@hughsie @pid_eins it's not documented, but you can see the list here: https://github.com/systemd/systemd/blob/bf49f3bb441b58c40b3e595bc5a5561051719d1c/src/shared/seccomp-util.c#L884
and yes, that includes mlock
@hughsie @pid_eins it's not documented, but you can see the list here: https://github.com/systemd/systemd/blob/bf49f3bb441b58c40b3e595bc5a5561051719d1c/src/shared/seccomp-util.c#L884
and yes, that includes mlock
@pid_eins is it expected a service can do mlock() when it has just allow-listed SystemCallFilter=@system-service? I couldn't find any docs on what caps system-service actually maps to.
We're trying to move from denying-listing caps to allow-listing in #fwupd. Thanks!
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.