From 14f4b1b568907350d023d1429c1aa4aaa8925f22 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Cristian=20Rodr=C3=ADguez?= Date: Fri, 9 Jul 2021 17:19:05 -0400 Subject: [PATCH] malloc() uses getrandom now glibc master uses getrandom in malloc since https://sourceware.org/git/?p=glibc.git;a=commit;h=fc859c304898a5ec72e0ba5269ed136ed0ea10e1 , getrandom should be in the default set so to avoid all non trivial programs to fallback to a PRNG. --- src/shared/seccomp-util.c | 1 + 1 file changed, 1 insertion(+) diff --git a/src/shared/seccomp-util.c b/src/shared/seccomp-util.c index e0f88aec73a..cad0af89f26 100644 --- a/src/shared/seccomp-util.c +++ b/src/shared/seccomp-util.c @@ -310,6 +310,7 @@ const SyscallFilterSet syscall_filter_sets[_SYSCALL_FILTER_SET_MAX] = { "getpgrp\0" "getpid\0" "getppid\0" + "getrandom\0" "getresgid\0" "getresgid32\0" "getresuid\0"