|
--- seccompsandbox.c.orig
|
|
+++ seccompsandbox.c
|
|
@@ -286,6 +286,9 @@
|
|
static void
|
|
seccomp_sandbox_setup_base()
|
|
{
|
|
+ /* allow getrandom. */
|
|
+ allow_nr(__NR_getrandom);
|
|
+
|
|
/* Simple reads and writes on existing descriptors. */
|
|
allow_nr(__NR_read);
|
|
allow_nr(__NR_write);
|