599352
{
599352
	"defaultAction": "SCMP_ACT_ERRNO",
599352
	"archMap": [
599352
		{
599352
			"architecture": "SCMP_ARCH_X86_64",
599352
			"subArchitectures": [
599352
				"SCMP_ARCH_X86",
599352
				"SCMP_ARCH_X32"
599352
			]
599352
		},
599352
		{
599352
			"architecture": "SCMP_ARCH_AARCH64",
599352
			"subArchitectures": [
599352
				"SCMP_ARCH_ARM"
599352
			]
599352
		},
599352
		{
599352
			"architecture": "SCMP_ARCH_MIPS64",
599352
			"subArchitectures": [
599352
				"SCMP_ARCH_MIPS",
599352
				"SCMP_ARCH_MIPS64N32"
599352
			]
599352
		},
599352
		{
599352
			"architecture": "SCMP_ARCH_MIPS64N32",
599352
			"subArchitectures": [
599352
				"SCMP_ARCH_MIPS",
599352
				"SCMP_ARCH_MIPS64"
599352
			]
599352
		},
599352
		{
599352
			"architecture": "SCMP_ARCH_MIPSEL64",
599352
			"subArchitectures": [
599352
				"SCMP_ARCH_MIPSEL",
599352
				"SCMP_ARCH_MIPSEL64N32"
599352
			]
599352
		},
599352
		{
599352
			"architecture": "SCMP_ARCH_MIPSEL64N32",
599352
			"subArchitectures": [
599352
				"SCMP_ARCH_MIPSEL",
599352
				"SCMP_ARCH_MIPSEL64"
599352
			]
599352
		},
599352
		{
599352
			"architecture": "SCMP_ARCH_S390X",
599352
			"subArchitectures": [
599352
				"SCMP_ARCH_S390"
599352
			]
599352
		}
599352
	],
599352
	"syscalls": [
599352
		{
599352
			"names": [
599352
				"accept",
599352
				"accept4",
599352
				"access",
599352
				"adjtimex",
599352
				"alarm",
599352
				"bind",
599352
				"brk",
599352
				"capget",
599352
				"capset",
599352
				"chdir",
599352
				"chmod",
599352
				"chown",
599352
				"chown32",
599352
				"clock_getres",
599352
				"clock_gettime",
599352
				"clock_nanosleep",
599352
				"close",
599352
				"connect",
599352
				"copy_file_range",
599352
				"creat",
599352
				"dup",
599352
				"dup2",
599352
				"dup3",
599352
				"epoll_create",
599352
				"epoll_create1",
599352
				"epoll_ctl",
599352
				"epoll_ctl_old",
599352
				"epoll_pwait",
599352
				"epoll_wait",
599352
				"epoll_wait_old",
599352
				"eventfd",
599352
				"eventfd2",
599352
				"execve",
599352
				"execveat",
599352
				"exit",
599352
				"exit_group",
599352
				"faccessat",
599352
				"fadvise64",
599352
				"fadvise64_64",
599352
				"fallocate",
599352
				"fanotify_mark",
599352
				"fchdir",
599352
				"fchmod",
599352
				"fchmodat",
599352
				"fchown",
599352
				"fchown32",
599352
				"fchownat",
599352
				"fcntl",
599352
				"fcntl64",
599352
				"fdatasync",
599352
				"fgetxattr",
599352
				"flistxattr",
599352
				"flock",
599352
				"fork",
599352
				"fremovexattr",
599352
				"fsetxattr",
599352
				"fstat",
599352
				"fstat64",
599352
				"fstatat64",
599352
				"fstatfs",
599352
				"fstatfs64",
599352
				"fsync",
599352
				"ftruncate",
599352
				"ftruncate64",
599352
				"futex",
599352
				"futimesat",
599352
				"getcpu",
599352
				"getcwd",
599352
				"getdents",
599352
				"getdents64",
599352
				"getegid",
599352
				"getegid32",
599352
				"geteuid",
599352
				"geteuid32",
599352
				"getgid",
599352
				"getgid32",
599352
				"getgroups",
599352
				"getgroups32",
599352
				"getitimer",
599352
				"getpeername",
599352
				"getpgid",
599352
				"getpgrp",
599352
				"getpid",
599352
				"getppid",
599352
				"getpriority",
599352
				"getrandom",
599352
				"getresgid",
599352
				"getresgid32",
599352
				"getresuid",
599352
				"getresuid32",
599352
				"getrlimit",
599352
				"get_robust_list",
599352
				"getrusage",
599352
				"getsid",
