Antonio Murdaca f061d69
{
Antonio Murdaca f061d69
	"defaultAction": "SCMP_ACT_ERRNO",
Antonio Murdaca f061d69
	"archMap": [
Antonio Murdaca f061d69
		{
Antonio Murdaca f061d69
			"architecture": "SCMP_ARCH_X86_64",
Antonio Murdaca f061d69
			"subArchitectures": [
Antonio Murdaca f061d69
				"SCMP_ARCH_X86",
Antonio Murdaca f061d69
				"SCMP_ARCH_X32"
Antonio Murdaca f061d69
			]
Antonio Murdaca f061d69
		},
Antonio Murdaca f061d69
		{
Antonio Murdaca f061d69
			"architecture": "SCMP_ARCH_AARCH64",
Antonio Murdaca f061d69
			"subArchitectures": [
Antonio Murdaca f061d69
				"SCMP_ARCH_ARM"
Antonio Murdaca f061d69
			]
Antonio Murdaca f061d69
		},
Antonio Murdaca f061d69
		{
Antonio Murdaca f061d69
			"architecture": "SCMP_ARCH_MIPS64",
Antonio Murdaca f061d69
			"subArchitectures": [
Antonio Murdaca f061d69
				"SCMP_ARCH_MIPS",
Antonio Murdaca f061d69
				"SCMP_ARCH_MIPS64N32"
Antonio Murdaca f061d69
			]
Antonio Murdaca f061d69
		},
Antonio Murdaca f061d69
		{
Antonio Murdaca f061d69
			"architecture": "SCMP_ARCH_MIPS64N32",
Antonio Murdaca f061d69
			"subArchitectures": [
Antonio Murdaca f061d69
				"SCMP_ARCH_MIPS",
Antonio Murdaca f061d69
				"SCMP_ARCH_MIPS64"
Antonio Murdaca f061d69
			]
Antonio Murdaca f061d69
		},
Antonio Murdaca f061d69
		{
Antonio Murdaca f061d69
			"architecture": "SCMP_ARCH_MIPSEL64",
Antonio Murdaca f061d69
			"subArchitectures": [
Antonio Murdaca f061d69
				"SCMP_ARCH_MIPSEL",
Antonio Murdaca f061d69
				"SCMP_ARCH_MIPSEL64N32"
Antonio Murdaca f061d69
			]
Antonio Murdaca f061d69
		},
Antonio Murdaca f061d69
		{
Antonio Murdaca f061d69
			"architecture": "SCMP_ARCH_MIPSEL64N32",
Antonio Murdaca f061d69
			"subArchitectures": [
Antonio Murdaca f061d69
				"SCMP_ARCH_MIPSEL",
Antonio Murdaca f061d69
				"SCMP_ARCH_MIPSEL64"
Antonio Murdaca f061d69
			]
Antonio Murdaca f061d69
		},
Antonio Murdaca f061d69
		{
Antonio Murdaca f061d69
			"architecture": "SCMP_ARCH_S390X",
Antonio Murdaca f061d69
			"subArchitectures": [
Antonio Murdaca f061d69
				"SCMP_ARCH_S390"
Antonio Murdaca f061d69
			]
Antonio Murdaca f061d69
		}
Antonio Murdaca f061d69
	],
Antonio Murdaca f061d69
	"syscalls": [
Antonio Murdaca f061d69
		{
Antonio Murdaca f061d69
			"names": [
Antonio Murdaca f061d69
				"accept",
Antonio Murdaca f061d69
				"accept4",
Antonio Murdaca f061d69
				"access",
Antonio Murdaca f061d69
				"alarm",
Antonio Murdaca f061d69
				"alarm",
Antonio Murdaca f061d69
				"bind",
Antonio Murdaca f061d69
				"brk",
Antonio Murdaca f061d69
				"capget",
Antonio Murdaca f061d69
				"capset",
Antonio Murdaca f061d69
				"chdir",
Antonio Murdaca f061d69
				"chmod",
Antonio Murdaca f061d69
				"chown",
Antonio Murdaca f061d69
				"chown32",
Antonio Murdaca f061d69
				"clock_getres",
Antonio Murdaca f061d69
				"clock_gettime",
Antonio Murdaca f061d69
				"clock_nanosleep",
Antonio Murdaca f061d69
				"close",
Antonio Murdaca f061d69
				"connect",
Antonio Murdaca f061d69
				"copy_file_range",
Antonio Murdaca f061d69
				"creat",
Antonio Murdaca f061d69
				"dup",
Antonio Murdaca f061d69
				"dup2",
Antonio Murdaca f061d69
				"dup3",
Antonio Murdaca f061d69
				"epoll_create",
Antonio Murdaca f061d69
				"epoll_create1",
Antonio Murdaca f061d69
				"epoll_ctl",
Antonio Murdaca f061d69
				"epoll_ctl_old",
Antonio Murdaca f061d69
				"epoll_pwait",
Antonio Murdaca f061d69
				"epoll_wait",
Antonio Murdaca f061d69
				"epoll_wait_old",
Antonio Murdaca f061d69
				"eventfd",
