mirror of
https://github.com/google/sandboxed-api.git
synced 2024-03-22 13:11:30 +08:00
Adjust sandboxed_api default policy
PiperOrigin-RevId: 557762512 Change-Id: I600c8126ee09b8bab927013de25fcb836c78ac9a
This commit is contained in:
parent
f378d22405
commit
18c64ae10f
|
@ -70,21 +70,20 @@ void InitDefaultPolicyBuilder(sandbox2::PolicyBuilder* builder) {
|
|||
.AllowHandleSignals()
|
||||
.AllowSystemMalloc()
|
||||
.AllowSafeFcntl()
|
||||
.AllowSyscall(__NR_recvmsg)
|
||||
.AllowSyscall(__NR_sendmsg)
|
||||
.AllowSyscall(__NR_futex)
|
||||
.AllowSyscall(__NR_close)
|
||||
.AllowSyscall(__NR_lseek)
|
||||
.AllowSyscall(__NR_getpid)
|
||||
.AllowSyscall(__NR_getppid)
|
||||
.AllowSyscall(__NR_gettid)
|
||||
.AllowGetPIDs()
|
||||
.AllowSleep()
|
||||
.AllowSyscall(__NR_uname)
|
||||
.AllowSyscall(__NR_getrandom)
|
||||
.AllowSyscall(__NR_kill)
|
||||
.AllowSyscall(__NR_tgkill)
|
||||
.AllowSyscall(__NR_tkill)
|
||||
.AllowReadlink();
|
||||
.AllowReadlink()
|
||||
.AllowSyscalls({
|
||||
__NR_recvmsg,
|
||||
__NR_sendmsg,
|
||||
__NR_futex,
|
||||
__NR_close,
|
||||
__NR_lseek,
|
||||
__NR_uname,
|
||||
__NR_kill,
|
||||
__NR_tgkill,
|
||||
__NR_tkill,
|
||||
});
|
||||
|
||||
#ifdef __NR_arch_prctl // x86-64 only
|
||||
builder->AllowSyscall(__NR_arch_prctl);
|
||||
|
|
Loading…
Reference in New Issue
Block a user