Seccomp

Seccomp Profiles and Syscall Filtering

Seccomp (secure computing mode) attaches a BPF filter to a process that the kernel consults on every system call. Docker 514 's built-in default profile blocks about 44 of the 300-plus calls, including keyctl, bpf and, without CAP_SYS_ADMIN, unshare and mount: the calls most often used to escape. docker info lists it as name=seccomp,profile=builtin. A custom profile is a JSON file:

no-chmod.json: allow everything except changing file modesJSON
{"defaultAction": "SCMP_ACT_ALLOW",
 "syscalls": [{"names": ["chmod", "fchmod", "fchmodat", "fchmodat2"],
               "action": "SCMP_ACT_ERRNO"}]}
The default profile, no profile, and the custom oneShell
docker run --rm alpine:3 unshare -r id
docker run --rm --security-opt seccomp=unconfined alpine:3 unshare -r id -u
docker run --rm --security-opt seccomp=no-chmod.json alpine:3 sh -c 'touch f && chmod 600 f'
docker run --rm alpine:3 grep Seccomp: /proc/self/status
Output
unshare: unshare(0x10000000): Operation not permitted
0
chmod: f: Operation not permitted
Seccomp:        2

The default profile stopped a new user namespace; unconfined removed the filter and the same command became root in a namespace of its own; the custom profile turned chmod into EPERM. Seccomp: 2 means filter mode is on. Real profiles work the other way round, denying by default with an allow list; start from Docker's default profile in the moby repository, and never ship seccomp=unconfined.