Skip to content

Commit a1ec855

Browse files
committed
Fix seccomp profile for clone syscall
All clone flags for namespace should be denied. Based-on-patch-by: Kenta Tada <[email protected]> Signed-off-by: Sebastiaan van Stijn <[email protected]>
1 parent 0105613 commit a1ec855

File tree

3 files changed

+5
-5
lines changed

3 files changed

+5
-5
lines changed

profiles/seccomp/default.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -596,7 +596,7 @@
596596
"args": [
597597
{
598598
"index": 0,
599-
"value": 2080505856,
599+
"value": 2114060288,
600600
"valueTwo": 0,
601601
"op": "SCMP_CMP_MASKED_EQ"
602602
}
@@ -621,7 +621,7 @@
621621
"args": [
622622
{
623623
"index": 1,
624-
"value": 2080505856,
624+
"value": 2114060288,
625625
"valueTwo": 0,
626626
"op": "SCMP_CMP_MASKED_EQ"
627627
}

profiles/seccomp/fixtures/example.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@
77
"args": [
88
{
99
"index": 0,
10-
"value": 2080505856,
10+
"value": 2114060288,
1111
"valueTwo": 0,
1212
"op": "SCMP_CMP_MASKED_EQ"
1313
}

profiles/seccomp/seccomp_default.go

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -518,7 +518,7 @@ func DefaultProfile() *types.Seccomp {
518518
Args: []*types.Arg{
519519
{
520520
Index: 0,
521-
Value: unix.CLONE_NEWNS | unix.CLONE_NEWUTS | unix.CLONE_NEWIPC | unix.CLONE_NEWUSER | unix.CLONE_NEWPID | unix.CLONE_NEWNET,
521+
Value: unix.CLONE_NEWNS | unix.CLONE_NEWUTS | unix.CLONE_NEWIPC | unix.CLONE_NEWUSER | unix.CLONE_NEWPID | unix.CLONE_NEWNET | unix.CLONE_NEWCGROUP,
522522
ValueTwo: 0,
523523
Op: types.OpMaskedEqual,
524524
},
@@ -536,7 +536,7 @@ func DefaultProfile() *types.Seccomp {
536536
Args: []*types.Arg{
537537
{
538538
Index: 1,
539-
Value: unix.CLONE_NEWNS | unix.CLONE_NEWUTS | unix.CLONE_NEWIPC | unix.CLONE_NEWUSER | unix.CLONE_NEWPID | unix.CLONE_NEWNET,
539+
Value: unix.CLONE_NEWNS | unix.CLONE_NEWUTS | unix.CLONE_NEWIPC | unix.CLONE_NEWUSER | unix.CLONE_NEWPID | unix.CLONE_NEWNET | unix.CLONE_NEWCGROUP,
540540
ValueTwo: 0,
541541
Op: types.OpMaskedEqual,
542542
},

0 commit comments

Comments
 (0)