tech:kernel_linux_syscall
Différences
Ci-dessous, les différences entre deux révisions de la page.
| Les deux révisions précédentesRévision précédente | |||
| tech:kernel_linux_syscall [2025/10/24 09:54] – Jean-Baptiste | tech:kernel_linux_syscall [2026/06/07 19:12] (Version actuelle) – modification externe 127.0.0.1 | ||
|---|---|---|---|
| Ligne 1: | Ligne 1: | ||
| + | < | ||
| + | {{tag> | ||
| + | |||
| + | # Kernel Linux syscall | ||
| + | |||
| + | |||
| + | Voir : | ||
| + | * seccomp | ||
| + | * [[Pb Docker RHEL CentOS 5 et 6]] | ||
| + | * https:// | ||
| + | |||
| + | |||
| + | ## Liste des tous les syscalls | ||
| + | |||
| + | Avec SystemD | ||
| + | ~~~bash | ||
| + | systemd-analyze syscall-filter | ||
| + | ~~~ | ||
| + | |||
| + | Avec AuditD | ||
| + | ~~~bash | ||
| + | ausyscall --dump | ||
| + | ~~~ | ||
| + | |||
| + | |||
| + | |||
| + | ## Liste des appels systèmes bloqué par défaut par Docker | ||
| + | |||
| + | Source : https:// | ||
| + | |||
| + | Significant syscalls blocked by the default profile | ||
| + | Docker' | ||
| + | |||
| + | ~~~ | ||
| + | Syscall Description | ||
| + | acct Accounting syscall which could let containers disable their own resource limits or process accounting. Also gated by CAP_SYS_PACCT. | ||
| + | add_key Prevent containers from using the kernel keyring, which is not namespaced. | ||
| + | bpf Deny loading potentially persistent bpf programs into kernel, already gated by CAP_SYS_ADMIN. | ||
| + | clock_adjtime Time/ | ||
| + | clock_settime Time/ | ||
| + | clone Deny cloning new namespaces. Also gated by CAP_SYS_ADMIN for CLONE_* flags, except CLONE_NEWUSER. | ||
| + | create_module Deny manipulation and functions on kernel modules. Obsolete. Also gated by CAP_SYS_MODULE. | ||
| + | delete_module Deny manipulation and functions on kernel modules. Also gated by CAP_SYS_MODULE. | ||
| + | finit_module Deny manipulation and functions on kernel modules. Also gated by CAP_SYS_MODULE. | ||
| + | get_kernel_syms Deny retrieval of exported kernel and module symbols. Obsolete. | ||
| + | get_mempolicy Syscall that modifies kernel memory and NUMA settings. Already gated by CAP_SYS_NICE. | ||
| + | init_module Deny manipulation and functions on kernel modules. Also gated by CAP_SYS_MODULE. | ||
| + | ioperm Prevent containers from modifying kernel I/O privilege levels. Already gated by CAP_SYS_RAWIO. | ||
| + | iopl Prevent containers from modifying kernel I/O privilege levels. Already gated by CAP_SYS_RAWIO. | ||
| + | kcmp Restrict process inspection capabilities, | ||
| + | kexec_file_load Sister syscall of kexec_load that does the same thing, slightly different arguments. Also gated by CAP_SYS_BOOT. | ||
| + | kexec_load Deny loading a new kernel for later execution. Also gated by CAP_SYS_BOOT. | ||
| + | keyctl Prevent containers from using the kernel keyring, which is not namespaced. | ||
| + | lookup_dcookie Tracing/ | ||
| + | mbind Syscall that modifies kernel memory and NUMA settings. Already gated by CAP_SYS_NICE. | ||
| + | mount Deny mounting, already gated by CAP_SYS_ADMIN. | ||
| + | move_pages Syscall that modifies kernel memory and NUMA settings. | ||
| + | nfsservctl Deny interaction with the kernel nfs daemon. Obsolete since Linux 3.1. | ||
| + | open_by_handle_at Cause of an old container breakout. Also gated by CAP_DAC_READ_SEARCH. | ||
| + | perf_event_open Tracing/ | ||
| + | personality Prevent container from enabling BSD emulation. Not inherently dangerous, but poorly tested, potential for a lot of kernel vulns. | ||
| + | pivot_root Deny pivot_root, should be privileged operation. | ||
| + | process_vm_readv Restrict process inspection capabilities, | ||
| + | process_vm_writev Restrict process inspection capabilities, | ||
| + | ptrace Tracing/ | ||
| + | query_module Deny manipulation and functions on kernel modules. Obsolete. | ||
| + | quotactl Quota syscall which could let containers disable their own resource limits or process accounting. Also gated by CAP_SYS_ADMIN. | ||
| + | reboot Don' | ||
| + | request_key Prevent containers from using the kernel keyring, which is not namespaced. | ||
| + | set_mempolicy Syscall that modifies kernel memory and NUMA settings. Already gated by CAP_SYS_NICE. | ||
| + | setns Deny associating a thread with a namespace. Also gated by CAP_SYS_ADMIN. | ||
| + | settimeofday Time/ | ||
| + | stime Time/ | ||
| + | swapon Deny start/stop swapping to file/ | ||
| + | swapoff Deny start/stop swapping to file/ | ||
| + | sysfs Obsolete syscall. | ||
| + | _sysctl Obsolete, | ||
| + | umount Should be a privileged operation. Also gated by CAP_SYS_ADMIN. | ||
| + | umount2 Should be a privileged operation. Also gated by CAP_SYS_ADMIN. | ||
| + | unshare Deny cloning new namespaces for processes. Also gated by CAP_SYS_ADMIN, | ||
| + | uselib Older syscall related to shared libraries, unused for a long time. | ||
| + | userfaultfd Userspace page fault handling, largely needed for process migration. | ||
| + | ustat Obsolete syscall. | ||
| + | vm86 In kernel x86 real mode virtual machine. Also gated by CAP_SYS_ADMIN. | ||
| + | vm86old In kernel x86 real mode virtual machine. Also gated by CAP_SYS_ADMIN. | ||
| + | ~~~ | ||
| + | |||
| + | |||
| + | |||
| + | ## SystemD | ||
| + | |||
| + | ### Service | ||
| + | |||
| + | ~~~ini | ||
| + | [Service] | ||
| + | SystemCallArchitectures=native | ||
| + | |||
| + | # Only permit system calls used by common system services, excluding any special purpose calls | ||
| + | SystemCallFilter=@system-service | ||
| + | ~~~ | ||
