3 ms·
Also, if you don't trust it, just set everything to SECCOMP_RET_TRACE, which kills the process if there is no ptracer A small correction, it causes for the sys
by jagger11 8y ago
Also, if you don't trust it, just set everything to SECCOMP_RET_TRACE, which kills the process if there is no ptracer
A small correction, it causes for the syscall not to be executed, and return with errno==ENOSYS
- geofft 8y agoOh, thanks. (It's still safe, because the inability to execute system calls basically translates into an inability to do anything the process was not previously authorized to do via... mmapped memory, and I think that's it.)