599352
				"getsockname",
599352
				"getsockopt",
599352
				"get_thread_area",
599352
				"gettid",
599352
				"gettimeofday",
599352
				"getuid",
599352
				"getuid32",
599352
				"getxattr",
599352
				"inotify_add_watch",
599352
				"inotify_init",
599352
				"inotify_init1",
599352
				"inotify_rm_watch",
599352
				"io_cancel",
599352
				"ioctl",
599352
				"io_destroy",
599352
				"io_getevents",
599352
				"ioprio_get",
599352
				"ioprio_set",
599352
				"io_setup",
599352
				"io_submit",
599352
				"ipc",
599352
				"kill",
599352
				"lchown",
599352
				"lchown32",
599352
				"lgetxattr",
599352
				"link",
599352
				"linkat",
599352
				"listen",
599352
				"listxattr",
599352
				"llistxattr",
599352
				"_llseek",
599352
				"lremovexattr",
599352
				"lseek",
599352
				"lsetxattr",
599352
				"lstat",
599352
				"lstat64",
599352
				"madvise",
599352
				"memfd_create",
599352
				"mincore",
599352
				"mkdir",
599352
				"mkdirat",
599352
				"mknod",
599352
				"mknodat",
599352
				"mlock",
599352
				"mlock2",
599352
				"mlockall",
599352
				"mmap",
599352
				"mmap2",
599352
				"mprotect",
599352
				"mq_getsetattr",
599352
				"mq_notify",
599352
				"mq_open",
599352
				"mq_timedreceive",
599352
				"mq_timedsend",
599352
				"mq_unlink",
599352
				"mremap",
599352
				"msgctl",
599352
				"msgget",
599352
				"msgrcv",
599352
				"msgsnd",
599352
				"msync",
599352
				"munlock",
599352
				"munlockall",
599352
				"munmap",
599352
				"nanosleep",
599352
				"newfstatat",
599352
				"_newselect",
599352
				"open",
599352
				"openat",
599352
				"pause",
599352
				"pipe",
599352
				"pipe2",
599352
				"poll",
599352
				"ppoll",
599352
				"prctl",
599352
				"pread64",
599352
				"preadv",
599352
				"preadv2",
599352
				"prlimit64",
599352
				"pselect6",
599352
				"pwrite64",
599352
				"pwritev",
599352
				"pwritev2",
599352
				"read",
599352
				"readahead",
599352
				"readlink",
599352
				"readlinkat",
599352
				"readv",
599352
				"recv",
599352
				"recvfrom",
599352
				"recvmmsg",
599352
				"recvmsg",
599352
				"remap_file_pages",
599352
				"removexattr",
599352
				"rename",
599352
				"renameat",
599352
				"renameat2",
599352
				"restart_syscall",
599352
				"rmdir",
599352
				"rt_sigaction",
599352
				"rt_sigpending",
599352
				"rt_sigprocmask",
599352
				"rt_sigqueueinfo",
599352
				"rt_sigreturn",
599352
				"rt_sigsuspend",
599352
				"rt_sigtimedwait",
599352
				"rt_tgsigqueueinfo",
599352
				"sched_getaffinity",
599352
				"sched_getattr",
599352
				"sched_getparam",
599352
				"sched_get_priority_max",
599352
				"sched_get_priority_min",
599352
				"sched_getscheduler",
599352
				"sched_rr_get_interval",
599352
				"sched_setaffinity",
599352
				"sched_setattr",
599352
				"sched_setparam",
599352
				"sched_setscheduler",
599352
				"sched_yield",
599352
				"seccomp",
599352
				"select",
599352
				"semctl",
599352
				"semget",
599352
				"semop",
599352
				"semtimedop",
599352
				"send",
599352
				"sendfile",
599352
				"sendfile64",
599352
				"sendmmsg",
599352
				"sendmsg",
599352
				"sendto",
599352
				"setfsgid",
599352
				"setfsgid32",
599352
				"setfsuid",
599352
				"setfsuid32",
599352
				"setgid",
599352
				"setgid32",
599352
				"setgroups",
599352
				"setgroups32",
599352
				"setitimer",
599352
				"setpgid",
599352
				"setpriority",
599352
				"setregid",
599352
				"setregid32",
599352
