
de7ddf
				"pipe2",
de7ddf
				"pivot_root",
de7ddf
				"pkey_alloc",
de7ddf
				"pkey_free",
de7ddf
				"pkey_mprotect",
de7ddf
				"poll",
de7ddf
				"ppoll",
de7ddf
				"ppoll_time64",
de7ddf
				"prctl",
de7ddf
				"pread64",
de7ddf
				"preadv",
de7ddf
				"preadv2",
de7ddf
				"prlimit64",
de7ddf
				"pselect6",
de7ddf
				"pselect6_time64",
de7ddf
				"pwrite64",
de7ddf
				"pwritev",
de7ddf
				"pwritev2",
de7ddf
				"read",
de7ddf
				"readahead",
de7ddf
				"readdir",
de7ddf
				"readlink",
de7ddf
				"readlinkat",
de7ddf
				"readv",
de7ddf
				"reboot",
de7ddf
				"recv",
de7ddf
				"recvfrom",
de7ddf
				"recvmmsg",
de7ddf
				"recvmmsg_time64",
de7ddf
				"recvmsg",
de7ddf
				"remap_file_pages",
de7ddf
				"removexattr",
de7ddf
				"rename",
de7ddf
				"renameat",
de7ddf
				"renameat2",
de7ddf
				"restart_syscall",
de7ddf
				"rmdir",
de7ddf
				"rseq",
de7ddf
				"rt_sigaction",
de7ddf
				"rt_sigpending",
de7ddf
				"rt_sigprocmask",
de7ddf
				"rt_sigqueueinfo",
de7ddf
				"rt_sigreturn",
de7ddf
				"rt_sigsuspend",
de7ddf
				"rt_sigtimedwait",
de7ddf
				"rt_sigtimedwait_time64",
de7ddf
				"rt_tgsigqueueinfo",
de7ddf
				"sched_get_priority_max",
de7ddf
				"sched_get_priority_min",
de7ddf
				"sched_getaffinity",
de7ddf
				"sched_getattr",
de7ddf
				"sched_getparam",
de7ddf
				"sched_getscheduler",
de7ddf
				"sched_rr_get_interval",
de7ddf
				"sched_rr_get_interval_time64",
de7ddf
				"sched_setaffinity",
de7ddf
				"sched_setattr",
de7ddf
				"sched_setparam",
de7ddf
				"sched_setscheduler",
de7ddf
				"sched_yield",
de7ddf
				"seccomp",
de7ddf
				"select",
de7ddf
				"semctl",
de7ddf
				"semget",
de7ddf
				"semop",
de7ddf
				"semtimedop",
de7ddf
				"semtimedop_time64",
de7ddf
				"send",
de7ddf
				"sendfile",
de7ddf
				"sendfile64",
de7ddf
				"sendmmsg",
de7ddf
				"sendmsg",
de7ddf
				"sendto",
de7ddf
				"setns",
de7ddf
				"set_mempolicy",
de7ddf
				"set_robust_list",
de7ddf
				"set_thread_area",
de7ddf
				"set_tid_address",
de7ddf
				"setfsgid",
de7ddf
				"setfsgid32",
de7ddf
				"setfsuid",
de7ddf
				"setfsuid32",
de7ddf
				"setgid",
de7ddf
				"setgid32",
de7ddf
				"setgroups",
de7ddf
				"setgroups32",
de7ddf
				"setitimer",
de7ddf
				"setpgid",
de7ddf
				"setpriority",
de7ddf
				"setregid",
de7ddf
				"setregid32",
de7ddf
				"setresgid",
de7ddf
				"setresgid32",
de7ddf
				"setresuid",
de7ddf
				"setresuid32",
de7ddf
				"setreuid",
de7ddf
				"setreuid32",
de7ddf
				"setrlimit",
de7ddf
				"setsid",
de7ddf
				"setsockopt",
de7ddf
				"setuid",
de7ddf
				"setuid32",
de7ddf
				"setxattr",
de7ddf
				"shmat",
de7ddf
				"shmctl",
de7ddf
				"shmdt",
de7ddf
				"shmget",
de7ddf
				"shutdown",
de7ddf
				"sigaltstack",
de7ddf
				"signalfd",
de7ddf
				"signalfd4",
de7ddf
				"sigreturn",
de7ddf
				"socket",
de7ddf
				"socketcall",
de7ddf
				"socketpair",
de7ddf
				"splice",
de7ddf
				"stat",
de7ddf
				"stat64",
de7ddf
				"statfs",
de7ddf
				"statfs64",
de7ddf
				"statx",
de7ddf
				"symlink",
de7ddf
				"symlinkat",
de7ddf
				"sync",
de7ddf
				"sync_file_range",
de7ddf
				"syncfs",
de7ddf
				"sysinfo",
de7ddf
				"syslog",
de7ddf
				"tee",
de7ddf
				"tgkill",
de7ddf
				"time",
de7ddf
				"timer_create",
de7ddf
				"timer_delete",
de7ddf
				"timer_getoverrun",
de7ddf