Antonio Murdaca f061d69
				"eventfd2",
Antonio Murdaca f061d69
				"execve",
Antonio Murdaca f061d69
				"execveat",
Antonio Murdaca f061d69
				"exit",
Antonio Murdaca f061d69
				"exit_group",
Antonio Murdaca f061d69
				"faccessat",
Antonio Murdaca f061d69
				"fadvise64",
Antonio Murdaca f061d69
				"fadvise64_64",
Antonio Murdaca f061d69
				"fallocate",
Antonio Murdaca f061d69
				"fanotify_mark",
Antonio Murdaca f061d69
				"fchdir",
Antonio Murdaca f061d69
				"fchmod",
Antonio Murdaca f061d69
				"fchmodat",
Antonio Murdaca f061d69
				"fchown",
Antonio Murdaca f061d69
				"fchown32",
Antonio Murdaca f061d69
				"fchownat",
Antonio Murdaca f061d69
				"fcntl",
Antonio Murdaca f061d69
				"fcntl64",
Antonio Murdaca f061d69
				"fdatasync",
Antonio Murdaca f061d69
				"fgetxattr",
Antonio Murdaca f061d69
				"flistxattr",
Antonio Murdaca f061d69
				"flock",
Antonio Murdaca f061d69
				"fork",
Antonio Murdaca f061d69
				"fremovexattr",
Antonio Murdaca f061d69
				"fsetxattr",
Antonio Murdaca f061d69
				"fstat",
Antonio Murdaca f061d69
				"fstat64",
Antonio Murdaca f061d69
				"fstatat64",
Antonio Murdaca f061d69
				"fstatfs",
Antonio Murdaca f061d69
				"fstatfs64",
Antonio Murdaca f061d69
				"fsync",
Antonio Murdaca f061d69
				"ftruncate",
Antonio Murdaca f061d69
				"ftruncate64",
Antonio Murdaca f061d69
				"futex",
Antonio Murdaca f061d69
				"futimesat",
Antonio Murdaca f061d69
				"getcpu",
Antonio Murdaca f061d69
				"getcwd",
Antonio Murdaca f061d69
				"getdents",
Antonio Murdaca f061d69
				"getdents64",
Antonio Murdaca f061d69
				"getegid",
Antonio Murdaca f061d69
				"getegid32",
Antonio Murdaca f061d69
				"geteuid",
Antonio Murdaca f061d69
				"geteuid32",
Antonio Murdaca f061d69
				"getgid",
Antonio Murdaca f061d69
				"getgid32",
Antonio Murdaca f061d69
				"getgroups",
Antonio Murdaca f061d69
				"getgroups32",
Antonio Murdaca f061d69
				"getitimer",
Antonio Murdaca f061d69
				"getpeername",
Antonio Murdaca f061d69
				"getpgid",
Antonio Murdaca f061d69
				"getpgrp",
Antonio Murdaca f061d69
				"getpid",
Antonio Murdaca f061d69
				"getppid",
Antonio Murdaca f061d69
				"getpriority",
Antonio Murdaca f061d69
				"getrandom",
Antonio Murdaca f061d69
				"getresgid",
Antonio Murdaca f061d69
				"getresgid32",
Antonio Murdaca f061d69
				"getresuid",
Antonio Murdaca f061d69
				"getresuid32",
Antonio Murdaca f061d69
				"getrlimit",
Antonio Murdaca f061d69
				"get_robust_list",
Antonio Murdaca f061d69
				"getrusage",
Antonio Murdaca f061d69
				"getsid",
Antonio Murdaca f061d69
				"getsockname",
Antonio Murdaca f061d69
				"getsockopt",
Antonio Murdaca f061d69
				"get_thread_area",
Antonio Murdaca f061d69
				"gettid",
Antonio Murdaca f061d69
				"gettimeofday",
Antonio Murdaca f061d69
				"getuid",
Antonio Murdaca f061d69
				"getuid32",
Antonio Murdaca f061d69
				"getxattr",
Antonio Murdaca f061d69
				"inotify_add_watch",
Antonio Murdaca f061d69
				"inotify_init",
Antonio Murdaca f061d69
				"inotify_init1",
Antonio Murdaca f061d69
				"inotify_rm_watch",
Antonio Murdaca f061d69
				"io_cancel",
Antonio Murdaca f061d69
				"ioctl",
Antonio Murdaca f061d69
				"io_destroy",
Antonio Murdaca f061d69
				"io_getevents",
Antonio Murdaca f061d69
				"ioprio_get",
Antonio Murdaca f061d69
				"ioprio_set",
Antonio Murdaca f061d69
				"io_setup",
Antonio Murdaca f061d69
				"io_submit",
Antonio Murdaca f061d69
				"ipc",
Antonio Murdaca f061d69
				"kill",