				"setresgid",
599352
				"setresgid32",
599352
				"setresuid",
599352
				"setresuid32",
599352
				"setreuid",
599352
				"setreuid32",
599352
				"setrlimit",
599352
				"set_robust_list",
599352
				"setsid",
599352
				"setsockopt",
599352
				"set_thread_area",
599352
				"set_tid_address",
599352
				"setuid",
599352
				"setuid32",
599352
				"setxattr",
599352
				"shmat",
599352
				"shmctl",
599352
				"shmdt",
599352
				"shmget",
599352
				"shutdown",
599352
				"sigaltstack",
599352
				"signalfd",
599352
				"signalfd4",
599352
				"sigreturn",
599352
				"socket",
599352
				"socketcall",
599352
				"socketpair",
599352
				"splice",
599352
				"stat",
599352
				"stat64",
599352
				"statfs",
599352
				"statfs64",
599352
				"statx",
599352
				"symlink",
599352
				"symlinkat",
599352
				"sync",
599352
				"sync_file_range",
599352
				"syncfs",
599352
				"sysinfo",
599352
				"syslog",
599352
				"tee",
599352
				"tgkill",
599352
				"time",
599352
				"timer_create",
599352
				"timer_delete",
599352
				"timerfd_create",
599352
				"timerfd_gettime",
599352
				"timerfd_settime",
599352
				"timer_getoverrun",
599352
				"timer_gettime",
599352
				"timer_settime",
599352
				"times",
599352
				"tkill",
599352
				"truncate",
599352
				"truncate64",
599352
				"ugetrlimit",
599352
				"umask",
599352
				"uname",
599352
				"unlink",
599352
				"unlinkat",
599352
				"utime",
599352
				"utimensat",
599352
				"utimes",
599352
				"vfork",
599352
				"vmsplice",
599352
				"wait4",
599352
				"waitid",
599352
				"waitpid",
599352
				"write",
599352
				"writev",
599352
				"mount",
599352
				"umount2",
599352
				"reboot",
599352
				"name_to_handle_at",
599352
				"unshare"
599352
			],
599352
			"action": "SCMP_ACT_ALLOW",
599352
			"args": [],
599352
			"comment": "",
599352
			"includes": {},
599352
			"excludes": {}
599352
		},
599352
		{
599352
			"names": [
599352
				"personality"
599352
			],
599352
			"action": "SCMP_ACT_ALLOW",
599352
			"args": [
599352
				{
599352
					"index": 0,
599352
					"value": 0,
599352
					"valueTwo": 0,
599352
					"op": "SCMP_CMP_EQ"
599352
				}
599352
			],
599352
			"comment": "",
599352
			"includes": {},
599352
			"excludes": {}
599352
		},
599352
		{
599352
			"names": [
599352
				"personality"
599352
			],
599352
			"action": "SCMP_ACT_ALLOW",
599352
			"args": [
599352
				{
599352
					"index": 0,
599352
					"value": 8,
599352
					"valueTwo": 0,
599352
					"op": "SCMP_CMP_EQ"
599352
				}
599352
			],
599352
			"comment": "",
599352
			"includes": {},
599352
			"excludes": {}
599352
		},
599352
		{
599352
			"names": [
599352
				"personality"
599352
			],
599352
			"action": "SCMP_ACT_ALLOW",
599352
			"args": [
599352
				{
599352
					"index": 0,
599352
					"value": 131072,
599352
					"valueTwo": 0,
599352
					"op": "SCMP_CMP_EQ"
599352
				}
599352
			],
599352
			"comment": "",
599352
			"includes": {},
599352
			"excludes": {}
599352
		},
599352
		{
599352
			"names": [
599352
				"personality"
599352
			],
599352
			"action": "SCMP_ACT_ALLOW",
599352
			"args": [
599352
				{
599352
					"index": 0,
599352
					"value": 131080,
599352
					"valueTwo": 0,
599352
					"op": "SCMP_CMP_EQ"
599352
				}
599352
			],
599352
			"comment": "",
599352
			"includes": {},
599352
			"excludes": {}
599352
		},
599352
		{
599352
			"names": [
599352
				"personality"
599352
			],
599352
			"action": "SCMP_ACT_ALLOW",
