On Mon, Feb 15, 2016 at 10:11:41AM -0500, Mike Frysinger wrote:
> On 15 Feb 2016 17:50, Dmitry V. Levin wrote:
> > On Mon, Feb 15, 2016 at 09:30:18AM -0500, Mike Frysinger wrote:
> > > On 15 Feb 2016 15:21, Dmitry V. Levin wrote:
[...]
> > > > On entering syscall, seccomp kernel hooks are executed
On 15 Feb 2016 17:50, Dmitry V. Levin wrote:
> On Mon, Feb 15, 2016 at 09:30:18AM -0500, Mike Frysinger wrote:
> > On 15 Feb 2016 15:21, Dmitry V. Levin wrote:
> > > On Mon, Feb 15, 2016 at 12:12:09PM +0100, Pas wrote:
> > > > Thanks for the quick response and for the hint! After testing with
> >
On Mon, Feb 15, 2016 at 09:30:18AM -0500, Mike Frysinger wrote:
> On 15 Feb 2016 15:21, Dmitry V. Levin wrote:
> > On Mon, Feb 15, 2016 at 12:12:09PM +0100, Pas wrote:
> > > Thanks for the quick response and for the hint! After testing with
> > > -fveseccomp,prctl
> > > it turns out that:
> > >
>
On 15 Feb 2016 15:21, Dmitry V. Levin wrote:
> On Mon, Feb 15, 2016 at 12:12:09PM +0100, Pas wrote:
> > Thanks for the quick response and for the hint! After testing with
> > -fveseccomp,prctl
> > it turns out that:
> >
> > docker-engine 1.10.1-0~wily uses seccomp (prctl PR_SET_SECCOMP,
> >
Hi,
On Mon, Feb 15, 2016 at 12:12:09PM +0100, Pas wrote:
> Hello!
>
> Thanks for the quick response and for the hint! After testing with
> -fveseccomp,prctl
> it turns out that:
>
> docker-engine 1.10.1-0~wily uses seccomp (prctl PR_SET_SECCOMP,
> SECCOMP_MODE_FILTER and PR_CAPBSET_DROP ...),
ewselect(0, NULL, NULL, NULL, {429496729600, 429631460482}
> >
> > [pid 17144] <... _newselect resumed> ) = 0 (Timeout)
> > [pid 17144] clock_gettime(CLOCK_MONOTONIC, {940046419857770693,
> > 579195224836800512}) = 0
> > [pid 17144] clock_gettime(CLOCK_REALTIME,
esumed> ) = 0 (Timeout)
> [pid 17144] clock_gettime(CLOCK_MONOTONIC, {940046419857770693,
> 579195224836800512}) = 0
> [pid 17144] clock_gettime(CLOCK_REALTIME,
> [pid 17148] syscall_4294967295(0x1, 0x18935730, 0, 0, 0, 0xff ...>
> [pid 17144] <... clock_gettime r
, {429496729600, 429631460482}
[pid 17144] <... _newselect resumed> ) = 0 (Timeout)
[pid 17144] clock_gettime(CLOCK_MONOTONIC, {940046419857770693,
579195224836800512}) = 0
[pid 17144] clock_gettime(CLOCK_REALTIME,
[pid 17148] syscall_4294967295(0x1, 0x18935730, 0, 0, 0, 0xff
[pid 17144] &l