a38d05
{
a38d05
	"defaultAction": "SCMP_ACT_ERRNO",
a38d05
	"archMap": [
a38d05
		{
a38d05
			"architecture": "SCMP_ARCH_X86_64",
a38d05
			"subArchitectures": [
a38d05
				"SCMP_ARCH_X86",
a38d05
				"SCMP_ARCH_X32"
a38d05
			]
a38d05
		},
a38d05
		{
a38d05
			"architecture": "SCMP_ARCH_AARCH64",
a38d05
			"subArchitectures": [
a38d05
				"SCMP_ARCH_ARM"
a38d05
			]
a38d05
		},
a38d05
		{
a38d05
			"architecture": "SCMP_ARCH_MIPS64",
a38d05
			"subArchitectures": [
a38d05
				"SCMP_ARCH_MIPS",
a38d05
				"SCMP_ARCH_MIPS64N32"
a38d05
			]
a38d05
		},
a38d05
		{
a38d05
			"architecture": "SCMP_ARCH_MIPS64N32",
a38d05
			"subArchitectures": [
a38d05
				"SCMP_ARCH_MIPS",
a38d05
				"SCMP_ARCH_MIPS64"
a38d05
			]
a38d05
		},
a38d05
		{
a38d05
			"architecture": "SCMP_ARCH_MIPSEL64",
a38d05
			"subArchitectures": [
a38d05
				"SCMP_ARCH_MIPSEL",
a38d05
				"SCMP_ARCH_MIPSEL64N32"
a38d05
			]
a38d05
		},
a38d05
		{
a38d05
			"architecture": "SCMP_ARCH_MIPSEL64N32",
a38d05
			"subArchitectures": [
a38d05
				"SCMP_ARCH_MIPSEL",
a38d05
				"SCMP_ARCH_MIPSEL64"
a38d05
			]
a38d05
		},
a38d05
		{
a38d05
			"architecture": "SCMP_ARCH_S390X",
a38d05
			"subArchitectures": [
a38d05
				"SCMP_ARCH_S390"
a38d05
			]
a38d05
		}
a38d05
	],
a38d05
	"syscalls": [
a38d05
		{
a38d05
			"names": [
a38d05
				"accept",
a38d05
				"accept4",
a38d05
				"access",
a38d05
				"adjtimex",
a38d05
				"alarm",
a38d05
				"bind",
a38d05
				"brk",
a38d05
				"capget",
a38d05
				"capset",
a38d05
				"chdir",
a38d05
				"chmod",
a38d05
				"chown",
a38d05
				"chown32",
a38d05
				"clock_getres",
a38d05
				"clock_gettime",
a38d05
				"clock_nanosleep",
a38d05
				"close",
a38d05
				"connect",
a38d05
				"copy_file_range",
a38d05
				"creat",
a38d05
				"dup",
a38d05
				"dup2",
a38d05
				"dup3",
a38d05
				"epoll_create",
a38d05
				"epoll_create1",
a38d05
				"epoll_ctl",
a38d05
				"epoll_ctl_old",
a38d05
				"epoll_pwait",
a38d05
				"epoll_wait",
a38d05
				"epoll_wait_old",
a38d05
				"eventfd",
a38d05
				"eventfd2",
a38d05
				"execve",
a38d05
				"execveat",
a38d05
				"exit",
a38d05
				"exit_group",
a38d05
				"faccessat",
a38d05
				"fadvise64",
a38d05
				"fadvise64_64",
a38d05
				"fallocate",
a38d05
				"fanotify_mark",
a38d05
				"fchdir",
a38d05
				"fchmod",
a38d05
				"fchmodat",
a38d05
				"fchown",
a38d05
				"fchown32",
a38d05
				"fchownat",
a38d05
				"fcntl",
a38d05
				"fcntl64",
a38d05
				"fdatasync",
a38d05
				"fgetxattr",
a38d05
				"flistxattr",
a38d05
				"flock",
a38d05
				"fork",
a38d05
				"fremovexattr",
a38d05
				"fsetxattr",
a38d05
				"fstat",
a38d05
				"fstat64",
a38d05
				"fstatat64",
a38d05
				"fstatfs",
a38d05
				"fstatfs64",
a38d05
				"fsync",
a38d05
				"ftruncate",
a38d05
				"ftruncate64",
a38d05
				"futex",
a38d05
				"futimesat",
a38d05
				"getcpu",
a38d05
				"getcwd",
a38d05
				"getdents",
a38d05