599352
			"args": [
599352
				{
599352
					"index": 0,
599352
					"value": 4294967295,
599352
					"valueTwo": 0,
599352
					"op": "SCMP_CMP_EQ"
599352
				}
599352
			],
599352
			"comment": "",
599352
			"includes": {},
599352
			"excludes": {}
599352
		},
599352
		{
599352
			"names": [
599352
				"sync_file_range2"
599352
			],
599352
			"action": "SCMP_ACT_ALLOW",
599352
			"args": [],
599352
			"comment": "",
599352
			"includes": {
599352
				"arches": [
599352
					"ppc64le"
599352
				]
599352
			},
599352
			"excludes": {}
599352
		},
599352
		{
599352
			"names": [
599352
				"arm_fadvise64_64",
599352
				"arm_sync_file_range",
599352
				"sync_file_range2",
599352
				"breakpoint",
599352
				"cacheflush",
599352
				"set_tls"
599352
			],
599352
			"action": "SCMP_ACT_ALLOW",
599352
			"args": [],
599352
			"comment": "",
599352
			"includes": {
599352
				"arches": [
599352
					"arm",
599352
					"arm64"
599352
				]
599352
			},
599352
			"excludes": {}
599352
		},
599352
		{
599352
			"names": [
599352
				"arch_prctl"
599352
			],
599352
			"action": "SCMP_ACT_ALLOW",
599352
			"args": [],
599352
			"comment": "",
599352
			"includes": {
599352
				"arches": [
599352
					"amd64",
599352
					"x32"
599352
				]
599352
			},
599352
			"excludes": {}
599352
		},
599352
		{
599352
			"names": [
599352
				"modify_ldt"
599352
			],
599352
			"action": "SCMP_ACT_ALLOW",
599352
			"args": [],
599352
			"comment": "",
599352
			"includes": {
599352
				"arches": [
599352
					"amd64",
599352
					"x32",
599352
					"x86"
599352
				]
599352
			},
599352
			"excludes": {}
599352
		},
599352
		{
599352
			"names": [
599352
				"s390_pci_mmio_read",
599352
				"s390_pci_mmio_write",
599352
				"s390_runtime_instr"
599352
			],
599352
			"action": "SCMP_ACT_ALLOW",
599352
			"args": [],
599352
			"comment": "",
599352
			"includes": {
599352
				"arches": [
599352
					"s390",
599352
					"s390x"
599352
				]
599352
			},
599352
			"excludes": {}
599352
		},
599352
		{
599352
			"names": [
599352
				"open_by_handle_at"
599352
			],
599352
			"action": "SCMP_ACT_ALLOW",
599352
			"args": [],
599352
			"comment": "",
599352
			"includes": {
599352
				"caps": [
599352
					"CAP_DAC_READ_SEARCH"
599352
				]
599352
			},
599352
			"excludes": {}
599352
		},
599352
		{
599352
			"names": [
599352
				"bpf",
599352
				"clone",
599352
				"fanotify_init",
599352
				"lookup_dcookie",
599352
				"mount",
599352
				"name_to_handle_at",
599352
				"perf_event_open",
599352
				"quotactl",
599352
				"setdomainname",
599352
				"sethostname",
599352
				"setns",
599352
				"umount",
599352
				"umount2",
599352
				"unshare"
599352
			],
599352
			"action": "SCMP_ACT_ALLOW",
599352
			"args": [],
599352
			"comment": "",
599352
			"includes": {
599352
				"caps": [
599352
					"CAP_SYS_ADMIN"
599352
				]
599352
			},
599352
			"excludes": {}
599352
		},
599352
		{
599352
			"names": [
599352
				"clone"
599352
			],
599352
			"action": "SCMP_ACT_ALLOW",
599352
			"args": [
599352
				{
599352
					"index": 0,
599352
					"value": 2080505856,
599352
					"valueTwo": 0,
599352
					"op": "SCMP_CMP_MASKED_EQ"
599352
				}
599352
			],
599352
			"comment": "",
599352
			"includes": {},
599352
			"excludes": {
599352
				"caps": [
599352
					"CAP_SYS_ADMIN"
599352
				],
599352
				"arches": [
599352
					"s390",
599352
					"s390x"
599352
				]
599352
			}
599352
		},
599352
		{
599352
			"names": [
