From d0e0be1e43e6628e6215e1803c7a2415dd58c9bd Mon Sep 17 00:00:00 2001 From: Tobias Berger Date: Sun, 13 Feb 2022 13:45:13 +0100 Subject: [PATCH] Allow Arch-Armv7 syscalls in sandbox.c --- sandbox.c | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/sandbox.c b/sandbox.c index 43f210d..2b5e9e0 100644 --- a/sandbox.c +++ b/sandbox.c @@ -344,6 +344,9 @@ static struct sock_filter filter[] = { #ifdef __NR_newfstatat SC_ALLOW(newfstatat), #endif +#ifdef __NR_fstatat64 + SC_ALLOW(fstatat64), +#endif #ifdef __NR_oldfstat SC_ALLOW(oldfstat), #endif @@ -383,6 +386,12 @@ static struct sock_filter filter[] = { #ifdef __NR_writev SC_ALLOW(writev), #endif +#ifdef __NR__llseek + SC_ALLOW(_llseek), +#endif +#ifdef __NR_sigreturn + SC_ALLOW(sigreturn), +#endif /* disallow everything else */ BPF_STMT(BPF_RET | BPF_K, SC_FAIL),