-
Notifications
You must be signed in to change notification settings - Fork 70
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
remove @resources from SystemCallFilter #322
remove @resources from SystemCallFilter #322
Conversation
Signed-off-by: morph027 <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hey @morph027, thanks for tracking down this issue!
I can't say I'm surprised, as the hardening measures were on the strict side, but I'm happy to know that everything else doesn't seem to create issues.
LGTM!
It's a bit odd that I didn't find this issue in my setup, but maybe the usage of some new syscall has been introduced in the latest release. Sorry for the issues I caused :) |
NP ;) Better safe than sorry in terms of security. |
Thanks! |
This PR contains the following updates: | Package | Update | Change | |---|---|---| | [strukturag/nextcloud-spreed-signaling](https://github.com/strukturag/nextcloud-spreed-signaling) | minor | `v1.0.0` -> `v1.1.1` | --- ### Release Notes <details> <summary>strukturag/nextcloud-spreed-signaling</summary> ### [`v1.1.1`](https://github.com/strukturag/nextcloud-spreed-signaling/releases/tag/v1.1.1) [Compare Source](strukturag/nextcloud-spreed-signaling@v1.1.0...v1.1.1) Required to fix a build issue in the Docker images of 1.1.0. No other changes. ##### Fixed - Fix Docker images. [#​425](strukturag/nextcloud-spreed-signaling#425) ### [`v1.1.0`](https://github.com/strukturag/nextcloud-spreed-signaling/releases/tag/v1.1.0) [Compare Source](strukturag/nextcloud-spreed-signaling@v1.0.0...v1.1.0) ##### Added - Official docker images. [#​314](strukturag/nextcloud-spreed-signaling#314) - Use proxy from environment for backend client requests. [#​326](strukturag/nextcloud-spreed-signaling#326) - Add aarch64/arm64 docker build [#​384](strukturag/nextcloud-spreed-signaling#384) - CI: Setup permissions for workflows. [#​393](strukturag/nextcloud-spreed-signaling#393) - Implement "switchto" support [#​409](strukturag/nextcloud-spreed-signaling#409) - Allow internal clients to set / change the "inCall" flags. [#​421](strukturag/nextcloud-spreed-signaling#421) - Add support for Golang 1.20 [#​413](strukturag/nextcloud-spreed-signaling#413) ##### Changed - Switch to apt-get on CLI. [#​312](strukturag/nextcloud-spreed-signaling#312) - vendor: Automatically vendor protobuf modules. [#​313](strukturag/nextcloud-spreed-signaling#313) - Bump github.com/prometheus/client_golang from 1.12.2 to 1.13.0 [#​316](strukturag/nextcloud-spreed-signaling#316) - Bump github.com/oschwald/maxminddb-golang from 1.9.0 to 1.10.0 [#​317](strukturag/nextcloud-spreed-signaling#317) - Bump github.com/pion/sdp/v3 from 3.0.5 to 3.0.6 [#​320](strukturag/nextcloud-spreed-signaling#320) - Bump google.golang.org/grpc from 1.48.0 to 1.49.0 [#​324](strukturag/nextcloud-spreed-signaling#324) - Bump github.com/nats-io/nats-server/v2 from 2.8.4 to 2.9.0 [#​330](strukturag/nextcloud-spreed-signaling#330) - Bump sphinx from 5.1.1 to 5.2.2 in /docs [#​339](strukturag/nextcloud-spreed-signaling#339) - Bump mkdocs from 1.3.1 to 1.4.0 in /docs [#​340](strukturag/nextcloud-spreed-signaling#340) - Bump sphinx from 5.2.2 to 5.2.3 in /docs [#​345](strukturag/nextcloud-spreed-signaling#345) - Bump github.com/nats-io/nats-server/v2 from 2.9.0 to 2.9.2 [#​344](strukturag/nextcloud-spreed-signaling#344) - Bump go.etcd.io/etcd/api/v3 from 3.5.4 to 3.5.5 [#​333](strukturag/nextcloud-spreed-signaling#333) - Bump go.etcd.io/etcd/server/v3 from 3.5.4 to 3.5.5 [#​334](strukturag/nextcloud-spreed-signaling#334) - Bump google.golang.org/grpc from 1.49.0 to 1.50.0 [#​346](strukturag/nextcloud-spreed-signaling#346) - Bump github.com/nats-io/nats-server/v2 from 2.9.2 to 2.9.3 [#​348](strukturag/nextcloud-spreed-signaling#348) - Bump github.com/nats-io/nats.go from 1.17.0 to 1.18.0 [#​349](strukturag/nextcloud-spreed-signaling#349) - Bump sphinx from 5.2.3 to 5.3.0 in /docs [#​351](strukturag/nextcloud-spreed-signaling#351) - Bump mkdocs from 1.4.0 to 1.4.1 in /docs [#​352](strukturag/nextcloud-spreed-signaling#352) - Bump google.golang.org/grpc from 1.50.0 to 1.50.1 [#​350](strukturag/nextcloud-spreed-signaling#350) - Bump golangci/golangci-lint-action from 3.2.0 to 3.3.0 [#​353](strukturag/nextcloud-spreed-signaling#353) - Bump mkdocs from 1.4.1 to 1.4.2 in /docs [#​358](strukturag/nextcloud-spreed-signaling#358) - Bump sphinx-rtd-theme from 1.0.0 to 1.1.0 in /docs [#​357](strukturag/nextcloud-spreed-signaling#357) - Bump github.com/nats-io/nats.go from 1.18.0 to 1.19.0 [#​354](strukturag/nextcloud-spreed-signaling#354) - Bump github.com/prometheus/client_golang from 1.13.0 to 1.13.1 [#​360](strukturag/nextcloud-spreed-signaling#360) - Bump github.com/nats-io/nats-server/v2 from 2.9.3 to 2.9.5 [#​359](strukturag/nextcloud-spreed-signaling#359) - build(deps): Bump golangci/golangci-lint-action from 3.3.0 to 3.3.1 [#​365](strukturag/nextcloud-spreed-signaling#365) - build(deps): Bump sphinx-rtd-theme from 1.1.0 to 1.1.1 in /docs [#​363](strukturag/nextcloud-spreed-signaling#363) - build(deps): Bump github.com/nats-io/nats-server/v2 from 2.9.5 to 2.9.6 [#​361](strukturag/nextcloud-spreed-signaling#361) - build(deps): Bump github.com/nats-io/nats.go from 1.19.0 to 1.20.0 [#​366](strukturag/nextcloud-spreed-signaling#366) - build(deps): Bump google.golang.org/grpc from 1.50.1 to 1.51.0 [#​368](strukturag/nextcloud-spreed-signaling#368) - build(deps): Bump github.com/prometheus/client_golang from 1.13.1 to 1.14.0 [#​364](strukturag/nextcloud-spreed-signaling#364) - build(deps): Bump github.com/nats-io/nats-server/v2 from 2.9.6 to 2.9.7 [#​367](strukturag/nextcloud-spreed-signaling#367) - build(deps): Bump go.etcd.io/etcd/server/v3 from 3.5.5 to 3.5.6 [#​372](strukturag/nextcloud-spreed-signaling#372) - build(deps): Bump github.com/nats-io/nats-server/v2 from 2.9.7 to 2.9.8 [#​371](strukturag/nextcloud-spreed-signaling#371) - build(deps): Bump github.com/nats-io/nats.go from 1.20.0 to 1.21.0 [#​375](strukturag/nextcloud-spreed-signaling#375) - build(deps): Bump github.com/golang-jwt/jwt/v4 from 4.4.2 to 4.4.3 [#​374](strukturag/nextcloud-spreed-signaling#374) - build(deps): Bump cirrus-actions/rebase from 1.7 to 1.8 [#​379](strukturag/nextcloud-spreed-signaling#379) - build(deps): Bump github.com/nats-io/nats-server/v2 from 2.9.8 to 2.9.9 [#​377](strukturag/nextcloud-spreed-signaling#377) - build(deps): Bump github.com/nats-io/nats-server/v2 from 2.9.9 to 2.9.10 [#​382](strukturag/nextcloud-spreed-signaling#382) - build(deps): Bump github.com/nats-io/nats.go from 1.21.0 to 1.22.1 [#​383](strukturag/nextcloud-spreed-signaling#383) - build(deps): Bump google.golang.org/grpc from 1.51.0 to 1.52.0 [#​391](strukturag/nextcloud-spreed-signaling#391) - build(deps): Bump github.com/nats-io/nats-server/v2 from 2.9.10 to 2.9.11 [#​387](strukturag/nextcloud-spreed-signaling#387) - Stop using WaitGroup to detect finished message processing. [#​394](strukturag/nextcloud-spreed-signaling#394) - Improve handling of throttled responses from Nextcloud. [#​395](strukturag/nextcloud-spreed-signaling#395) - Test: add timeout while waiting for etcd event. [#​397](strukturag/nextcloud-spreed-signaling#397) - build(deps): Bump github.com/nats-io/nats.go from 1.22.1 to 1.23.0 [#​399](strukturag/nextcloud-spreed-signaling#399) - build(deps): Bump go.etcd.io/etcd/api/v3 from 3.5.6 to 3.5.7 [#​402](strukturag/nextcloud-spreed-signaling#402) - build(deps): Bump go.etcd.io/etcd/client/v3 from 3.5.6 to 3.5.7 [#​403](strukturag/nextcloud-spreed-signaling#403) - build(deps): Bump go.etcd.io/etcd/server/v3 from 3.5.6 to 3.5.7 [#​404](strukturag/nextcloud-spreed-signaling#404) - build(deps): Bump golangci/golangci-lint-action from 3.3.1 to 3.4.0 [#​405](strukturag/nextcloud-spreed-signaling#405) - build(deps): Bump readthedocs-sphinx-search from 0.1.2 to 0.2.0 in /docs [#​407](strukturag/nextcloud-spreed-signaling#407) - build(deps): Bump google.golang.org/grpc from 1.52.0 to 1.52.1 [#​406](strukturag/nextcloud-spreed-signaling#406) - build(deps): Bump docker/build-push-action from 3 to 4 [#​412](strukturag/nextcloud-spreed-signaling#412) - build(deps): Bump google.golang.org/grpc from 1.52.1 to 1.52.3 [#​410](strukturag/nextcloud-spreed-signaling#410) - Explicitly use type "sysConn". [#​416](strukturag/nextcloud-spreed-signaling#416) - build(deps): Bump github.com/nats-io/nats-server/v2 from 2.9.11 to 2.9.14 [#​415](strukturag/nextcloud-spreed-signaling#415) - build(deps): Bump sphinx-rtd-theme from 1.1.1 to 1.2.0 in /docs [#​418](strukturag/nextcloud-spreed-signaling#418) - build(deps): Bump google.golang.org/grpc from 1.52.3 to 1.53.0 [#​417](strukturag/nextcloud-spreed-signaling#417) - build(deps): Bump golang.org/x/net from 0.5.0 to 0.7.0 [#​422](strukturag/nextcloud-spreed-signaling#422) - build(deps): Bump github.com/golang-jwt/jwt/v4 from 4.4.3 to 4.5.0 [#​423](strukturag/nextcloud-spreed-signaling#423) - build(deps): Bump sphinx from 5.3.0 to 6.1.3 in /docs [#​390](strukturag/nextcloud-spreed-signaling#390) - Various refactorings to simplify code [#​400](strukturag/nextcloud-spreed-signaling#400) ##### Fixed - Remove [@​resources](https://github.com/resources) from SystemCallFilter [#​322](strukturag/nextcloud-spreed-signaling#322) - Fix deadlock for proxy connection issues [#​327](strukturag/nextcloud-spreed-signaling#327) - Fix goroutines leak check. [#​396](strukturag/nextcloud-spreed-signaling#396) </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNC4xNDYuMSIsInVwZGF0ZWRJblZlciI6IjM0LjE0Ni4xIn0=--> Reviewed-on: https://git.walbeck.it/walbeck-it/docker-nextcloud-spreed-signaling/pulls/285 Co-authored-by: renovate-bot <[email protected]> Co-committed-by: renovate-bot <[email protected]>
Introduced in #276.
As @Tachi107 left a comment about
ProcSubset
, i tested the other way around and leave ´@resourcesin place while removing
ProcSubset=pid`, still does not work.