From 8aa5517ff639fe7101de34c24701057d56a44346 Mon Sep 17 00:00:00 2001 From: Cristian Toader Date: Wed, 21 Aug 2013 13:38:00 +0300 Subject: [PATCH] fix: flock filter update --- src/common/sandbox.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/src/common/sandbox.c b/src/common/sandbox.c index 87c8946bc1..7ff0fb0afa 100644 --- a/src/common/sandbox.c +++ b/src/common/sandbox.c @@ -531,6 +531,11 @@ sb_flock(scmp_filter_ctx ctx, sandbox_cfg_t *filter) if (rc) return rc; + rc = seccomp_rule_add(ctx, SCMP_ACT_ALLOW, SCMP_SYS(flock), 1, + SCMP_CMP(1, SCMP_CMP_EQ, LOCK_UN)); + if (rc) + return rc; + return 0; }