3 ms·
That's why I explicitly mention "whitelisting". If you just want to ban some obscure syscalls and call it a day, you can do that. It will probably even be help
by fefe23 4y ago
That's why I explicitly mention "whitelisting".
If you just want to ban some obscure syscalls and call it a day, you can do that.
It will probably even be helpful to some degree.
I personally think our aspirations should be higher than "let's ban ptrace(2)".
- mmis1000 4y agoIt's actually a bit more than that. The syscall docker allowed isn't really fixed. It is affected by what linux capabilities the container had granted. Like: if you whitelist the container about CAP_SYS_PTRACE, you probably also want ptrace(2) to be whitelisted. Instead of a all or nothing/your program will still break even cap added model.