				"getdents64",
a38d05
				"getegid",
a38d05
				"getegid32",
a38d05
				"geteuid",
a38d05
				"geteuid32",
a38d05
				"getgid",
a38d05
				"getgid32",
a38d05
				"getgroups",
a38d05
				"getgroups32",
a38d05
				"getitimer",
a38d05
				"getpeername",
a38d05
				"getpgid",
a38d05
				"getpgrp",
a38d05
				"getpid",
a38d05
				"getppid",
a38d05
				"getpriority",
a38d05
				"getrandom",
a38d05
				"getresgid",
a38d05
				"getresgid32",
a38d05
				"getresuid",
a38d05
				"getresuid32",
a38d05
				"getrlimit",
a38d05
				"get_robust_list",
a38d05
				"getrusage",
a38d05
				"getsid",
a38d05
				"getsockname",
a38d05
				"getsockopt",
a38d05
				"get_thread_area",
a38d05
				"gettid",
a38d05
				"gettimeofday",
a38d05
				"getuid",
a38d05
				"getuid32",
a38d05
				"getxattr",
a38d05
				"inotify_add_watch",
a38d05
				"inotify_init",
a38d05
				"inotify_init1",
a38d05
				"inotify_rm_watch",
a38d05
				"io_cancel",
a38d05
				"ioctl",
a38d05
				"io_destroy",
a38d05
				"io_getevents",
a38d05
				"ioprio_get",
a38d05
				"ioprio_set",
a38d05
				"io_setup",
a38d05
				"io_submit",
a38d05
				"ipc",
a38d05
				"kill",
a38d05
				"lchown",
a38d05
				"lchown32",
a38d05
				"lgetxattr",
a38d05
				"link",
a38d05
				"linkat",
a38d05
				"listen",
a38d05
				"listxattr",
a38d05
				"llistxattr",
a38d05
				"_llseek",
a38d05
				"lremovexattr",
a38d05
				"lseek",
a38d05
				"lsetxattr",
a38d05
				"lstat",
a38d05
				"lstat64",
a38d05
				"madvise",
a38d05
				"memfd_create",
a38d05
				"mincore",
a38d05
				"mkdir",
a38d05
				"mkdirat",
a38d05
				"mknod",
a38d05
				"mknodat",
a38d05
				"mlock",
a38d05
				"mlock2",
a38d05
				"mlockall",
a38d05
				"mmap",
a38d05
				"mmap2",
a38d05
				"mprotect",
a38d05
				"mq_getsetattr",
a38d05
				"mq_notify",
a38d05
				"mq_open",
a38d05
				"mq_timedreceive",
a38d05
				"mq_timedsend",
a38d05
				"mq_unlink",
a38d05
				"mremap",
a38d05
				"msgctl",
a38d05
				"msgget",
a38d05
				"msgrcv",
a38d05
				"msgsnd",
a38d05
				"msync",
a38d05
				"munlock",
a38d05
				"munlockall",
a38d05
				"munmap",
a38d05
				"nanosleep",
a38d05
				"newfstatat",
a38d05
				"_newselect",
a38d05
				"open",
a38d05
				"openat",
a38d05
				"pause",
a38d05
				"pipe",
a38d05
				"pipe2",
a38d05
				"poll",
a38d05
				"ppoll",
a38d05
				"prctl",
a38d05
				"pread64",
a38d05
				"preadv",
a38d05
				"preadv2",
a38d05
				"prlimit64",
a38d05
				"pselect6",
a38d05
				"pwrite64",
a38d05
				"pwritev",
a38d05
				"pwritev2",
a38d05
				"read",
a38d05
				"readahead",
a38d05
				"readlink",
a38d05
				"readlinkat",
a38d05
				"readv",
a38d05
				"recv",
a38d05
				"recvfrom",
a38d05
				"recvmmsg",
a38d05
				"recvmsg",
a38d05
				"remap_file_pages",
a38d05
				"removexattr",
a38d05
				"rename",
a38d05
				"renameat",
a38d05
				"renameat2",
a38d05
				"restart_syscall",
a38d05
				"rmdir",
a38d05
				"rt_sigaction",
a38d05
