umdns: convert seccomp filter rules to OCI format
[openwrt/openwrt.git] / package / network / services / umdns / files / umdns.json
index c22ba6f5fb6a6289080f6d7eaf42ec493a1b3ab2..db62f5f36de5ee56cb26de7769072651ecb1e7ce 100644 (file)
@@ -1,32 +1,43 @@
 {
-       "whitelist": [
-               "read",
-               "write",
-               "open",
-               "close",
-               "time",
-               "brk",
-               "ioctl",
-               "uname",
-               "bind",
-               "connect",
-               "getsockname",
-               "recvmsg",
-               "sendmsg",
-               "sendto",
-               "setsockopt",
-               "socket",
-               "poll",
-               "fcntl64",
-               "epoll_create",
-               "epoll_ctl",
-               "epoll_wait",
-               "rt_sigaction",
-               "sigreturn",
-               "rt_sigreturn",
-               "exit_group",
-               "exit",
-               "clock_gettime"
-       ],
-       "policy": 1
+       "defaultAction": "SCMP_ACT_KILL_PROCESS",
+       "syscalls": [
+               {
+                       "names": [
+                               "read",
+                               "write",
+                               "open",
+                               "close",
+                               "time",
+                               "brk",
+                               "ioctl",
+                               "uname",
+                               "bind",
+                               "connect",
+                               "getsockname",
+                               "recvmsg",
+                               "recvfrom",
+                               "sendmsg",
+                               "sendto",
+                               "setsockopt",
+                               "socket",
+                               "pipe",
+                               "poll",
+                               "fcntl64",
+                               "epoll_create",
+                               "epoll_create1",
+                               "epoll_ctl",
+                               "epoll_wait",
+                               "epoll_pwait",
+                               "rt_sigaction",
+                               "sigreturn",
+                               "rt_sigreturn",
+                               "rt_sigprocmask",
+                               "exit_group",
+                               "exit",
+                               "fcntl",
+                               "clock_gettime"
+                       ],
+                       "action": "SCMP_ACT_ALLOW"
+               }
+       ]
 }