From 37780456a75c08652bd191d0e9c2bb9077198dc4 Mon Sep 17 00:00:00 2001 From: Ophestra Date: Sat, 25 Jan 2025 12:35:47 +0900 Subject: helper: block more unusual/privileged syscalls These are toggled by F_EXT and exposed as SyscallPolicy.Compat in the Go interface. Signed-off-by: Ophestra --- helper/bwrap/seccomp-export.h | 15 ++++++++------- 1 file changed, 8 insertions(+), 7 deletions(-) (limited to 'helper/bwrap/seccomp-export.h') diff --git a/helper/bwrap/seccomp-export.h b/helper/bwrap/seccomp-export.h index 5df0dc65..90640d8f 100644 --- a/helper/bwrap/seccomp-export.h +++ b/helper/bwrap/seccomp-export.h @@ -8,13 +8,14 @@ #endif typedef enum { - F_DENY_NS = 1 << 0, - F_DENY_TTY = 1 << 1, - F_DENY_DEVEL = 1 << 2, - F_MULTIARCH = 1 << 3, - F_LINUX32 = 1 << 4, - F_CAN = 1 << 5, - F_BLUETOOTH = 1 << 6, + F_EXT = 1 << 0, + F_DENY_NS = 1 << 1, + F_DENY_TTY = 1 << 2, + F_DENY_DEVEL = 1 << 3, + F_MULTIARCH = 1 << 4, + F_LINUX32 = 1 << 5, + F_CAN = 1 << 6, + F_BLUETOOTH = 1 << 7, } f_syscall_opts; extern void F_println(char *v); -- cgit v1.3.1