From ccc16c7842a144af5df6accbb2f01281ee0d3129 Mon Sep 17 00:00:00 2001 From: Lennart Poettering Date: Mon, 29 Apr 2019 12:03:58 +0200 Subject: [PATCH] core: prefer SCMP_ACT_KILL_PROCESS for SystemCallFilter= behaviour If we have it, use it. It makes a ton more sense. Fixes: #11967 --- src/core/execute.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/core/execute.c b/src/core/execute.c index 9975de1ff59..e90c3ac4f38 100644 --- a/src/core/execute.c +++ b/src/core/execute.c @@ -1439,7 +1439,7 @@ static int apply_syscall_filter(const Unit* u, const ExecContext *c, bool needs_ if (skip_seccomp_unavailable(u, "SystemCallFilter=")) return 0; - negative_action = c->syscall_errno == 0 ? SCMP_ACT_KILL : SCMP_ACT_ERRNO(c->syscall_errno); + negative_action = c->syscall_errno == 0 ? scmp_act_kill_process() : SCMP_ACT_ERRNO(c->syscall_errno); if (c->syscall_whitelist) { default_action = negative_action;