				"timer_gettime",
de7ddf
				"timer_gettime64",
de7ddf
				"timer_settime",
de7ddf
				"timer_settime64",
de7ddf
				"timerfd_create",
de7ddf
				"timerfd_gettime",
de7ddf
				"timerfd_gettime64",
de7ddf
				"timerfd_settime",
de7ddf
				"timerfd_settime64",
de7ddf
				"times",
de7ddf
				"tkill",
de7ddf
				"truncate",
de7ddf
				"truncate64",
de7ddf
				"ugetrlimit",
de7ddf
				"umask",
de7ddf
				"umount",
de7ddf
				"umount2",
de7ddf
				"uname",
de7ddf
				"unlink",
de7ddf
				"unlinkat",
de7ddf
				"unshare",
de7ddf
				"utime",
de7ddf
				"utimensat",
de7ddf
				"utimensat_time64",
de7ddf
				"utimes",
de7ddf
				"vfork",
de7ddf
				"wait4",
de7ddf
				"waitid",
de7ddf
				"waitpid",
de7ddf
				"write",
de7ddf
				"writev"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ALLOW",
de7ddf
			"args": [],
de7ddf
			"comment": "",
de7ddf
			"includes": {},
de7ddf
			"excludes": {}
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"personality"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ALLOW",
de7ddf
			"args": [
de7ddf
				{
de7ddf
					"index": 0,
de7ddf
					"value": 0,
de7ddf
					"valueTwo": 0,
de7ddf
					"op": "SCMP_CMP_EQ"
de7ddf
				}
de7ddf
			],
de7ddf
			"comment": "",
de7ddf
			"includes": {},
de7ddf
			"excludes": {}
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"personality"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ALLOW",
de7ddf
			"args": [
de7ddf
				{
de7ddf
					"index": 0,
de7ddf
					"value": 8,
de7ddf
					"valueTwo": 0,
de7ddf
					"op": "SCMP_CMP_EQ"
de7ddf
				}
de7ddf
			],
de7ddf
			"comment": "",
de7ddf
			"includes": {},
de7ddf
			"excludes": {}
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"personality"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ALLOW",
de7ddf
			"args": [
de7ddf
				{
de7ddf
					"index": 0,
de7ddf
					"value": 131072,
de7ddf
					"valueTwo": 0,
de7ddf
					"op": "SCMP_CMP_EQ"
de7ddf
				}
de7ddf
			],
de7ddf
			"comment": "",
de7ddf
			"includes": {},
de7ddf
			"excludes": {}
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"personality"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ALLOW",
de7ddf
			"args": [
de7ddf
				{
de7ddf
					"index": 0,
de7ddf
					"value": 131080,
de7ddf
					"valueTwo": 0,
de7ddf
					"op": "SCMP_CMP_EQ"
de7ddf
				}
de7ddf
			],
de7ddf
			"comment": "",
de7ddf
			"includes": {},
de7ddf
			"excludes": {}
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"personality"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ALLOW",
de7ddf
			"args": [
de7ddf
				{
de7ddf
					"index": 0,
de7ddf
					"value": 4294967295,
de7ddf
					"valueTwo": 0,
de7ddf
					"op": "SCMP_CMP_EQ"
de7ddf
				}
de7ddf
			],
de7ddf
			"comment": "",
de7ddf
			"includes": {},
de7ddf
			"excludes": {}
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"sync_file_range2"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ALLOW",
de7ddf
			"args": [],
de7ddf
			"comment": "",
de7ddf
			"includes": {
de7ddf
				"arches": [
de7ddf
					"ppc64le"
de7ddf
				]
de7ddf
			},
de7ddf
			"excludes": {}
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"arm_fadvise64_64",
de7ddf
				"arm_sync_file_range",
de7ddf
				"sync_file_range2",
de7ddf
				"breakpoint",
de7ddf
				"cacheflush",
de7ddf
				"set_tls"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ALLOW",