Antonio Murdaca f061d69
				"lchown",
Antonio Murdaca f061d69
				"lchown32",
Antonio Murdaca f061d69
				"lgetxattr",
Antonio Murdaca f061d69
				"link",
Antonio Murdaca f061d69
				"linkat",
Antonio Murdaca f061d69
				"listen",
Antonio Murdaca f061d69
				"listxattr",
Antonio Murdaca f061d69
				"llistxattr",
Antonio Murdaca f061d69
				"_llseek",
Antonio Murdaca f061d69
				"lremovexattr",
Antonio Murdaca f061d69
				"lseek",
Antonio Murdaca f061d69
				"lsetxattr",
Antonio Murdaca f061d69
				"lstat",
Antonio Murdaca f061d69
				"lstat64",
Antonio Murdaca f061d69
				"madvise",
Antonio Murdaca f061d69
				"memfd_create",
Antonio Murdaca f061d69
				"mincore",
Antonio Murdaca f061d69
				"mkdir",
Antonio Murdaca f061d69
				"mkdirat",
Antonio Murdaca f061d69
				"mknod",
Antonio Murdaca f061d69
				"mknodat",
Antonio Murdaca f061d69
				"mlock",
Antonio Murdaca f061d69
				"mlock2",
Antonio Murdaca f061d69
				"mlockall",
Antonio Murdaca f061d69
				"mmap",
Antonio Murdaca f061d69
				"mmap2",
Antonio Murdaca f061d69
				"mprotect",
Antonio Murdaca f061d69
				"mq_getsetattr",
Antonio Murdaca f061d69
				"mq_notify",
Antonio Murdaca f061d69
				"mq_open",
Antonio Murdaca f061d69
				"mq_timedreceive",
Antonio Murdaca f061d69
				"mq_timedsend",
Antonio Murdaca f061d69
				"mq_unlink",
Antonio Murdaca f061d69
				"mremap",
Antonio Murdaca f061d69
				"msgctl",
Antonio Murdaca f061d69
				"msgget",
Antonio Murdaca f061d69
				"msgrcv",
Antonio Murdaca f061d69
				"msgsnd",
Antonio Murdaca f061d69
				"msync",
Antonio Murdaca f061d69
				"munlock",
Antonio Murdaca f061d69
				"munlockall",
Antonio Murdaca f061d69
				"munmap",
Antonio Murdaca f061d69
				"nanosleep",
Antonio Murdaca f061d69
				"newfstatat",
Antonio Murdaca f061d69
				"_newselect",
Antonio Murdaca f061d69
				"open",
Antonio Murdaca f061d69
				"openat",
Antonio Murdaca f061d69
				"pause",
Antonio Murdaca f061d69
				"pipe",
Antonio Murdaca f061d69
				"pipe2",
Antonio Murdaca f061d69
				"poll",
Antonio Murdaca f061d69
				"ppoll",
Antonio Murdaca f061d69
				"prctl",
Antonio Murdaca f061d69
				"pread64",
Antonio Murdaca f061d69
				"preadv",
Antonio Murdaca f061d69
				"prlimit64",
Antonio Murdaca f061d69
				"pselect6",
Antonio Murdaca f061d69
				"pwrite64",
Antonio Murdaca f061d69
				"pwritev",
Antonio Murdaca f061d69
				"read",
Antonio Murdaca f061d69
				"readahead",
Antonio Murdaca f061d69
				"readlink",
Antonio Murdaca f061d69
				"readlinkat",
Antonio Murdaca f061d69
				"readv",
Antonio Murdaca f061d69
				"recv",
Antonio Murdaca f061d69
				"recvfrom",
Antonio Murdaca f061d69
				"recvmmsg",
Antonio Murdaca f061d69
				"recvmsg",
Antonio Murdaca f061d69
				"remap_file_pages",
Antonio Murdaca f061d69
				"removexattr",
Antonio Murdaca f061d69
				"rename",
Antonio Murdaca f061d69
				"renameat",
Antonio Murdaca f061d69
				"renameat2",
Antonio Murdaca f061d69
				"restart_syscall",
Antonio Murdaca f061d69
				"rmdir",
Antonio Murdaca f061d69
				"rt_sigaction",
Antonio Murdaca f061d69
				"rt_sigpending",
Antonio Murdaca f061d69
				"rt_sigprocmask",
Antonio Murdaca f061d69
				"rt_sigqueueinfo",
Antonio Murdaca f061d69
				"rt_sigreturn",
Antonio Murdaca f061d69
				"rt_sigsuspend",
Antonio Murdaca f061d69
				"rt_sigtimedwait",
Antonio Murdaca f061d69
				"rt_tgsigqueueinfo",
Antonio Murdaca f061d69
				"sched_getaffinity",
Antonio Murdaca f061d69
				"sched_getattr",
Antonio Murdaca f061d69
				"sched_getparam",
