Skip to content

Commit 0963c05

Browse files
committed
seccomp: augment the @resources group a bit
Given that sched_setattr/sched_setparam/sched_setscheduler are already in the group the closely related nice + ioprio_set should also be included. Also, order things alphabetically.
1 parent b887d2e commit 0963c05

File tree

1 file changed

+9
-7
lines changed

1 file changed

+9
-7
lines changed

src/shared/seccomp-util.c

Lines changed: 9 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -658,17 +658,19 @@ const SyscallFilterSet syscall_filter_sets[_SYSCALL_FILTER_SET_MAX] = {
658658
.name = "@resources",
659659
.help = "Alter resource settings",
660660
.value =
661+
"ioprio_set\0"
662+
"mbind\0"
663+
"migrate_pages\0"
664+
"move_pages\0"
665+
"nice\0"
666+
"prlimit64\0"
667+
"sched_setaffinity\0"
668+
"sched_setattr\0"
661669
"sched_setparam\0"
662670
"sched_setscheduler\0"
663-
"sched_setaffinity\0"
671+
"set_mempolicy\0"
664672
"setpriority\0"
665673
"setrlimit\0"
666-
"set_mempolicy\0"
667-
"migrate_pages\0"
668-
"move_pages\0"
669-
"mbind\0"
670-
"sched_setattr\0"
671-
"prlimit64\0"
672674
},
673675
[SYSCALL_FILTER_SET_SETUID] = {
674676
.name = "@setuid",

0 commit comments

Comments
 (0)