2 ms·
That also means that if you used seccomp to restrict mprotect syscall, the child process may never ever write again, which is an unfortunate design choice.
by enedil 5y ago
That also means that if you used seccomp to restrict mprotect syscall, the child process may never ever write again, which is an unfortunate design choice.
- magicalhippo 5y agoSeccomp can check for the PROT_EXEC flag though, and let the others pass, no?