summaryrefslogtreecommitdiff
path: root/src/nspawn/nspawn-seccomp.c
diff options
context:
space:
mode:
authorLennart Poettering <lennart@poettering.net>2017-09-30 14:08:26 +0200
committerLennart Poettering <lennart@poettering.net>2017-10-05 11:27:34 +0200
commit4c3a917617260956faeb4eceb606c316f6bea407 (patch)
tree4a0f3fb53da5ba19c4e9bfc9eedd9c023b6518ad /src/nspawn/nspawn-seccomp.c
parentc9905d4dd291c1525dc1a075651aade26498b204 (diff)
downloadsystemd-4c3a917617260956faeb4eceb606c316f6bea407.tar.gz
seccomp: include prlimit64 and ugetrlimit in @default
Also, move prlimit64() out of @resources. prlimit64() may be used both for getting and setting resource limits, and is implicitly called by glibc at various places, on some archs, the same was as getrlimit(). SImilar, igetrlimit() is an arch-specific replacement for getrlimit(), and hence should be whitelisted at the same place as getrlimit() and prlimit64(). Also see: https://lists.freedesktop.org/archives/systemd-devel/2017-September/039543.html
Diffstat (limited to 'src/nspawn/nspawn-seccomp.c')
-rw-r--r--src/nspawn/nspawn-seccomp.c1
1 files changed, 0 insertions, 1 deletions
diff --git a/src/nspawn/nspawn-seccomp.c b/src/nspawn/nspawn-seccomp.c
index 196766dc98..92d8103ad5 100644
--- a/src/nspawn/nspawn-seccomp.c
+++ b/src/nspawn/nspawn-seccomp.c
@@ -136,7 +136,6 @@ static int seccomp_add_default_syscall_filter(
{ 0, "syncfs" },
{ 0, "sysinfo" },
{ 0, "tee" },
- { 0, "ugetrlimit" },
{ 0, "umask" },
{ 0, "uname" },
{ 0, "userfaultfd" },