				"rt_sigpending",
a38d05
				"rt_sigprocmask",
a38d05
				"rt_sigqueueinfo",
a38d05
				"rt_sigreturn",
a38d05
				"rt_sigsuspend",
a38d05
				"rt_sigtimedwait",
a38d05
				"rt_tgsigqueueinfo",
a38d05
				"sched_getaffinity",
a38d05
				"sched_getattr",
a38d05
				"sched_getparam",
a38d05
				"sched_get_priority_max",
a38d05
				"sched_get_priority_min",
a38d05
				"sched_getscheduler",
a38d05
				"sched_rr_get_interval",
a38d05
				"sched_setaffinity",
a38d05
				"sched_setattr",
a38d05
				"sched_setparam",
a38d05
				"sched_setscheduler",
a38d05
				"sched_yield",
a38d05
				"seccomp",
a38d05
				"select",
a38d05
				"semctl",
a38d05
				"semget",
a38d05
				"semop",
a38d05
				"semtimedop",
a38d05
				"send",
a38d05
				"sendfile",
a38d05
				"sendfile64",
a38d05
				"sendmmsg",
a38d05
				"sendmsg",
a38d05
				"sendto",
a38d05
				"setfsgid",
a38d05
				"setfsgid32",
a38d05
				"setfsuid",
a38d05
				"setfsuid32",
a38d05
				"setgid",
a38d05
				"setgid32",
a38d05
				"setgroups",
a38d05
				"setgroups32",
a38d05
				"setitimer",
a38d05
				"setpgid",
a38d05
				"setpriority",
a38d05
				"setregid",
a38d05
				"setregid32",
a38d05
				"setresgid",
a38d05
				"setresgid32",
a38d05
				"setresuid",
a38d05
				"setresuid32",
a38d05
				"setreuid",
a38d05
				"setreuid32",
a38d05
				"setrlimit",
a38d05
				"set_robust_list",
a38d05
				"setsid",
a38d05
				"setsockopt",
a38d05
				"set_thread_area",
a38d05
				"set_tid_address",
a38d05
				"setuid",
a38d05
				"setuid32",
a38d05
				"setxattr",
a38d05
				"shmat",
a38d05
				"shmctl",
a38d05
				"shmdt",
a38d05
				"shmget",
a38d05
				"shutdown",
a38d05
				"sigaltstack",
a38d05
				"signalfd",
a38d05
				"signalfd4",
a38d05
				"sigreturn",
a38d05
				"socket",
a38d05
				"socketcall",
a38d05
				"socketpair",
a38d05
				"splice",
a38d05
				"stat",
a38d05
				"stat64",
a38d05
				"statfs",
a38d05
				"statfs64",
a38d05
				"statx",
a38d05
				"symlink",
a38d05
				"symlinkat",
a38d05
				"sync",
a38d05
				"sync_file_range",
a38d05
				"syncfs",
a38d05
				"sysinfo",
a38d05
				"syslog",
a38d05
				"tee",
a38d05
				"tgkill",
a38d05
				"time",
a38d05
				"timer_create",
a38d05
				"timer_delete",
a38d05
				"timerfd_create",
a38d05
				"timerfd_gettime",
a38d05
				"timerfd_settime",
a38d05
				"timer_getoverrun",
a38d05
				"timer_gettime",
a38d05
				"timer_settime",
a38d05
				"times",
a38d05
				"tkill",
a38d05
				"truncate",
a38d05
				"truncate64",
a38d05
				"ugetrlimit",
a38d05
				"umask",
a38d05
				"uname",
a38d05
				"unlink",
a38d05
				"unlinkat",
a38d05
				"utime",
a38d05
				"utimensat",
a38d05
				"utimes",
a38d05
				"vfork",
a38d05
				"vmsplice",
a38d05
				"wait4",
a38d05
				"waitid",
a38d05
				"waitpid",
a38d05
				"write",
a38d05
				"writev",
a38d05
				"mount",
a38d05
				"umount2",
a38d05
				"reboot",
a38d05
				"name_to_handle_at",
a38d05
				"unshare"
