3 ms·
Their point about test coverage is that you don't know what syscalls will be made, or with what arguments, without running the program with enough coverage to f
by staticassertion 4y ago
Their point about test coverage is that you don't know what syscalls will be made, or with what arguments, without running the program with enough coverage to find out.
This is probably the most well known issue with sandboxing - maintaining the sandbox. It's especially hard with seccomp, because you could upgrade your distro, or a dependency, and suddenly you're making a different system call.