864398
{
864398
	"defaultAction": "SCMP_ACT_ERRNO",
864398
	"archMap": [
864398
		{
864398
			"architecture": "SCMP_ARCH_X86_64",
864398
			"subArchitectures": [
864398
				"SCMP_ARCH_X86",
864398
				"SCMP_ARCH_X32"
864398
			]
864398
		},
864398
		{
864398
			"architecture": "SCMP_ARCH_AARCH64",
864398
			"subArchitectures": [
864398
				"SCMP_ARCH_ARM"
864398
			]
864398
		},
864398
		{
864398
			"architecture": "SCMP_ARCH_MIPS64",
864398
			"subArchitectures": [
864398
				"SCMP_ARCH_MIPS",
864398
				"SCMP_ARCH_MIPS64N32"
864398
			]
864398
		},
864398
		{
864398
			"architecture": "SCMP_ARCH_MIPS64N32",
864398
			"subArchitectures": [
864398
				"SCMP_ARCH_MIPS",
864398
				"SCMP_ARCH_MIPS64"
864398
			]
864398
		},
864398
		{
864398
			"architecture": "SCMP_ARCH_MIPSEL64",
864398
			"subArchitectures": [
864398
				"SCMP_ARCH_MIPSEL",
864398
				"SCMP_ARCH_MIPSEL64N32"
864398
			]
864398
		},
864398
		{
864398
			"architecture": "SCMP_ARCH_MIPSEL64N32",
864398
			"subArchitectures": [
864398
				"SCMP_ARCH_MIPSEL",
864398
				"SCMP_ARCH_MIPSEL64"
864398
			]
864398
		},
864398
		{
864398
			"architecture": "SCMP_ARCH_S390X",
864398
			"subArchitectures": [
864398
				"SCMP_ARCH_S390"
864398
			]
864398
		}
864398
	],
864398
	"syscalls": [
864398
		{
864398
			"names": [
864398
				"accept",
864398
				"accept4",
864398
				"access",
864398
				"adjtimex",
864398
				"alarm",
864398
				"bind",
864398
				"brk",
864398
				"capget",
864398
				"capset",
864398
				"chdir",
864398
				"chmod",
864398
				"chown",
864398
				"chown32",
864398
				"clock_getres",
864398
				"clock_gettime",
864398
				"clock_nanosleep",
864398
				"close",
864398
				"connect",
864398
				"copy_file_range",
864398
				"creat",
864398
				"dup",
864398
				"dup2",
864398
				"dup3",
864398
				"epoll_create",
864398
				"epoll_create1",
864398
				"epoll_ctl",
864398
				"epoll_ctl_old",
864398
				"epoll_pwait",
864398
				"epoll_wait",
864398
				"epoll_wait_old",
864398
				"eventfd",
864398
				"eventfd2",
864398
				"execve",
864398
				"execveat",
864398
				"exit",
864398
				"exit_group",
864398
				"faccessat",
864398
				"fadvise64",
864398
				"fadvise64_64",
864398
				"fallocate",
864398
				"fanotify_mark",
864398
				"fchdir",
864398
				"fchmod",
864398
				"fchmodat",
864398
				"fchown",
864398
				"fchown32",
864398
				"fchownat",
864398
				"fcntl",
864398
				"fcntl64",
864398
				"fdatasync",
864398
				"fgetxattr",
864398
				"flistxattr",
864398
				"flock",
864398
				"fork",
864398
				"fremovexattr",
864398
				"fsetxattr",
864398
				"fstat",
864398
				"fstat64",
864398
				"fstatat64",
864398
				"fstatfs",
864398
				"fstatfs64",
864398
				"fsync",
864398
				"ftruncate",
864398
				"ftruncate64",
864398
				"futex",
864398
				"futimesat",
864398
				"getcpu",
864398
				"getcwd",
864398
				"getdents",
864398
				"getdents64",
864398
				"getegid",
864398
				"getegid32",
864398
				"geteuid",
864398
				"geteuid32",
864398
				"getgid",
864398
				"getgid32",
864398
				"getgroups",
864398
				"getgroups32",
864398
				"getitimer",
864398
				"getpeername",
864398
				"getpgid",
864398
				"getpgrp",
864398
				"getpid",
864398
				"getppid",
864398
				"getpriority",
864398
				"getrandom",
864398
				"getresgid",
864398
				"getresgid32",
864398
				"getresuid",
864398
				"getresuid32",
864398
				"getrlimit",
864398
				"get_robust_list",
864398
				"getrusage",
864398
				"getsid",