Antonio Murdaca f061d69
				"sched_get_priority_max",
Antonio Murdaca f061d69
				"sched_get_priority_min",
Antonio Murdaca f061d69
				"sched_getscheduler",
Antonio Murdaca f061d69
				"sched_rr_get_interval",
Antonio Murdaca f061d69
				"sched_setaffinity",
Antonio Murdaca f061d69
				"sched_setattr",
Antonio Murdaca f061d69
				"sched_setparam",
Antonio Murdaca f061d69
				"sched_setscheduler",
Antonio Murdaca f061d69
				"sched_yield",
Antonio Murdaca f061d69
				"seccomp",
Antonio Murdaca f061d69
				"select",
Antonio Murdaca f061d69
				"semctl",
Antonio Murdaca f061d69
				"semget",
Antonio Murdaca f061d69
				"semop",
Antonio Murdaca f061d69
				"semtimedop",
Antonio Murdaca f061d69
				"send",
Antonio Murdaca f061d69
				"sendfile",
Antonio Murdaca f061d69
				"sendfile64",
Antonio Murdaca f061d69
				"sendmmsg",
Antonio Murdaca f061d69
				"sendmsg",
Antonio Murdaca f061d69
				"sendto",
Antonio Murdaca f061d69
				"setfsgid",
Antonio Murdaca f061d69
				"setfsgid32",
Antonio Murdaca f061d69
				"setfsuid",
Antonio Murdaca f061d69
				"setfsuid32",
Antonio Murdaca f061d69
				"setgid",
Antonio Murdaca f061d69
				"setgid32",
Antonio Murdaca f061d69
				"setgroups",
Antonio Murdaca f061d69
				"setgroups32",
Antonio Murdaca f061d69
				"setitimer",
Antonio Murdaca f061d69
				"setpgid",
Antonio Murdaca f061d69
				"setpriority",
Antonio Murdaca f061d69
				"setregid",
Antonio Murdaca f061d69
				"setregid32",
Antonio Murdaca f061d69
				"setresgid",
Antonio Murdaca f061d69
				"setresgid32",
Antonio Murdaca f061d69
				"setresuid",
Antonio Murdaca f061d69
				"setresuid32",
Antonio Murdaca f061d69
				"setreuid",
Antonio Murdaca f061d69
				"setreuid32",
Antonio Murdaca f061d69
				"setrlimit",
Antonio Murdaca f061d69
				"set_robust_list",
Antonio Murdaca f061d69
				"setsid",
Antonio Murdaca f061d69
				"setsockopt",
Antonio Murdaca f061d69
				"set_thread_area",
Antonio Murdaca f061d69
				"set_tid_address",
Antonio Murdaca f061d69
				"setuid",
Antonio Murdaca f061d69
				"setuid32",
Antonio Murdaca f061d69
				"setxattr",
Antonio Murdaca f061d69
				"shmat",
Antonio Murdaca f061d69
				"shmctl",
Antonio Murdaca f061d69
				"shmdt",
Antonio Murdaca f061d69
				"shmget",
Antonio Murdaca f061d69
				"shutdown",
Antonio Murdaca f061d69
				"sigaltstack",
Antonio Murdaca f061d69
				"signalfd",
Antonio Murdaca f061d69
				"signalfd4",
Antonio Murdaca f061d69
				"sigreturn",
Antonio Murdaca f061d69
				"socket",
Antonio Murdaca f061d69
				"socketcall",
Antonio Murdaca f061d69
				"socketpair",
Antonio Murdaca f061d69
				"splice",
Antonio Murdaca f061d69
				"stat",
Antonio Murdaca f061d69
				"stat64",
Antonio Murdaca f061d69
				"statfs",
Antonio Murdaca f061d69
				"statfs64",
Antonio Murdaca f061d69
				"symlink",
Antonio Murdaca f061d69
				"symlinkat",
Antonio Murdaca f061d69
				"sync",
Antonio Murdaca f061d69
				"sync_file_range",
Antonio Murdaca f061d69
				"syncfs",
Antonio Murdaca f061d69
				"sysinfo",
Antonio Murdaca f061d69
				"syslog",
Antonio Murdaca f061d69
				"tee",
Antonio Murdaca f061d69
				"tgkill",
Antonio Murdaca f061d69
				"time",
Antonio Murdaca f061d69
				"timer_create",
Antonio Murdaca f061d69
				"timer_delete",
Antonio Murdaca f061d69
				"timerfd_create",
Antonio Murdaca f061d69
				"timerfd_gettime",
Antonio Murdaca f061d69
				"timerfd_settime",
Antonio Murdaca f061d69
				"timer_getoverrun",
Antonio Murdaca f061d69
				"timer_gettime",
