Conversation

It's available to an attacker outside of a very lean sandbox where loading a seccomp-bpf filter isn't allowed. It's both possible and sensible for seccomp-bpf filters to be layered. It makes sense to use a weak filter for a generic app sandbox and then proper strict ones inside.
1
1
Show replies