diff --git a/man2/ptrace.2 b/man2/ptrace.2 index 47c96b1c2..5cb426ab8 100644 --- a/man2/ptrace.2 +++ b/man2/ptrace.2 @@ -593,14 +593,18 @@ The seccomp event message data (from the portion of the seccomp filter rule) can be retrieved with .BR PTRACE_GETEVENTMSG . .TP -.BR PTRACE_O_SUSPEND_SECCOMP " (since Linux 4.2)" -Suspend the tracee's seccomp protections. This applies regardless of mode, and -can be used when the tracee has not yet installed seccomp filters. That is, a -valid usecase is to suspend a tracee's seccomp protections before they are -installed by the tracee, let the tracee install the filters, and then clear -this flag when the filters should be resumed. Setting this option requires that -the tracer have -.BR CAP_SYS_ADMIN , +.BR PTRACE_O_SUSPEND_SECCOMP " (since Linux 4.3)" +.\" commit 13c4a90119d28cfcb6b5bdd820c233b86c2b0237 +Suspend the tracee's seccomp protections. +This applies regardless of mode, and +can be used when the tracee has not yet installed seccomp filters. +That is, a valid use case is to suspend a tracee's seccomp protections +before they are installed by the tracee, +let the tracee install the filters, +and then clear this flag when the filters should be resumed. +Setting this option requires that the tracer have the +.BR CAP_SYS_ADMIN +capability, not have any seccomp protections installed, and not have .BR PTRACE_O_SUSPEND_SECCOMP set on itself.