a38d05
			],
a38d05
			"action": "SCMP_ACT_ALLOW",
a38d05
			"args": [],
a38d05
			"comment": "",
a38d05
			"includes": {},
a38d05
			"excludes": {}
a38d05
		},
a38d05
		{
a38d05
			"names": [
a38d05
				"personality"
a38d05
			],
a38d05
			"action": "SCMP_ACT_ALLOW",
a38d05
			"args": [
a38d05
				{
a38d05
					"index": 0,
a38d05
					"value": 0,
a38d05
					"valueTwo": 0,
a38d05
					"op": "SCMP_CMP_EQ"
a38d05
				}
a38d05
			],
a38d05
			"comment": "",
a38d05
			"includes": {},
a38d05
			"excludes": {}
a38d05
		},
a38d05
		{
a38d05
			"names": [
a38d05
				"personality"
a38d05
			],
a38d05
			"action": "SCMP_ACT_ALLOW",
a38d05
			"args": [
a38d05
				{
a38d05
					"index": 0,
a38d05
					"value": 8,
a38d05
					"valueTwo": 0,
a38d05
					"op": "SCMP_CMP_EQ"
a38d05
				}
a38d05
			],
a38d05
			"comment": "",
a38d05
			"includes": {},
a38d05
			"excludes": {}
a38d05
		},
a38d05
		{
a38d05
			"names": [
a38d05
				"personality"
a38d05
			],
a38d05
			"action": "SCMP_ACT_ALLOW",
a38d05
			"args": [
a38d05
				{
a38d05
					"index": 0,
a38d05
					"value": 131072,
a38d05
					"valueTwo": 0,
a38d05
					"op": "SCMP_CMP_EQ"
a38d05
				}
a38d05
			],
a38d05
			"comment": "",
a38d05
			"includes": {},
a38d05
			"excludes": {}
a38d05
		},
a38d05
		{
a38d05
			"names": [
a38d05
				"personality"
a38d05
			],
a38d05
			"action": "SCMP_ACT_ALLOW",
a38d05
			"args": [
a38d05
				{
a38d05
					"index": 0,
a38d05
					"value": 131080,
a38d05
					"valueTwo": 0,
a38d05
					"op": "SCMP_CMP_EQ"
a38d05
				}
a38d05
			],
a38d05
			"comment": "",
a38d05
			"includes": {},
a38d05
			"excludes": {}
a38d05
		},
a38d05
		{
a38d05
			"names": [
a38d05
				"personality"
a38d05
			],
a38d05
			"action": "SCMP_ACT_ALLOW",
a38d05
			"args": [
a38d05
				{
a38d05
					"index": 0,
a38d05
					"value": 4294967295,
a38d05
					"valueTwo": 0,
a38d05
					"op": "SCMP_CMP_EQ"
a38d05
				}
a38d05
			],
a38d05
			"comment": "",
a38d05
			"includes": {},
a38d05
			"excludes": {}
a38d05
		},
a38d05
		{
a38d05
			"names": [
a38d05
				"sync_file_range2"
a38d05
			],
a38d05
			"action": "SCMP_ACT_ALLOW",
a38d05
			"args": [],
a38d05
			"comment": "",
a38d05
			"includes": {
a38d05
				"arches": [
a38d05
					"ppc64le"
a38d05
				]
a38d05
			},
a38d05
			"excludes": {}
a38d05
		},
a38d05
		{
a38d05
			"names": [
a38d05
				"arm_fadvise64_64",
a38d05
				"arm_sync_file_range",
a38d05
				"sync_file_range2",
a38d05
				"breakpoint",
a38d05
				"cacheflush",
a38d05
				"set_tls"
a38d05
			],
a38d05
			"action": "SCMP_ACT_ALLOW",
a38d05
			"args": [],
a38d05
			"comment": "",
a38d05
			"includes": {
a38d05
				"arches": [
a38d05
					"arm",
a38d05
					"arm64"
a38d05
				]
a38d05
			},
a38d05
			"excludes": {}
a38d05
		},
a38d05
		{
a38d05
			"names": [
a38d05
				"arch_prctl"
a38d05
			],
a38d05
			"action": "SCMP_ACT_ALLOW",
a38d05
			"args": [],
a38d05
			"comment": "",
