seccomp: explain why we use setuid rather than @setuid in @privileged
authorLennart Poettering <lennart@poettering.net>
Wed, 18 Apr 2018 19:45:44 +0000 (21:45 +0200)
committerLennart Poettering <lennart@poettering.net>
Thu, 14 Jun 2018 15:44:20 +0000 (17:44 +0200)
src/shared/seccomp-util.c

index 4a02d8c..c433cb9 100644 (file)
@@ -632,7 +632,7 @@ const SyscallFilterSet syscall_filter_sets[_SYSCALL_FILTER_SET_MAX] = {
                 "setresuid32\0"
                 "setreuid\0"
                 "setreuid32\0"
-                "setuid\0"
+                "setuid\0"      /* We list the explicit system calls here, as @setuid also includes setgid() which is not necessarily privileged */
                 "setuid32\0"
                 "vhangup\0"
         },