diff options
-rw-r--r-- | sandbox-seccomp-filter.c | 6 |
1 files changed, 6 insertions, 0 deletions
diff --git a/sandbox-seccomp-filter.c b/sandbox-seccomp-filter.c index d132e2646..2e1ed2c52 100644 --- a/sandbox-seccomp-filter.c +++ b/sandbox-seccomp-filter.c | |||
@@ -103,6 +103,12 @@ static const struct sock_filter preauth_insns[] = { | |||
103 | offsetof(struct seccomp_data, nr)), | 103 | offsetof(struct seccomp_data, nr)), |
104 | 104 | ||
105 | /* Syscalls to non-fatally deny */ | 105 | /* Syscalls to non-fatally deny */ |
106 | #ifdef __NR_lstat | ||
107 | SC_DENY(lstat, EACCES), | ||
108 | #endif | ||
109 | #ifdef __NR_lstat64 | ||
110 | SC_DENY(lstat64, EACCES), | ||
111 | #endif | ||
106 | #ifdef __NR_fstat | 112 | #ifdef __NR_fstat |
107 | SC_DENY(fstat, EACCES), | 113 | SC_DENY(fstat, EACCES), |
108 | #endif | 114 | #endif |