a38d05
			"includes": {
a38d05
				"arches": [
a38d05
					"amd64",
a38d05
					"x32"
a38d05
				]
a38d05
			},
a38d05
			"excludes": {}
a38d05
		},
a38d05
		{
a38d05
			"names": [
a38d05
				"modify_ldt"
a38d05
			],
a38d05
			"action": "SCMP_ACT_ALLOW",
a38d05
			"args": [],
a38d05
			"comment": "",
a38d05
			"includes": {
a38d05
				"arches": [
a38d05
					"amd64",
a38d05
					"x32",
a38d05
					"x86"
a38d05
				]
a38d05
			},
a38d05
			"excludes": {}
a38d05
		},
a38d05
		{
a38d05
			"names": [
a38d05
				"s390_pci_mmio_read",
a38d05
				"s390_pci_mmio_write",
a38d05
				"s390_runtime_instr"
a38d05
			],
a38d05
			"action": "SCMP_ACT_ALLOW",
a38d05
			"args": [],
a38d05
			"comment": "",
a38d05
			"includes": {
a38d05
				"arches": [
a38d05
					"s390",
a38d05
					"s390x"
a38d05
				]
a38d05
			},
a38d05
			"excludes": {}
a38d05
		},
a38d05
		{
a38d05
			"names": [
a38d05
				"open_by_handle_at"
a38d05
			],
a38d05
			"action": "SCMP_ACT_ALLOW",
a38d05
			"args": [],
a38d05
			"comment": "",
a38d05
			"includes": {
a38d05
				"caps": [
a38d05
					"CAP_DAC_READ_SEARCH"
a38d05
				]
a38d05
			},
a38d05
			"excludes": {}
a38d05
		},
a38d05
		{
a38d05
			"names": [
a38d05
				"bpf",
a38d05
				"clone",
a38d05
				"fanotify_init",
a38d05
				"lookup_dcookie",
a38d05
				"mount",
a38d05
				"name_to_handle_at",
a38d05
				"perf_event_open",
a38d05
				"quotactl",
a38d05
				"setdomainname",
a38d05
				"sethostname",
a38d05
				"setns",
a38d05
				"umount",
a38d05
				"umount2",
a38d05
				"unshare"
a38d05
			],
a38d05
			"action": "SCMP_ACT_ALLOW",
a38d05
			"args": [],
a38d05
			"comment": "",
a38d05
			"includes": {
a38d05
				"caps": [
a38d05
					"CAP_SYS_ADMIN"
a38d05
				]
a38d05
			},
a38d05
			"excludes": {}
a38d05
		},
a38d05
		{
a38d05
			"names": [
a38d05
				"clone"
a38d05
			],
a38d05
			"action": "SCMP_ACT_ALLOW",
a38d05
			"args": [
a38d05
				{
a38d05
					"index": 0,
a38d05
					"value": 2080505856,
a38d05
					"valueTwo": 0,
a38d05
					"op": "SCMP_CMP_MASKED_EQ"
a38d05
				}
a38d05
			],
a38d05
			"comment": "",
a38d05
			"includes": {},
a38d05
			"excludes": {
a38d05
				"caps": [
a38d05
					"CAP_SYS_ADMIN"
a38d05
				],
a38d05
				"arches": [
a38d05
					"s390",
a38d05
					"s390x"
a38d05
				]
a38d05
			}
a38d05
		},
a38d05
		{
a38d05
			"names": [
a38d05
				"clone"
a38d05
			],
a38d05
			"action": "SCMP_ACT_ALLOW",
a38d05
			"args": [
a38d05
				{
a38d05
					"index": 1,
a38d05
					"value": 2080505856,
a38d05
					"valueTwo": 0,
a38d05
					"op": "SCMP_CMP_MASKED_EQ"
a38d05
				}
a38d05
			],
a38d05
			"comment": "s390 parameter ordering for clone is different",
a38d05
			"includes": {
a38d05
				"arches": [
a38d05
					"s390",
a38d05
					"s390x"
a38d05
				]
a38d05
			},
a38d05
			"excludes": {
a38d05
				"caps": [
a38d05
					"CAP_SYS_ADMIN"
a38d05
				]
a38d05
			}
a38d05
		},
a38d05
		{
a38d05
			"names": [