Antonio Murdaca f061d69
				"timer_settime",
Antonio Murdaca f061d69
				"times",
Antonio Murdaca f061d69
				"tkill",
Antonio Murdaca f061d69
				"truncate",
Antonio Murdaca f061d69
				"truncate64",
Antonio Murdaca f061d69
				"ugetrlimit",
Antonio Murdaca f061d69
				"umask",
Antonio Murdaca f061d69
				"uname",
Antonio Murdaca f061d69
				"unlink",
Antonio Murdaca f061d69
				"unlinkat",
Antonio Murdaca f061d69
				"utime",
Antonio Murdaca f061d69
				"utimensat",
Antonio Murdaca f061d69
				"utimes",
Antonio Murdaca f061d69
				"vfork",
Antonio Murdaca f061d69
				"vmsplice",
Antonio Murdaca f061d69
				"wait4",
Antonio Murdaca f061d69
				"waitid",
Antonio Murdaca f061d69
				"waitpid",
Antonio Murdaca f061d69
				"write",
Antonio Murdaca f061d69
				"writev",
Antonio Murdaca f061d69
				"mount",
Antonio Murdaca f061d69
				"umount2",
Antonio Murdaca f061d69
				"reboot",
Antonio Murdaca f061d69
				"name_to_handle_at",
Antonio Murdaca f061d69
				"unshare"
Antonio Murdaca f061d69
			],
Antonio Murdaca f061d69
			"action": "SCMP_ACT_ALLOW",
Antonio Murdaca f061d69
			"args": [],
Antonio Murdaca f061d69
			"comment": "",
Antonio Murdaca f061d69
			"includes": {},
Antonio Murdaca f061d69
			"excludes": {}
Antonio Murdaca f061d69
		},
Antonio Murdaca f061d69
		{
Antonio Murdaca f061d69
			"names": [
Antonio Murdaca f061d69
				"personality"
Antonio Murdaca f061d69
			],
Antonio Murdaca f061d69
			"action": "SCMP_ACT_ALLOW",
Antonio Murdaca f061d69
			"args": [
Antonio Murdaca f061d69
				{
Antonio Murdaca f061d69
					"index": 0,
Antonio Murdaca f061d69
					"value": 0,
Antonio Murdaca f061d69
					"valueTwo": 0,
Antonio Murdaca f061d69
					"op": "SCMP_CMP_EQ"
Antonio Murdaca f061d69
				}
Antonio Murdaca f061d69
			],
Antonio Murdaca f061d69
			"comment": "",
Antonio Murdaca f061d69
			"includes": {},
Antonio Murdaca f061d69
			"excludes": {}
Antonio Murdaca f061d69
		},
Antonio Murdaca f061d69
		{
Antonio Murdaca f061d69
			"names": [
Antonio Murdaca f061d69
				"personality"
Antonio Murdaca f061d69
			],
Antonio Murdaca f061d69
			"action": "SCMP_ACT_ALLOW",
Antonio Murdaca f061d69
			"args": [
Antonio Murdaca f061d69
				{
Antonio Murdaca f061d69
					"index": 0,
Antonio Murdaca f061d69
					"value": 8,
Antonio Murdaca f061d69
					"valueTwo": 0,
Antonio Murdaca f061d69
					"op": "SCMP_CMP_EQ"
Antonio Murdaca f061d69
				}
Antonio Murdaca f061d69
			],
Antonio Murdaca f061d69
			"comment": "",
Antonio Murdaca f061d69
			"includes": {},
Antonio Murdaca f061d69
			"excludes": {}
Antonio Murdaca f061d69
		},
Antonio Murdaca f061d69
		{
Antonio Murdaca f061d69
			"names": [
Antonio Murdaca f061d69
				"personality"
Antonio Murdaca f061d69
			],
Antonio Murdaca f061d69
			"action": "SCMP_ACT_ALLOW",
Antonio Murdaca f061d69
			"args": [
Antonio Murdaca f061d69
				{
Antonio Murdaca f061d69
					"index": 0,
Antonio Murdaca f061d69
					"value": 4294967295,
Antonio Murdaca f061d69
					"valueTwo": 0,
Antonio Murdaca f061d69
					"op": "SCMP_CMP_EQ"
Antonio Murdaca f061d69
				}
Antonio Murdaca f061d69
			],
Antonio Murdaca f061d69
			"comment": "",
Antonio Murdaca f061d69
			"includes": {},
Antonio Murdaca f061d69
			"excludes": {}
Antonio Murdaca f061d69
		},
Antonio Murdaca f061d69
		{
Antonio Murdaca f061d69
			"names": [
Antonio Murdaca f061d69
				"breakpoint",
Antonio Murdaca f061d69
				"cacheflush",
Antonio Murdaca f061d69
				"set_tls"
Antonio Murdaca f061d69
			],
Antonio Murdaca f061d69
