4 ms·
> fully generic approaches for syscall filtering, such as BPF How do you constrain filesystem access to be under a list of allowed directories using BPF? I br
by floatboth 8y ago
> fully generic approaches for syscall filtering, such as BPF
How do you constrain filesystem access to be under a list of allowed directories using BPF?
I briefly looked at it, and there doesn't seem to be a good way to manipulate strings. Everyone seems to be using chroot / bind mounts for that on Linux, which adds crap lines to `mount` output.