599352
				"clone"
599352
			],
599352
			"action": "SCMP_ACT_ALLOW",
599352
			"args": [
599352
				{
599352
					"index": 1,
599352
					"value": 2080505856,
599352
					"valueTwo": 0,
599352
					"op": "SCMP_CMP_MASKED_EQ"
599352
				}
599352
			],
599352
			"comment": "s390 parameter ordering for clone is different",
599352
			"includes": {
599352
				"arches": [
599352
					"s390",
599352
					"s390x"
599352
				]
599352
			},
599352
			"excludes": {
599352
				"caps": [
599352
					"CAP_SYS_ADMIN"
599352
				]
599352
			}
599352
		},
599352
		{
599352
			"names": [
599352
				"reboot"
599352
			],
599352
			"action": "SCMP_ACT_ALLOW",
599352
			"args": [],
599352
			"comment": "",
599352
			"includes": {
599352
				"caps": [
599352
					"CAP_SYS_BOOT"
599352
				]
599352
			},
599352
			"excludes": {}
599352
		},
599352
		{
599352
			"names": [
599352
				"chroot"
599352
			],
599352
			"action": "SCMP_ACT_ALLOW",
599352
			"args": [],
599352
			"comment": "",
599352
			"includes": {
599352
				"caps": [
599352
					"CAP_SYS_CHROOT"
599352
				]
599352
			},
599352
			"excludes": {}
599352
		},
599352
		{
599352
			"names": [
599352
				"delete_module",
599352
				"init_module",
599352
				"finit_module",
599352
				"query_module"
599352
			],
599352
			"action": "SCMP_ACT_ALLOW",
599352
			"args": [],
599352
			"comment": "",
599352
			"includes": {
599352
				"caps": [
599352
					"CAP_SYS_MODULE"
599352
				]
599352
			},
599352
			"excludes": {}
599352
		},
599352
		{
599352
			"names": [
599352
				"get_mempolicy",
599352
				"mbind",
599352
				"name_to_handle_at",
599352
				"set_mempolicy"
599352
			],
599352
			"action": "SCMP_ACT_ALLOW",
599352
			"args": [],
599352
			"comment": "",
599352
			"includes": {
599352
				"caps": [
599352
					"CAP_SYS_NICE"
599352
				]
599352
			},
599352
			"excludes": {}
599352
		},
599352
		{
599352
			"names": [
599352
				"acct"
599352
			],
599352
			"action": "SCMP_ACT_ALLOW",
599352
			"args": [],
599352
			"comment": "",
599352
			"includes": {
599352
				"caps": [
599352
					"CAP_SYS_PACCT"
599352
				]
599352
			},
599352
			"excludes": {}
599352
		},
599352
		{
599352
			"names": [
599352
				"kcmp",
599352
				"process_vm_readv",
599352
				"process_vm_writev",
599352
				"ptrace"
599352
			],
599352
			"action": "SCMP_ACT_ALLOW",
599352
			"args": [],
599352
			"comment": "",
599352
			"includes": {
599352
				"caps": [
599352
					"CAP_SYS_PTRACE"
599352
				]
599352
			},
599352
			"excludes": {}
599352
		},
599352
		{
599352
			"names": [
599352
				"iopl",
599352
				"ioperm"
599352
			],
599352
			"action": "SCMP_ACT_ALLOW",
599352
			"args": [],
599352
			"comment": "",
599352
			"includes": {
599352
				"caps": [
599352
					"CAP_SYS_RAWIO"
599352
				]
599352
			},
599352
			"excludes": {}
599352
		},
599352
		{
599352
			"names": [
599352
				"settimeofday",
599352
				"stime",
599352
				"clock_settime"
599352
			],
599352
			"action": "SCMP_ACT_ALLOW",
599352
			"args": [],
599352
			"comment": "",
599352
			"includes": {
599352
				"caps": [
599352
					"CAP_SYS_TIME"
599352
				]
599352
			},
599352
			"excludes": {}
599352
		},
599352
		{
599352
			"names": [
599352
				"vhangup"
599352
			],
599352
			"action": "SCMP_ACT_ALLOW",
599352
			"args": [],
599352
			"comment": "",
599352
			"includes": {
599352
				"caps": [
599352
					"CAP_SYS_TTY_CONFIG"
599352
				]
599352
			},
599352
			"excludes": {}
599352
		}
599352
	]
599352
}