			"action": "SCMP_ACT_ALLOW",
Antonio Murdaca f061d69
			"args": [],
Antonio Murdaca f061d69
			"comment": "",
Antonio Murdaca f061d69
			"includes": {
Antonio Murdaca f061d69
				"arches": [
Antonio Murdaca f061d69
					"arm",
Antonio Murdaca f061d69
					"arm64"
Antonio Murdaca f061d69
				]
Antonio Murdaca f061d69
			},
Antonio Murdaca f061d69
			"excludes": {}
Antonio Murdaca f061d69
		},
Antonio Murdaca f061d69
		{
Antonio Murdaca f061d69
			"names": [
Antonio Murdaca f061d69
				"arch_prctl"
Antonio Murdaca f061d69
			],
Antonio Murdaca f061d69
			"action": "SCMP_ACT_ALLOW",
Antonio Murdaca f061d69
			"args": [],
Antonio Murdaca f061d69
			"comment": "",
Antonio Murdaca f061d69
			"includes": {
Antonio Murdaca f061d69
				"arches": [
Antonio Murdaca f061d69
					"amd64",
Antonio Murdaca f061d69
					"x32"
Antonio Murdaca f061d69
				]
Antonio Murdaca f061d69
			},
Antonio Murdaca f061d69
			"excludes": {}
Antonio Murdaca f061d69
		},
Antonio Murdaca f061d69
		{
Antonio Murdaca f061d69
			"names": [
Antonio Murdaca f061d69
				"modify_ldt"
Antonio Murdaca f061d69
			],
Antonio Murdaca f061d69
			"action": "SCMP_ACT_ALLOW",
Antonio Murdaca f061d69
			"args": [],
Antonio Murdaca f061d69
			"comment": "",
Antonio Murdaca f061d69
			"includes": {
Antonio Murdaca f061d69
				"arches": [
Antonio Murdaca f061d69
					"amd64",
Antonio Murdaca f061d69
					"x32",
Antonio Murdaca f061d69
					"x86"
Antonio Murdaca f061d69
				]
Antonio Murdaca f061d69
			},
Antonio Murdaca f061d69
			"excludes": {}
Antonio Murdaca f061d69
		},
Antonio Murdaca f061d69
		{
Antonio Murdaca f061d69
			"names": [
Antonio Murdaca f061d69
				"s390_pci_mmio_read",
Antonio Murdaca f061d69
				"s390_pci_mmio_write",
Antonio Murdaca f061d69
				"s390_runtime_instr"
Antonio Murdaca f061d69
			],
Antonio Murdaca f061d69
			"action": "SCMP_ACT_ALLOW",
Antonio Murdaca f061d69
			"args": [],
Antonio Murdaca f061d69
			"comment": "",
Antonio Murdaca f061d69
			"includes": {
Antonio Murdaca f061d69
				"arches": [
Antonio Murdaca f061d69
					"s390",
Antonio Murdaca f061d69
					"s390x"
Antonio Murdaca f061d69
				]
Antonio Murdaca f061d69
			},
Antonio Murdaca f061d69
			"excludes": {}
Antonio Murdaca f061d69
		},
Antonio Murdaca f061d69
		{
Antonio Murdaca f061d69
			"names": [
Antonio Murdaca f061d69
				"open_by_handle_at"
Antonio Murdaca f061d69
			],
Antonio Murdaca f061d69
			"action": "SCMP_ACT_ALLOW",
Antonio Murdaca f061d69
			"args": [],
Antonio Murdaca f061d69
			"comment": "",
Antonio Murdaca f061d69
			"includes": {
Antonio Murdaca f061d69
				"caps": [
Antonio Murdaca f061d69
					"CAP_DAC_READ_SEARCH"
Antonio Murdaca f061d69
				]
Antonio Murdaca f061d69
			},
Antonio Murdaca f061d69
			"excludes": {}
Antonio Murdaca f061d69
		},
Antonio Murdaca f061d69
		{
Antonio Murdaca f061d69
			"names": [
Antonio Murdaca f061d69
				"bpf",
Antonio Murdaca f061d69
				"clone",
Antonio Murdaca f061d69
				"fanotify_init",
Antonio Murdaca f061d69
				"lookup_dcookie",
Antonio Murdaca f061d69
				"mount",
Antonio Murdaca f061d69
				"name_to_handle_at",
Antonio Murdaca f061d69
				"perf_event_open",
Antonio Murdaca f061d69
				"setdomainname",
Antonio Murdaca f061d69
				"sethostname",
Antonio Murdaca f061d69
				"setns",
Antonio Murdaca f061d69
				"umount",
Antonio Murdaca f061d69
				"umount2",
Antonio Murdaca f061d69
				"unshare"
Antonio Murdaca f061d69
			],
Antonio Murdaca f061d69
			"action": "SCMP_ACT_ALLOW",
Antonio Murdaca f061d69