864398
				"getsockname",
864398
				"getsockopt",
864398
				"get_thread_area",
864398
				"gettid",
864398
				"gettimeofday",
864398
				"getuid",
864398
				"getuid32",
864398
				"getxattr",
864398
				"inotify_add_watch",
864398
				"inotify_init",
864398
				"inotify_init1",
864398
				"inotify_rm_watch",
864398
				"io_cancel",
864398
				"ioctl",
864398
				"io_destroy",
864398
				"io_getevents",
864398
				"ioprio_get",
864398
				"ioprio_set",
864398
				"io_setup",
864398
				"io_submit",
864398
				"ipc",
864398
				"kill",
864398
				"lchown",
864398
				"lchown32",
864398
				"lgetxattr",
864398
				"link",
864398
				"linkat",
864398
				"listen",
864398
				"listxattr",
864398
				"llistxattr",
864398
				"_llseek",
864398
				"lremovexattr",
864398
				"lseek",
864398
				"lsetxattr",
864398
				"lstat",
864398
				"lstat64",
864398
				"madvise",
864398
				"memfd_create",
864398
				"mincore",
864398
				"mkdir",
864398
				"mkdirat",
864398
				"mknod",
864398
				"mknodat",
864398
				"mlock",
864398
				"mlock2",
864398
				"mlockall",
864398
				"mmap",
864398
				"mmap2",
864398
				"mprotect",
864398
				"mq_getsetattr",
864398
				"mq_notify",
864398
				"mq_open",
864398
				"mq_timedreceive",
864398
				"mq_timedsend",
864398
				"mq_unlink",
864398
				"mremap",
864398
				"msgctl",
864398
				"msgget",
864398
				"msgrcv",
864398
				"msgsnd",
864398
				"msync",
864398
				"munlock",
864398
				"munlockall",
864398
				"munmap",
864398
				"nanosleep",
864398
				"newfstatat",
864398
				"_newselect",
864398
				"open",
864398
				"openat",
864398
				"pause",
864398
				"pipe",
864398
				"pipe2",
864398
				"poll",
864398
				"ppoll",
864398
				"prctl",
864398
				"pread64",
864398
				"preadv",
864398
				"preadv2",
864398
				"prlimit64",
864398
				"pselect6",
864398
				"pwrite64",
864398
				"pwritev",
864398
				"pwritev2",
864398
				"read",
864398
				"readahead",
864398
				"readlink",
864398
				"readlinkat",
864398
				"readv",
864398
				"recv",
864398
				"recvfrom",
864398
				"recvmmsg",
864398
				"recvmsg",
864398
				"remap_file_pages",
864398
				"removexattr",
864398
				"rename",
864398
				"renameat",
864398
				"renameat2",
864398
				"restart_syscall",
864398
				"rmdir",
864398
				"rt_sigaction",
864398
				"rt_sigpending",
864398
				"rt_sigprocmask",
864398
				"rt_sigqueueinfo",
864398
				"rt_sigreturn",
864398
				"rt_sigsuspend",
864398
				"rt_sigtimedwait",
864398
				"rt_tgsigqueueinfo",
864398
				"sched_getaffinity",
864398
				"sched_getattr",
864398
				"sched_getparam",
864398
				"sched_get_priority_max",
864398
				"sched_get_priority_min",
864398
				"sched_getscheduler",
864398
				"sched_rr_get_interval",
864398
				"sched_setaffinity",
864398
				"sched_setattr",
864398
				"sched_setparam",
864398
				"sched_setscheduler",
864398
				"sched_yield",
864398
				"seccomp",
864398
				"select",
864398
				"semctl",
864398
				"semget",
864398
				"semop",
864398
				"semtimedop",
864398
				"send",
864398
				"sendfile",
864398
				"sendfile64",
864398
				"sendmmsg",
864398
				"sendmsg",
864398
				"sendto",
864398
				"setfsgid",
864398
				"setfsgid32",
864398
				"setfsuid",
864398
				"setfsuid32",
864398
				"setgid",
864398
				"setgid32",
864398
				"setgroups",
864398
				"setgroups32",
864398
				"setitimer",
864398
				"setpgid",
864398
				"setpriority",
864398
				"setregid",
864398
				"setregid32",
864398