a38d05
				"reboot"
a38d05
			],
a38d05
			"action": "SCMP_ACT_ALLOW",
a38d05
			"args": [],
a38d05
			"comment": "",
a38d05
			"includes": {
a38d05
				"caps": [
a38d05
					"CAP_SYS_BOOT"
a38d05
				]
a38d05
			},
a38d05
			"excludes": {}
a38d05
		},
a38d05
		{
a38d05
			"names": [
a38d05
				"chroot"
a38d05
			],
a38d05
			"action": "SCMP_ACT_ALLOW",
a38d05
			"args": [],
a38d05
			"comment": "",
a38d05
			"includes": {
a38d05
				"caps": [
a38d05
					"CAP_SYS_CHROOT"
a38d05
				]
a38d05
			},
a38d05
			"excludes": {}
a38d05
		},
a38d05
		{
a38d05
			"names": [
a38d05
				"delete_module",
a38d05
				"init_module",
a38d05
				"finit_module",
a38d05
				"query_module"
a38d05
			],
a38d05
			"action": "SCMP_ACT_ALLOW",
a38d05
			"args": [],
a38d05
			"comment": "",
a38d05
			"includes": {
a38d05
				"caps": [
a38d05
					"CAP_SYS_MODULE"
a38d05
				]
a38d05
			},
a38d05
			"excludes": {}
a38d05
		},
a38d05
		{
a38d05
			"names": [
a38d05
				"get_mempolicy",
a38d05
				"mbind",
a38d05
				"name_to_handle_at",
a38d05
				"set_mempolicy"
a38d05
			],
a38d05
			"action": "SCMP_ACT_ALLOW",
a38d05
			"args": [],
a38d05
			"comment": "",
a38d05
			"includes": {
a38d05
				"caps": [
a38d05
					"CAP_SYS_NICE"
a38d05
				]
a38d05
			},
a38d05
			"excludes": {}
a38d05
		},
a38d05
		{
a38d05
			"names": [
a38d05
				"acct"
a38d05
			],
a38d05
			"action": "SCMP_ACT_ALLOW",
a38d05
			"args": [],
a38d05
			"comment": "",
a38d05
			"includes": {
a38d05
				"caps": [
a38d05
					"CAP_SYS_PACCT"
a38d05
				]
a38d05
			},
a38d05
			"excludes": {}
a38d05
		},
a38d05
		{
a38d05
			"names": [
a38d05
				"kcmp",
a38d05
				"process_vm_readv",
a38d05
				"process_vm_writev",
a38d05
				"ptrace"
a38d05
			],
a38d05
			"action": "SCMP_ACT_ALLOW",
a38d05
			"args": [],
a38d05
			"comment": "",
a38d05
			"includes": {
a38d05
				"caps": [
a38d05
					"CAP_SYS_PTRACE"
a38d05
				]
a38d05
			},
a38d05
			"excludes": {}
a38d05
		},
a38d05
		{
a38d05
			"names": [
a38d05
				"iopl",
a38d05
				"ioperm"
a38d05
			],
a38d05
			"action": "SCMP_ACT_ALLOW",
a38d05
			"args": [],
a38d05
			"comment": "",
a38d05
			"includes": {
a38d05
				"caps": [
a38d05
					"CAP_SYS_RAWIO"
a38d05
				]
a38d05
			},
a38d05
			"excludes": {}
a38d05
		},
a38d05
		{
a38d05
			"names": [
a38d05
				"settimeofday",
a38d05
				"stime",
a38d05
				"clock_settime"
a38d05
			],
a38d05
			"action": "SCMP_ACT_ALLOW",
a38d05
			"args": [],
a38d05
			"comment": "",
a38d05
			"includes": {
a38d05
				"caps": [
a38d05
					"CAP_SYS_TIME"
a38d05
				]
a38d05
			},
a38d05
			"excludes": {}
a38d05
		},
a38d05
		{
a38d05
			"names": [
a38d05
				"vhangup"
a38d05
			],
a38d05
			"action": "SCMP_ACT_ALLOW",
a38d05
			"args": [],
a38d05
			"comment": "",
a38d05
			"includes": {
a38d05
				"caps": [
a38d05
					"CAP_SYS_TTY_CONFIG"
a38d05
				]
a38d05
			},
a38d05
			"excludes": {}
a38d05
		}
a38d05
	]
a38d05
}