3 ms·
This is neat but I am still partial to slower but fully generic approaches for syscall filtering, such as BPF. Sooner or later you run out of clever English ve
by rphlx 8y ago
This is neat but I am still partial to slower but fully generic approaches for syscall filtering, such as BPF.
Sooner or later you run out of clever English verbs for the plethora of fixed-function ones.
- floatboth 8y ago> fully generic approaches for syscall filtering, such as BPF How do you constrain filesystem access to be under a list of allowed directories using BPF? I briefly looked at it, and there doesn't seem to be a good way to manipulate strings. Everyone seems to be using chroot / bind mounts for that on Linux, which adds crap lines to `mount` output.