From 83b898c9d7c14e70bb7531fffc56de40d2db4fb8 Mon Sep 17 00:00:00 2001 From: netblue30 Date: Fri, 16 Oct 2015 07:17:55 -0400 Subject: seccomp testing --- src/man/firejail.txt | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) (limited to 'src/man') diff --git a/src/man/firejail.txt b/src/man/firejail.txt index 9d3595d16..ae9d07bb8 100644 --- a/src/man/firejail.txt +++ b/src/man/firejail.txt @@ -861,7 +861,11 @@ $ firejail \-\-net=eth0 \-\-scan Enable seccomp filter and blacklist the syscalls in the default list. The default list is as follows: mount, umount2, ptrace, kexec_load, open_by_handle_at, init_module, finit_module, delete_module, iopl, ioperm, swapon, swapoff, syslog, process_vm_readv and process_vm_writev, -sysfs,_sysctl, adjtimex, clock_adjtime, lookup_dcookie, perf_event_open, fanotify_init and kcmp. +sysfs,_sysctl, adjtimex, clock_adjtime, lookup_dcookie, perf_event_open, fanotify_init, kcmp, +add_key, request_key, keyctl, uselib, acct, modify_ldt, pivot_root, io_setup, +io_destroy, io_getevents, io_submit, io_cancel, +remap_file_pages, mbind, get_mempolicy, set_mempolicy, +migrate_pages, move_pages, vmsplice, and perf_event_open. .br .br -- cgit v1.2.3-54-g00ecf