de7ddf
			"args": [],
de7ddf
			"comment": "",
de7ddf
			"includes": {
de7ddf
				"arches": [
de7ddf
					"arm",
de7ddf
					"arm64"
de7ddf
				]
de7ddf
			},
de7ddf
			"excludes": {}
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"arch_prctl"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ALLOW",
de7ddf
			"args": [],
de7ddf
			"comment": "",
de7ddf
			"includes": {
de7ddf
				"arches": [
de7ddf
					"amd64",
de7ddf
					"x32"
de7ddf
				]
de7ddf
			},
de7ddf
			"excludes": {}
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"modify_ldt"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ALLOW",
de7ddf
			"args": [],
de7ddf
			"comment": "",
de7ddf
			"includes": {
de7ddf
				"arches": [
de7ddf
					"amd64",
de7ddf
					"x32",
de7ddf
					"x86"
de7ddf
				]
de7ddf
			},
de7ddf
			"excludes": {}
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"s390_pci_mmio_read",
de7ddf
				"s390_pci_mmio_write",
de7ddf
				"s390_runtime_instr"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ALLOW",
de7ddf
			"args": [],
de7ddf
			"comment": "",
de7ddf
			"includes": {
de7ddf
				"arches": [
de7ddf
					"s390",
de7ddf
					"s390x"
de7ddf
				]
de7ddf
			},
de7ddf
			"excludes": {}
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"open_by_handle_at"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ALLOW",
de7ddf
			"args": [],
de7ddf
			"comment": "",
de7ddf
			"includes": {
de7ddf
				"caps": [
de7ddf
					"CAP_DAC_READ_SEARCH"
de7ddf
				]
de7ddf
			},
de7ddf
			"excludes": {}
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"open_by_handle_at"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ERRNO",
de7ddf
			"args": [],
de7ddf
			"comment": "",
de7ddf
			"includes": {},
de7ddf
			"excludes": {
de7ddf
				"caps": [
de7ddf
					"CAP_DAC_READ_SEARCH"
de7ddf
				]
de7ddf
			},
de7ddf
			"errnoRet": 1
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"bpf",
de7ddf
				"fanotify_init",
de7ddf
				"lookup_dcookie",
de7ddf
				"perf_event_open",
de7ddf
				"quotactl",
de7ddf
				"setdomainname",
de7ddf
				"sethostname",
de7ddf
				"setns"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ALLOW",
de7ddf
			"args": [],
de7ddf
			"comment": "",
de7ddf
			"includes": {
de7ddf
				"caps": [
de7ddf
					"CAP_SYS_ADMIN"
de7ddf
				]
de7ddf
			},
de7ddf
			"excludes": {}
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"bpf",
de7ddf
				"fanotify_init",
de7ddf
				"lookup_dcookie",
de7ddf
				"perf_event_open",
de7ddf
				"quotactl",
de7ddf
				"setdomainname",
de7ddf
				"sethostname",
de7ddf
				"setns"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ERRNO",
de7ddf
			"args": [],
de7ddf
			"comment": "",
de7ddf
			"includes": {},
de7ddf
			"excludes": {
de7ddf
				"caps": [
de7ddf
					"CAP_SYS_ADMIN"
de7ddf
				]
de7ddf
			},
de7ddf
			"errnoRet": 1
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"chroot"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ALLOW",
de7ddf
			"args": [],
de7ddf
			"comment": "",
de7ddf
			"includes": {
de7ddf
				"caps": [
de7ddf
					"CAP_SYS_CHROOT"
de7ddf
				]
de7ddf
			},
de7ddf
			"excludes": {}
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"chroot"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ERRNO",
de7ddf
			"args": [],
de7ddf
			"comment": "",
de7ddf
			"includes": {},
