Lines 220-231
enable_sandbox_full(void)
Link Here
|
220 |
ALLOW_RULE(rt_sigreturn); |
220 |
ALLOW_RULE(rt_sigreturn); |
221 |
ALLOW_RULE(select); |
221 |
ALLOW_RULE(select); |
222 |
ALLOW_RULE(stat); |
222 |
ALLOW_RULE(stat); |
|
|
223 |
ALLOW_RULE(statx); |
223 |
ALLOW_RULE(stat64); |
224 |
ALLOW_RULE(stat64); |
224 |
ALLOW_RULE(sysinfo); |
225 |
ALLOW_RULE(sysinfo); |
225 |
ALLOW_RULE(umask); // Used in file_pipe2file() |
226 |
ALLOW_RULE(umask); // Used in file_pipe2file() |
226 |
ALLOW_RULE(getpid); // Used by glibc in file_pipe2file() |
227 |
ALLOW_RULE(getpid); // Used by glibc in file_pipe2file() |
227 |
ALLOW_RULE(unlink); |
228 |
ALLOW_RULE(unlink); |
228 |
ALLOW_RULE(write); |
229 |
ALLOW_RULE(write); |
|
|
230 |
ALLOW_RULE(writev); |
229 |
|
231 |
|
230 |
// needed by Gentoo's portage sandbox |
232 |
// needed by Gentoo's portage sandbox |
231 |
ALLOW_RULE(getcwd); |
233 |
ALLOW_RULE(getcwd); |