From ae3db84128503c16fd638b5c7bf9408d64ce14ba Mon Sep 17 00:00:00 2001 From: netblue30 Date: Mon, 14 Jan 2019 09:44:53 -0500 Subject: adding mincore syscall to the default seccomp filter and some independent profiles --- etc/mpd.profile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'etc/mpd.profile') diff --git a/etc/mpd.profile b/etc/mpd.profile index e06b83aa9..c532edeb2 100644 --- a/etc/mpd.profile +++ b/etc/mpd.profile @@ -30,7 +30,7 @@ novideo protocol unix,inet,inet6 # blacklisting of ioprio_set system calls breaks auto-updating of # MPD's database when files in music_directory are changed -seccomp.drop @cpu-emulation,@debug,@obsolete,@privileged,@resources,add_key,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,kcmp,keyctl,name_to_handle_at,ni_syscall,open_by_handle_at,personality,process_vm_readv,ptrace,remap_file_pages,request_key,syslog,umount,userfaultfd,vmsplice +seccomp.drop mincore,@cpu-emulation,@debug,@obsolete,@privileged,@resources,add_key,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,kcmp,keyctl,name_to_handle_at,ni_syscall,open_by_handle_at,personality,process_vm_readv,ptrace,remap_file_pages,request_key,syslog,umount,userfaultfd,vmsplice shell none #private-bin mpd,bash -- cgit v1.2.3-70-g09d2