mirror of
https://github.com/docker/docs.git
synced 2026-03-27 14:28:47 +07:00
Merge pull request #18956 from justincormack/umount
Block original umount syscall in default seccomp filter
This commit is contained in:
@@ -316,6 +316,12 @@ var defaultSeccompProfile = &configs.Seccomp{
|
||||
Action: configs.Errno,
|
||||
Args: []*configs.Arg{},
|
||||
},
|
||||
{
|
||||
// Deny umount
|
||||
Name: "umount",
|
||||
Action: configs.Errno,
|
||||
Args: []*configs.Arg{},
|
||||
},
|
||||
{
|
||||
// Deny umount
|
||||
Name: "umount2",
|
||||
|
||||
Reference in New Issue
Block a user