				"setresgid",
864398
				"setresgid32",
864398
				"setresuid",
864398
				"setresuid32",
864398
				"setreuid",
864398
				"setreuid32",
864398
				"setrlimit",
864398
				"set_robust_list",
864398
				"setsid",
864398
				"setsockopt",
864398
				"set_thread_area",
864398
				"set_tid_address",
864398
				"setuid",
864398
				"setuid32",
864398
				"setxattr",
864398
				"shmat",
864398
				"shmctl",
864398
				"shmdt",
864398
				"shmget",
864398
				"shutdown",
864398
				"sigaltstack",
864398
				"signalfd",
864398
				"signalfd4",
864398
				"sigreturn",
864398
				"socket",
864398
				"socketcall",
864398
				"socketpair",
864398
				"splice",
864398
				"stat",
864398
				"stat64",
864398
				"statfs",
864398
				"statfs64",
864398
				"statx",
864398
				"symlink",
864398
				"symlinkat",
864398
				"sync",
864398
				"sync_file_range",
864398
				"syncfs",
864398
				"sysinfo",
864398
				"syslog",
864398
				"tee",
864398
				"tgkill",
864398
				"time",
864398
				"timer_create",
864398
				"timer_delete",
864398
				"timerfd_create",
864398
				"timerfd_gettime",
864398
				"timerfd_settime",
864398
				"timer_getoverrun",
864398
				"timer_gettime",
864398
				"timer_settime",
864398
				"times",
864398
				"tkill",
864398
				"truncate",
864398
				"truncate64",
864398
				"ugetrlimit",
864398
				"umask",
864398
				"uname",
864398
				"unlink",
864398
				"unlinkat",
864398
				"utime",
864398
				"utimensat",
864398
				"utimes",
864398
				"vfork",
864398
				"vmsplice",
864398
				"wait4",
864398
				"waitid",
864398
				"waitpid",
864398
				"write",
864398
				"writev",
864398
				"mount",
864398
				"umount2",
864398
				"reboot",
864398
				"name_to_handle_at",
864398
				"unshare"
864398
			],
864398
			"action": "SCMP_ACT_ALLOW",
864398
			"args": [],
864398
			"comment": "",
864398
			"includes": {},
864398
			"excludes": {}
864398
		},
864398
		{
864398
			"names": [
864398
				"personality"
864398
			],
864398
			"action": "SCMP_ACT_ALLOW",
864398
			"args": [
864398
				{
864398
					"index": 0,
864398
					"value": 0,
864398
					"valueTwo": 0,
864398
					"op": "SCMP_CMP_EQ"
864398
				}
864398
			],
864398
			"comment": "",
864398
			"includes": {},
864398
			"excludes": {}
864398
		},
864398
		{
864398
			"names": [
864398
				"personality"
864398
			],
864398
			"action": "SCMP_ACT_ALLOW",
864398
			"args": [
864398
				{
864398
					"index": 0,
864398
					"value": 8,
864398
					"valueTwo": 0,
864398
					"op": "SCMP_CMP_EQ"
864398
				}
864398
			],
864398
			"comment": "",
864398
			"includes": {},
864398
			"excludes": {}
864398
		},
864398
		{
864398
			"names": [
864398
				"personality"
864398
			],
864398
			"action": "SCMP_ACT_ALLOW",
864398
			"args": [
864398
				{
864398
					"index": 0,
864398
					"value": 131072,
864398
					"valueTwo": 0,
864398
					"op": "SCMP_CMP_EQ"
864398
				}
864398
			],
864398
			"comment": "",
864398
			"includes": {},
864398
			"excludes": {}
864398
		},
864398
		{
864398
			"names": [
864398
				"personality"
864398
			],
864398
			"action": "SCMP_ACT_ALLOW",
864398
			"args": [
864398
				{
864398
					"index": 0,
864398
					"value": 131080,
864398
					"valueTwo": 0,
864398
					"op": "SCMP_CMP_EQ"
864398
				}
864398
			],
864398
			"comment": "",
864398
			"includes": {},
864398
			"excludes": {}
864398
		},
864398
		{
864398
			"names": [
864398
				"personality"
864398
			],
864398
			"action": "SCMP_ACT_ALLOW",
