This file is indexed.

/usr/share/doc/lxc/examples/seccomp-v2.conf is in lxc 1:1.0.6-6+deb8u6.

This file is owned by root:root, with mode 0o644.

The actual contents of the file can be viewed below.

 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
2
whitelist trap
# 'whitelist' would normally mean kill a task doing any syscall which is not
# whitelisted below.  By appending 'trap' to the line, we will cause a SIGSYS
# to be sent to the task instead.  'errno 0' would  mean don't allow the system
# call but immediately return 0.  'errno 22' would mean return EINVAL immediately.
[x86_64]
open
close
read
write
mount
umount2
# Since we are listing system calls by name, we can also ask to have them resolved
# for another arch, i.e. for 32/64-bit versions.
[x86]
open
close
read
write
mount
umount2
# Do note that this policy does not whitelist enough system calls to allow a
# system container to boot.