-
Notifications
You must be signed in to change notification settings - Fork 8.2k
Please add io_uring to the list of significant syscalls blocked by the default profile #23784
Copy link
Copy link
Open
Labels
agent/fixAgent has opened a PR for this issueAgent has opened a PR for this issueagent/triagedAgent has analyzed this issue; verdict in task fileAgent has analyzed this issue; verdict in task filestatus/triageNeeds triageNeeds triage
Description
Is this a docs issue?
- My issue is about the documentation content or website
Type of issue
Information is incorrect
Description
The io_uring_* syscalls are missing from the significant syscalls blocked table on https://docs.docker.com/engine/security/seccomp/#significant-syscalls-blocked-by-the-default-profile .
Location
Suggestion
Please can can you add the individual io_uring_* syscalls to the table of significant syscalls blocked by default? moby/moby#46762 is the commit that switched docker to blocking them and hopefully by listing them in the docs it will help people open things up just enough rather than reaching straight for --security-opt seccomp=unconfined if they need to use io_uring...
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
agent/fixAgent has opened a PR for this issueAgent has opened a PR for this issueagent/triagedAgent has analyzed this issue; verdict in task fileAgent has analyzed this issue; verdict in task filestatus/triageNeeds triageNeeds triage