864398
			"args": [
864398
				{
864398
					"index": 0,
864398
					"value": 4294967295,
864398
					"valueTwo": 0,
864398
					"op": "SCMP_CMP_EQ"
864398
				}
864398
			],
864398
			"comment": "",
864398
			"includes": {},
864398
			"excludes": {}
864398
		},
864398
		{
864398
			"names": [
864398
				"sync_file_range2"
864398
			],
864398
			"action": "SCMP_ACT_ALLOW",
864398
			"args": [],
864398
			"comment": "",
864398
			"includes": {
864398
				"arches": [
864398
					"ppc64le"
864398
				]
864398
			},
864398
			"excludes": {}
864398
		},
864398
		{
864398
			"names": [
864398
				"arm_fadvise64_64",
864398
				"arm_sync_file_range",
864398
				"sync_file_range2",
864398
				"breakpoint",
864398
				"cacheflush",
864398
				"set_tls"
864398
			],
864398
			"action": "SCMP_ACT_ALLOW",
864398
			"args": [],
864398
			"comment": "",
864398
			"includes": {
864398
				"arches": [
864398
					"arm",
864398
					"arm64"
864398
				]
864398
			},
864398
			"excludes": {}
864398
		},
864398
		{
864398
			"names": [
864398
				"arch_prctl"
864398
			],
864398
			"action": "SCMP_ACT_ALLOW",
864398
			"args": [],
864398
			"comment": "",
864398
			"includes": {
864398
				"arches": [
864398
					"amd64",
864398
					"x32"
864398
				]
864398
			},
864398
			"excludes": {}
864398
		},
864398
		{
864398
			"names": [
864398
				"modify_ldt"
864398
			],
864398
			"action": "SCMP_ACT_ALLOW",
864398
			"args": [],
864398
			"comment": "",
864398
			"includes": {
864398
				"arches": [
864398
					"amd64",
864398
					"x32",
864398
					"x86"
864398
				]
864398
			},
864398
			"excludes": {}
864398
		},
864398
		{
864398
			"names": [
864398
				"s390_pci_mmio_read",
864398
				"s390_pci_mmio_write",
864398
				"s390_runtime_instr"
864398
			],
864398
			"action": "SCMP_ACT_ALLOW",
864398
			"args": [],
864398
			"comment": "",
864398
			"includes": {
864398
				"arches": [
864398
					"s390",
864398
					"s390x"
864398
				]
864398
			},
864398
			"excludes": {}
864398
		},
864398
		{
864398
			"names": [
864398
				"open_by_handle_at"
864398
			],
864398
			"action": "SCMP_ACT_ALLOW",
864398
			"args": [],
864398
			"comment": "",
864398
			"includes": {
864398
				"caps": [
864398
					"CAP_DAC_READ_SEARCH"
864398
				]
864398
			},
864398
			"excludes": {}
864398
		},
864398
		{
864398
			"names": [
864398
				"bpf",
864398
				"clone",
864398
				"fanotify_init",
864398
				"lookup_dcookie",
864398
				"mount",
864398
				"name_to_handle_at",
864398
				"perf_event_open",
864398
				"quotactl",
864398
				"setdomainname",
864398
				"sethostname",
864398
				"setns",
864398
				"umount",
864398
				"umount2",
864398
				"unshare"
864398
			],
864398
			"action": "SCMP_ACT_ALLOW",
864398
			"args": [],
864398
			"comment": "",
864398
			"includes": {
864398
				"caps": [
864398
					"CAP_SYS_ADMIN"
864398
				]
864398
			},
864398
			"excludes": {}
864398
		},
864398
		{
864398
			"names": [
864398
				"clone"
864398
			],
864398
			"action": "SCMP_ACT_ALLOW",
864398
			"args": [
864398
				{
864398
					"index": 0,
864398
					"value": 2080505856,
864398
					"valueTwo": 0,
864398
					"op": "SCMP_CMP_MASKED_EQ"
864398
				}
864398
			],
864398
			"comment": "",
864398
			"includes": {},
864398
			"excludes": {
864398
				"caps": [
864398
					"CAP_SYS_ADMIN"
864398
				],
864398
				"arches": [
864398
					"s390",
864398
					"s390x"
864398
				]
864398
			}
864398
		},
864398
		{
864398
			"names": [
