You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: config-linux.md
+31-16Lines changed: 31 additions & 16 deletions
Original file line number
Diff line number
Diff line change
@@ -498,7 +498,14 @@ For more information about Seccomp, see [Seccomp][seccomp] kernel documentation.
498
498
The actions, architectures, and operators are strings that match the definitions in seccomp.h from [libseccomp][] and are translated to corresponding values.
499
499
A valid list of constants as of libseccomp v2.3.2 is shown below.
500
500
501
-
Architecture Constants
501
+
**`seccomp`** (object, OPTIONAL)
502
+
503
+
The following parameters can be specified to setup seccomp:
504
+
505
+
***`defaultAction`***(string, REQUIRED)* - the default action for seccomp.
506
+
507
+
***`architectures`***(array, OPTIONAL)* - the architecture used for system calls. Implementations MUST support at least the following values:
508
+
502
509
*`SCMP_ARCH_X86`
503
510
*`SCMP_ARCH_X86_64`
504
511
*`SCMP_ARCH_X32`
@@ -518,21 +525,29 @@ Architecture Constants
518
525
*`SCMP_ARCH_PARISC`
519
526
*`SCMP_ARCH_PARISC64`
520
527
521
-
Action Constants:
522
-
*`SCMP_ACT_KILL`
523
-
*`SCMP_ACT_TRAP`
524
-
*`SCMP_ACT_ERRNO`
525
-
*`SCMP_ACT_TRACE`
526
-
*`SCMP_ACT_ALLOW`
527
-
528
-
Operator Constants:
529
-
*`SCMP_CMP_NE`
530
-
*`SCMP_CMP_LT`
531
-
*`SCMP_CMP_LE`
532
-
*`SCMP_CMP_EQ`
533
-
*`SCMP_CMP_GE`
534
-
*`SCMP_CMP_GT`
535
-
*`SCMP_CMP_MASKED_EQ`
528
+
***`syscalls`***(object, REQUIRED)* - match a syscall in seccomp.
529
+
530
+
***`names`***(array of strings, REQUIRED)* - the name of the syscall.
531
+
532
+
***`action`***(string, REQUIRED)* - the action for seccomp rules. Implementations MUST support at least the following values:
533
+
534
+
*`SCMP_ACT_KILL`
535
+
*`SCMP_ACT_TRAP`
536
+
*`SCMP_ACT_ERRNO`
537
+
*`SCMP_ACT_TRACE`
538
+
*`SCMP_ACT_ALLOW`
539
+
540
+
***`args`***(object, OPTIONAL)* - the specific syscall in seccomp.
541
+
542
+
***`op`***(string, REQUIRED)* - the operator for syscall arguments in seccomp. Implementations MUST support at least the following values:
0 commit comments