From 569149a46e88924fa11b107d905cdc6b889934c3 Mon Sep 17 00:00:00 2001 From: rusty-snake Date: Mon, 26 Aug 2019 09:59:10 +0200 Subject: Use new seccomp syntax from #2926 in more profiles --- etc/simple-scan.profile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'etc/simple-scan.profile') diff --git a/etc/simple-scan.profile b/etc/simple-scan.profile index 64441483d..a0c9e8303 100644 --- a/etc/simple-scan.profile +++ b/etc/simple-scan.profile @@ -27,7 +27,7 @@ notv # novideo protocol unix,inet,inet6,netlink # blacklisting of ioperm system calls breaks simple-scan -seccomp.drop @clock,@cpu-emulation,@debug,@module,@obsolete,@reboot,@resources,@swap,acct,add_key,bpf,chroot,fanotify_init,io_cancel,io_destroy,io_getevents,io_setup,io_submit,iopl,ioprio_set,kcmp,keyctl,mount,name_to_handle_at,nfsservctl,ni_syscall,open_by_handle_at,pciconfig_iobase,pciconfig_read,pciconfig_write,personality,pivot_root,process_vm_readv,ptrace,remap_file_pages,request_key,s390_mmio_read,s390_mmio_write,setdomainname,sethostname,syslog,umount,umount2,userfaultfd,vhangup,vmsplice +seccomp !ioperm shell none tracelog -- cgit v1.2.3-70-g09d2