Skip to content

Commit 3dbded8

Browse files
committed
Removed syscalls open and openat from policy defined in addExecutionControlRules due to this syscalls being handled by policy defined in addFileSystemAccessRules
1 parent b5903c6 commit 3dbded8

File tree

1 file changed

+1
-3
lines changed

1 file changed

+1
-3
lines changed

src/seccomp/policy/DefaultPolicy.cc

+1-3
Original file line numberDiff line numberDiff line change
@@ -42,9 +42,7 @@ void DefaultPolicy::addExecutionControlRules(bool allowFork) {
4242
"sigaltstack",
4343
"sigsuspend",
4444
"clock_nanosleep",
45-
"open",
46-
"epoll_create1",
47-
"openat"});
45+
"epoll_create1"});
4846

4947
rules_.emplace_back(SeccompRule(
5048
"set_thread_area", action::ActionTrace([](auto& /* tracee */) {

0 commit comments

Comments
 (0)