			"args": [],
Antonio Murdaca f061d69
			"comment": "",
Antonio Murdaca f061d69
			"includes": {
Antonio Murdaca f061d69
				"caps": [
Antonio Murdaca f061d69
					"CAP_SYS_ADMIN"
Antonio Murdaca f061d69
				]
Antonio Murdaca f061d69
			},
Antonio Murdaca f061d69
			"excludes": {}
Antonio Murdaca f061d69
		},
Antonio Murdaca f061d69
		{
Antonio Murdaca f061d69
			"names": [
Antonio Murdaca f061d69
				"clone"
Antonio Murdaca f061d69
			],
Antonio Murdaca f061d69
			"action": "SCMP_ACT_ALLOW",
Antonio Murdaca f061d69
			"args": [
Antonio Murdaca f061d69
				{
Antonio Murdaca f061d69
					"index": 0,
Antonio Murdaca f061d69
					"value": 2080505856,
Antonio Murdaca f061d69
					"valueTwo": 0,
Antonio Murdaca f061d69
					"op": "SCMP_CMP_MASKED_EQ"
Antonio Murdaca f061d69
				}
Antonio Murdaca f061d69
			],
Antonio Murdaca f061d69
			"comment": "",
Antonio Murdaca f061d69
			"includes": {},
Antonio Murdaca f061d69
			"excludes": {
Antonio Murdaca f061d69
				"caps": [
Antonio Murdaca f061d69
					"CAP_SYS_ADMIN"
Antonio Murdaca f061d69
				],
Antonio Murdaca f061d69
				"arches": [
Antonio Murdaca f061d69
					"s390",
Antonio Murdaca f061d69
					"s390x"
Antonio Murdaca f061d69
				]
Antonio Murdaca f061d69
			}
Antonio Murdaca f061d69
		},
Antonio Murdaca f061d69
		{
Antonio Murdaca f061d69
			"names": [
Antonio Murdaca f061d69
				"clone"
Antonio Murdaca f061d69
			],
Antonio Murdaca f061d69
			"action": "SCMP_ACT_ALLOW",
Antonio Murdaca f061d69
			"args": [
Antonio Murdaca f061d69
				{
Antonio Murdaca f061d69
					"index": 1,
Antonio Murdaca f061d69
					"value": 2080505856,
Antonio Murdaca f061d69
					"valueTwo": 0,
Antonio Murdaca f061d69
					"op": "SCMP_CMP_MASKED_EQ"
Antonio Murdaca f061d69
				}
Antonio Murdaca f061d69
			],
Antonio Murdaca f061d69
			"comment": "s390 parameter ordering for clone is different",
Antonio Murdaca f061d69
			"includes": {
Antonio Murdaca f061d69
				"arches": [
Antonio Murdaca f061d69
					"s390",
Antonio Murdaca f061d69
					"s390x"
Antonio Murdaca f061d69
				]
Antonio Murdaca f061d69
			},
Antonio Murdaca f061d69
			"excludes": {
Antonio Murdaca f061d69
				"caps": [
Antonio Murdaca f061d69
					"CAP_SYS_ADMIN"
Antonio Murdaca f061d69
				]
Antonio Murdaca f061d69
			}
Antonio Murdaca f061d69
		},
Antonio Murdaca f061d69
		{
Antonio Murdaca f061d69
			"names": [
Antonio Murdaca f061d69
				"reboot"
Antonio Murdaca f061d69
			],
Antonio Murdaca f061d69
			"action": "SCMP_ACT_ALLOW",
Antonio Murdaca f061d69
			"args": [],
Antonio Murdaca f061d69
			"comment": "",
Antonio Murdaca f061d69
			"includes": {
Antonio Murdaca f061d69
				"caps": [
Antonio Murdaca f061d69
					"CAP_SYS_BOOT"
Antonio Murdaca f061d69
				]
Antonio Murdaca f061d69
			},
Antonio Murdaca f061d69
			"excludes": {}
Antonio Murdaca f061d69
		},
Antonio Murdaca f061d69
		{
Antonio Murdaca f061d69
			"names": [
Antonio Murdaca f061d69
				"chroot"
Antonio Murdaca f061d69
			],
Antonio Murdaca f061d69
			"action": "SCMP_ACT_ALLOW",
Antonio Murdaca f061d69
			"args": [],
Antonio Murdaca f061d69
			"comment": "",
Antonio Murdaca f061d69
			"includes": {
Antonio Murdaca f061d69
				"caps": [
Antonio Murdaca f061d69
					"CAP_SYS_CHROOT"
Antonio Murdaca f061d69
				]
Antonio Murdaca f061d69
			},
Antonio Murdaca f061d69
			"excludes": {}
Antonio Murdaca f061d69
		},
Antonio Murdaca f061d69
		{
Antonio Murdaca f061d69
			"names": [
Antonio Murdaca f061d69
				"delete_module",