864398
				"clone"
864398
			],
864398
			"action": "SCMP_ACT_ALLOW",
864398
			"args": [
864398
				{
864398
					"index": 1,
864398
					"value": 2080505856,
864398
					"valueTwo": 0,
864398
					"op": "SCMP_CMP_MASKED_EQ"
864398
				}
864398
			],
864398
			"comment": "s390 parameter ordering for clone is different",
864398
			"includes": {
864398
				"arches": [
864398
					"s390",
864398
					"s390x"
864398
				]
864398
			},
864398
			"excludes": {
864398
				"caps": [
864398
					"CAP_SYS_ADMIN"
864398
				]
864398
			}
864398
		},
864398
		{
864398
			"names": [
864398
				"reboot"
864398
			],
864398
			"action": "SCMP_ACT_ALLOW",
864398
			"args": [],
864398
			"comment": "",
864398
			"includes": {
864398
				"caps": [
864398
					"CAP_SYS_BOOT"
864398
				]
864398
			},
864398
			"excludes": {}
864398
		},
864398
		{
864398
			"names": [
864398
				"chroot"
864398
			],
864398
			"action": "SCMP_ACT_ALLOW",
864398
			"args": [],
864398
			"comment": "",
864398
			"includes": {
864398
				"caps": [
864398
					"CAP_SYS_CHROOT"
864398
				]
864398
			},
864398
			"excludes": {}
864398
		},
864398
		{
864398
			"names": [
864398
				"delete_module",
864398
				"init_module",
864398
				"finit_module",
864398
				"query_module"
864398
			],
864398
			"action": "SCMP_ACT_ALLOW",
864398
			"args": [],
864398
			"comment": "",
864398
			"includes": {
864398
				"caps": [
864398
					"CAP_SYS_MODULE"
864398
				]
864398
			},
864398
			"excludes": {}
864398
		},
864398
		{
864398
			"names": [
864398
				"get_mempolicy",
864398
				"mbind",
864398
				"name_to_handle_at",
864398
				"set_mempolicy"
864398
			],
864398
			"action": "SCMP_ACT_ALLOW",
864398
			"args": [],
864398
			"comment": "",
864398
			"includes": {
864398
				"caps": [
864398
					"CAP_SYS_NICE"
864398
				]
864398
			},
864398
			"excludes": {}
864398
		},
864398
		{
864398
			"names": [
864398
				"acct"
864398
			],
864398
			"action": "SCMP_ACT_ALLOW",
864398
			"args": [],
864398
			"comment": "",
864398
			"includes": {
864398
				"caps": [
864398
					"CAP_SYS_PACCT"
864398
				]
864398
			},
864398
			"excludes": {}
864398
		},
864398
		{
864398
			"names": [
864398
				"kcmp",
864398
				"process_vm_readv",
864398
				"process_vm_writev",
864398
				"ptrace"
864398
			],
864398
			"action": "SCMP_ACT_ALLOW",
864398
			"args": [],
864398
			"comment": "",
864398
			"includes": {
864398
				"caps": [
864398
					"CAP_SYS_PTRACE"
864398
				]
864398
			},
864398
			"excludes": {}
864398
		},
864398
		{
864398
			"names": [
864398
				"iopl",
864398
				"ioperm"
864398
			],
864398
			"action": "SCMP_ACT_ALLOW",
864398
			"args": [],
864398
			"comment": "",
864398
			"includes": {
864398
				"caps": [
864398
					"CAP_SYS_RAWIO"
864398
				]
864398
			},
864398
			"excludes": {}
864398
		},
864398
		{
864398
			"names": [
864398
				"settimeofday",
864398
				"stime",
864398
				"clock_settime"
864398
			],
864398
			"action": "SCMP_ACT_ALLOW",
864398
			"args": [],
864398
			"comment": "",
864398
			"includes": {
864398
				"caps": [
864398
					"CAP_SYS_TIME"
864398
				]
864398
			},
864398
			"excludes": {}
864398
		},
864398
		{
864398
			"names": [
864398
				"vhangup"
864398
			],
864398
			"action": "SCMP_ACT_ALLOW",
864398
			"args": [],
864398
			"comment": "",
864398
			"includes": {
864398
				"caps": [
864398
					"CAP_SYS_TTY_CONFIG"
864398
				]
864398
			},
864398
			"excludes": {}
864398
		}
864398
	]
864398
}