de7ddf
			"excludes": {
de7ddf
				"caps": [
de7ddf
					"CAP_SYS_CHROOT"
de7ddf
				]
de7ddf
			},
de7ddf
			"errnoRet": 1
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"delete_module",
de7ddf
				"init_module",
de7ddf
				"finit_module",
de7ddf
				"query_module"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ALLOW",
de7ddf
			"args": [],
de7ddf
			"comment": "",
de7ddf
			"includes": {
de7ddf
				"caps": [
de7ddf
					"CAP_SYS_MODULE"
de7ddf
				]
de7ddf
			},
de7ddf
			"excludes": {}
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"delete_module",
de7ddf
				"init_module",
de7ddf
				"finit_module",
de7ddf
				"query_module"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ERRNO",
de7ddf
			"args": [],
de7ddf
			"comment": "",
de7ddf
			"includes": {},
de7ddf
			"excludes": {
de7ddf
				"caps": [
de7ddf
					"CAP_SYS_MODULE"
de7ddf
				]
de7ddf
			},
de7ddf
			"errnoRet": 1
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"acct"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ALLOW",
de7ddf
			"args": [],
de7ddf
			"comment": "",
de7ddf
			"includes": {
de7ddf
				"caps": [
de7ddf
					"CAP_SYS_PACCT"
de7ddf
				]
de7ddf
			},
de7ddf
			"excludes": {}
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"acct"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ERRNO",
de7ddf
			"args": [],
de7ddf
			"comment": "",
de7ddf
			"includes": {},
de7ddf
			"excludes": {
de7ddf
				"caps": [
de7ddf
					"CAP_SYS_PACCT"
de7ddf
				]
de7ddf
			},
de7ddf
			"errnoRet": 1
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"kcmp",
de7ddf
				"process_madvise",
de7ddf
				"process_vm_readv",
de7ddf
				"process_vm_writev",
de7ddf
				"ptrace"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ALLOW",
de7ddf
			"args": [],
de7ddf
			"comment": "",
de7ddf
			"includes": {
de7ddf
				"caps": [
de7ddf
					"CAP_SYS_PTRACE"
de7ddf
				]
de7ddf
			},
de7ddf
			"excludes": {}
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"kcmp",
de7ddf
				"process_madvise",
de7ddf
				"process_vm_readv",
de7ddf
				"process_vm_writev",
de7ddf
				"ptrace"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ERRNO",
de7ddf
			"args": [],
de7ddf
			"comment": "",
de7ddf
			"includes": {},
de7ddf
			"excludes": {
de7ddf
				"caps": [
de7ddf
					"CAP_SYS_PTRACE"
de7ddf
				]
de7ddf
			},
de7ddf
			"errnoRet": 1
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"iopl",
de7ddf
				"ioperm"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ALLOW",
de7ddf
			"args": [],
de7ddf
			"comment": "",
de7ddf
			"includes": {
de7ddf
				"caps": [
de7ddf
					"CAP_SYS_RAWIO"
de7ddf
				]
de7ddf
			},
de7ddf
			"excludes": {}
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"iopl",
de7ddf
				"ioperm"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ERRNO",
de7ddf
			"args": [],
de7ddf
			"comment": "",
de7ddf
			"includes": {},
de7ddf
			"excludes": {
de7ddf
				"caps": [
de7ddf
					"CAP_SYS_RAWIO"
de7ddf
				]
de7ddf
			},
de7ddf
			"errnoRet": 1
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"settimeofday",
de7ddf
				"stime",
de7ddf
				"clock_settime",
de7ddf
				"clock_settime64"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ALLOW",
de7ddf
			"args": [],
de7ddf
			"comment": "",
de7ddf
			"includes": {
de7ddf
				"caps": [
de7ddf
					"CAP_SYS_TIME"