Antonio Murdaca f061d69
				"init_module",
Antonio Murdaca f061d69
				"finit_module",
Antonio Murdaca f061d69
				"query_module"
Antonio Murdaca f061d69
			],
Antonio Murdaca f061d69
			"action": "SCMP_ACT_ALLOW",
Antonio Murdaca f061d69
			"args": [],
Antonio Murdaca f061d69
			"comment": "",
Antonio Murdaca f061d69
			"includes": {
Antonio Murdaca f061d69
				"caps": [
Antonio Murdaca f061d69
					"CAP_SYS_MODULE"
Antonio Murdaca f061d69
				]
Antonio Murdaca f061d69
			},
Antonio Murdaca f061d69
			"excludes": {}
Antonio Murdaca f061d69
		},
Antonio Murdaca f061d69
		{
Antonio Murdaca f061d69
			"names": [
Antonio Murdaca f061d69
				"acct"
Antonio Murdaca f061d69
			],
Antonio Murdaca f061d69
			"action": "SCMP_ACT_ALLOW",
Antonio Murdaca f061d69
			"args": [],
Antonio Murdaca f061d69
			"comment": "",
Antonio Murdaca f061d69
			"includes": {
Antonio Murdaca f061d69
				"caps": [
Antonio Murdaca f061d69
					"CAP_SYS_PACCT"
Antonio Murdaca f061d69
				]
Antonio Murdaca f061d69
			},
Antonio Murdaca f061d69
			"excludes": {}
Antonio Murdaca f061d69
		},
Antonio Murdaca f061d69
		{
Antonio Murdaca f061d69
			"names": [
Antonio Murdaca f061d69
				"kcmp",
Antonio Murdaca f061d69
				"process_vm_readv",
Antonio Murdaca f061d69
				"process_vm_writev",
Antonio Murdaca f061d69
				"ptrace"
Antonio Murdaca f061d69
			],
Antonio Murdaca f061d69
			"action": "SCMP_ACT_ALLOW",
Antonio Murdaca f061d69
			"args": [],
Antonio Murdaca f061d69
			"comment": "",
Antonio Murdaca f061d69
			"includes": {
Antonio Murdaca f061d69
				"caps": [
Antonio Murdaca f061d69
					"CAP_SYS_PTRACE"
Antonio Murdaca f061d69
				]
Antonio Murdaca f061d69
			},
Antonio Murdaca f061d69
			"excludes": {}
Antonio Murdaca f061d69
		},
Antonio Murdaca f061d69
		{
Antonio Murdaca f061d69
			"names": [
Antonio Murdaca f061d69
				"iopl",
Antonio Murdaca f061d69
				"ioperm"
Antonio Murdaca f061d69
			],
Antonio Murdaca f061d69
			"action": "SCMP_ACT_ALLOW",
Antonio Murdaca f061d69
			"args": [],
Antonio Murdaca f061d69
			"comment": "",
Antonio Murdaca f061d69
			"includes": {
Antonio Murdaca f061d69
				"caps": [
Antonio Murdaca f061d69
					"CAP_SYS_RAWIO"
Antonio Murdaca f061d69
				]
Antonio Murdaca f061d69
			},
Antonio Murdaca f061d69
			"excludes": {}
Antonio Murdaca f061d69
		},
Antonio Murdaca f061d69
		{
Antonio Murdaca f061d69
			"names": [
Antonio Murdaca f061d69
				"settimeofday",
Antonio Murdaca f061d69
				"stime",
Antonio Murdaca f061d69
				"adjtimex"
Antonio Murdaca f061d69
			],
Antonio Murdaca f061d69
			"action": "SCMP_ACT_ALLOW",
Antonio Murdaca f061d69
			"args": [],
Antonio Murdaca f061d69
			"comment": "",
Antonio Murdaca f061d69
			"includes": {
Antonio Murdaca f061d69
				"caps": [
Antonio Murdaca f061d69
					"CAP_SYS_TIME"
Antonio Murdaca f061d69
				]
Antonio Murdaca f061d69
			},
Antonio Murdaca f061d69
			"excludes": {}
Antonio Murdaca f061d69
		},
Antonio Murdaca f061d69
		{
Antonio Murdaca f061d69
			"names": [
Antonio Murdaca f061d69
				"vhangup"
Antonio Murdaca f061d69
			],
Antonio Murdaca f061d69
			"action": "SCMP_ACT_ALLOW",
Antonio Murdaca f061d69
			"args": [],
Antonio Murdaca f061d69
			"comment": "",
Antonio Murdaca f061d69
			"includes": {
Antonio Murdaca f061d69
				"caps": [
Antonio Murdaca f061d69
					"CAP_SYS_TTY_CONFIG"
Antonio Murdaca f061d69
				]
Antonio Murdaca f061d69
			},
Antonio Murdaca f061d69
			"excludes": {}
Antonio Murdaca f061d69
		}
Antonio Murdaca f061d69
	]
eda8567
}