aboutsummaryrefslogtreecommitdiffstats
path: root/src
diff options
context:
space:
mode:
authorLibravatar netblue30 <netblue30@yahoo.com>2019-01-14 09:44:53 -0500
committerLibravatar netblue30 <netblue30@yahoo.com>2019-01-14 09:44:53 -0500
commitae3db84128503c16fd638b5c7bf9408d64ce14ba (patch)
treec9767454fa6a0555f3bd9784e6d5d7b7433b932e /src
parentfix error message (diff)
downloadfirejail-ae3db84128503c16fd638b5c7bf9408d64ce14ba.tar.gz
firejail-ae3db84128503c16fd638b5c7bf9408d64ce14ba.tar.zst
firejail-ae3db84128503c16fd638b5c7bf9408d64ce14ba.zip
adding mincore syscall to the default seccomp filter and some independent profiles
Diffstat (limited to 'src')
-rw-r--r--src/fseccomp/syscall.c5
-rw-r--r--src/man/firejail.txt2
2 files changed, 5 insertions, 2 deletions
diff --git a/src/fseccomp/syscall.c b/src/fseccomp/syscall.c
index 3b10c4473..b17d86a0b 100644
--- a/src/fseccomp/syscall.c
+++ b/src/fseccomp/syscall.c
@@ -168,7 +168,10 @@ static const SyscallGroupList sysgroups[] = {
168 "umount," 168 "umount,"
169#endif 169#endif
170#ifdef SYS_userfaultfd 170#ifdef SYS_userfaultfd
171 "userfaultfd" 171 "userfaultfd,"
172#endif
173#ifdef SYS_mincore // 0.9.57
174 "mincore"
172#endif 175#endif
173 }, 176 },
174 { .name = "@default-nodebuggers", .list = 177 { .name = "@default-nodebuggers", .list =
diff --git a/src/man/firejail.txt b/src/man/firejail.txt
index 2d0bd26d0..0d402ef36 100644
--- a/src/man/firejail.txt
+++ b/src/man/firejail.txt
@@ -1700,7 +1700,7 @@ Enable seccomp filter and blacklist the syscalls in the default list (@default).
1700_sysctl, acct, add_key, adjtimex, afs_syscall, bdflush, bpf, break, chroot, clock_adjtime, clock_settime, 1700_sysctl, acct, add_key, adjtimex, afs_syscall, bdflush, bpf, break, chroot, clock_adjtime, clock_settime,
1701create_module, delete_module, fanotify_init, finit_module, ftime, get_kernel_syms, getpmsg, gtty, init_module, 1701create_module, delete_module, fanotify_init, finit_module, ftime, get_kernel_syms, getpmsg, gtty, init_module,
1702io_cancel, io_destroy, io_getevents, io_setup, io_submit, ioperm, iopl, ioprio_set, kcmp, kexec_file_load, 1702io_cancel, io_destroy, io_getevents, io_setup, io_submit, ioperm, iopl, ioprio_set, kcmp, kexec_file_load,
1703kexec_load, keyctl, lock, lookup_dcookie, mbind, migrate_pages, modify_ldt, mount, move_pages, mpx, 1703kexec_load, keyctl, lock, lookup_dcookie, mbind, migrate_pages, modify_ldt, mount, mincore, move_pages, mpx,
1704name_to_handle_at, nfsservctl, ni_syscall, open_by_handle_at, pciconfig_iobase, pciconfig_read, pciconfig_write, perf_event_open, 1704name_to_handle_at, nfsservctl, ni_syscall, open_by_handle_at, pciconfig_iobase, pciconfig_read, pciconfig_write, perf_event_open,
1705personality, pivot_root, process_vm_readv, process_vm_writev, prof, profil, ptrace, putpmsg, 1705personality, pivot_root, process_vm_readv, process_vm_writev, prof, profil, ptrace, putpmsg,
1706query_module, reboot, remap_file_pages, request_key, rtas, s390_mmio_read, s390_mmio_write, s390_runtime_instr, 1706query_module, reboot, remap_file_pages, request_key, rtas, s390_mmio_read, s390_mmio_write, s390_runtime_instr,