Skip to content

[20.10 backport] profiles: seccomp: update to Linux 5.11 syscall list#41971

Merged
tiborvass merged 1 commit into
moby:20.10from
thaJeztah:20.10_backport_seccomp_update
Feb 18, 2021
Merged

[20.10 backport] profiles: seccomp: update to Linux 5.11 syscall list#41971
tiborvass merged 1 commit into
moby:20.10from
thaJeztah:20.10_backport_seccomp_update

Conversation

@thaJeztah

Copy link
Copy Markdown
Member

backport of #41889

These syscalls (some of which have been in Linux for a while but were
missing from the profile) fall into a few buckets:

  • close_range(2), epoll_pwait2(2) are just extensions of existing "safe
    for everyone" syscalls.

  • The mountv2 API syscalls (fs*(2), move_mount(2), open_tree(2)) are
    all equivalent to aspects of mount(2) and thus go into the
    CAP_SYS_ADMIN category.

  • process_madvise(2) is similar to the other process_*(2) syscalls and
    thus goes in the CAP_SYS_PTRACE category.

- Description for the changelog

@thaJeztah

Copy link
Copy Markdown
Member Author

@tonistiigi @AkihiroSuda ptal

These syscalls (some of which have been in Linux for a while but were
missing from the profile) fall into a few buckets:

 * close_range(2), epoll_pwait2(2) are just extensions of existing "safe
   for everyone" syscalls.

 * The mountv2 API syscalls (fs*(2), move_mount(2), open_tree(2)) are
   all equivalent to aspects of mount(2) and thus go into the
   CAP_SYS_ADMIN category.

 * process_madvise(2) is similar to the other process_*(2) syscalls and
   thus goes in the CAP_SYS_PTRACE category.

Signed-off-by: Aleksa Sarai <[email protected]>
(cherry picked from commit 54eff43)
Signed-off-by: Sebastiaan van Stijn <[email protected]>
@thaJeztah
thaJeztah force-pushed the 20.10_backport_seccomp_update branch from 8c44f6f to a6a88b3 Compare February 17, 2021 20:22
@thaJeztah

Copy link
Copy Markdown
Member Author

rebased to trigger CI with test-fixes that were merged

Comment thread profiles/seccomp/default.json

@cpuguy83 cpuguy83 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants