mirror of https://github.com/docker/docs.git
Update seccomp.md
This commit is contained in:
parent
970338ff45
commit
d035738408
|
@ -26,7 +26,7 @@ protective while providing wide application compatibility. The default Docker
|
||||||
profile can be found
|
profile can be found
|
||||||
[here](https://github.com/moby/moby/blob/master/profiles/seccomp/default.json).
|
[here](https://github.com/moby/moby/blob/master/profiles/seccomp/default.json).
|
||||||
|
|
||||||
In effect, the profile is a allowlist which denies access to system calls by
|
In effect, the profile is an allowlist which denies access to system calls by
|
||||||
default, then allowlists specific system calls. The profile works by defining a
|
default, then allowlists specific system calls. The profile works by defining a
|
||||||
`defaultAction` of `SCMP_ACT_ERRNO` and overriding that action only for specific
|
`defaultAction` of `SCMP_ACT_ERRNO` and overriding that action only for specific
|
||||||
system calls. The effect of `SCMP_ACT_ERRNO` is to cause a `Permission Denied`
|
system calls. The effect of `SCMP_ACT_ERRNO` is to cause a `Permission Denied`
|
||||||
|
@ -117,4 +117,4 @@ profile.
|
||||||
```console
|
```console
|
||||||
$ docker run --rm -it --security-opt seccomp=unconfined debian:jessie \
|
$ docker run --rm -it --security-opt seccomp=unconfined debian:jessie \
|
||||||
unshare --map-root-user --user sh -c whoami
|
unshare --map-root-user --user sh -c whoami
|
||||||
```
|
```
|
||||||
|
|
Loading…
Reference in New Issue