de7ddf
				]
de7ddf
			},
de7ddf
			"excludes": {}
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"settimeofday",
de7ddf
				"stime",
de7ddf
				"clock_settime",
de7ddf
				"clock_settime64"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ERRNO",
de7ddf
			"args": [],
de7ddf
			"comment": "",
de7ddf
			"includes": {},
de7ddf
			"excludes": {
de7ddf
				"caps": [
de7ddf
					"CAP_SYS_TIME"
de7ddf
				]
de7ddf
			},
de7ddf
			"errnoRet": 1
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"vhangup"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ALLOW",
de7ddf
			"args": [],
de7ddf
			"comment": "",
de7ddf
			"includes": {
de7ddf
				"caps": [
de7ddf
					"CAP_SYS_TTY_CONFIG"
de7ddf
				]
de7ddf
			},
de7ddf
			"excludes": {}
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"vhangup"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ERRNO",
de7ddf
			"args": [],
de7ddf
			"comment": "",
de7ddf
			"includes": {},
de7ddf
			"excludes": {
de7ddf
				"caps": [
de7ddf
					"CAP_SYS_TTY_CONFIG"
de7ddf
				]
de7ddf
			},
de7ddf
			"errnoRet": 1
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"socket"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ERRNO",
de7ddf
			"args": [
de7ddf
				{
de7ddf
					"index": 0,
de7ddf
					"value": 16,
de7ddf
					"valueTwo": 0,
de7ddf
					"op": "SCMP_CMP_EQ"
de7ddf
				},
de7ddf
				{
de7ddf
					"index": 2,
de7ddf
					"value": 9,
de7ddf
					"valueTwo": 0,
de7ddf
					"op": "SCMP_CMP_EQ"
de7ddf
				}
de7ddf
			],
de7ddf
			"comment": "",
de7ddf
			"includes": {},
de7ddf
			"excludes": {
de7ddf
				"caps": [
de7ddf
					"CAP_AUDIT_WRITE"
de7ddf
				]
de7ddf
			},
de7ddf
			"errnoRet": 22
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"socket"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ALLOW",
de7ddf
			"args": [
de7ddf
				{
de7ddf
					"index": 2,
de7ddf
					"value": 9,
de7ddf
					"valueTwo": 0,
de7ddf
					"op": "SCMP_CMP_NE"
de7ddf
				}
de7ddf
			],
de7ddf
			"comment": "",
de7ddf
			"includes": {},
de7ddf
			"excludes": {
de7ddf
				"caps": [
de7ddf
					"CAP_AUDIT_WRITE"
de7ddf
				]
de7ddf
			}
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"socket"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ALLOW",
de7ddf
			"args": [
de7ddf
				{
de7ddf
					"index": 0,
de7ddf
					"value": 16,
de7ddf
					"valueTwo": 0,
de7ddf
					"op": "SCMP_CMP_NE"
de7ddf
				}
de7ddf
			],
de7ddf
			"comment": "",
de7ddf
			"includes": {},
de7ddf
			"excludes": {
de7ddf
				"caps": [
de7ddf
					"CAP_AUDIT_WRITE"
de7ddf
				]
de7ddf
			}
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"socket"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ALLOW",
de7ddf
			"args": [
de7ddf
				{
de7ddf
					"index": 2,
de7ddf
					"value": 9,
de7ddf
					"valueTwo": 0,
de7ddf
					"op": "SCMP_CMP_NE"
de7ddf
				}
de7ddf
			],
de7ddf
			"comment": "",
de7ddf
			"includes": {},
de7ddf
			"excludes": {
de7ddf
				"caps": [
de7ddf
					"CAP_AUDIT_WRITE"
de7ddf
				]
de7ddf
			}
de7ddf
		},
de7ddf
		{
de7ddf
			"names": [
de7ddf
				"socket"
de7ddf
			],
de7ddf
			"action": "SCMP_ACT_ALLOW",
de7ddf
			"args": null,
de7ddf
			"comment": "",
de7ddf
			"includes": {
de7ddf
				"caps": [
de7ddf
					"CAP_AUDIT_WRITE"
de7ddf
				]
de7ddf
			},
de7ddf
			"excludes": {}
de7ddf
		}
de7ddf
	]
de7ddf
}