2 ms·
This is more or less what seccomp is on Linux: >The only system calls that the calling thread is permitted to make are read(2), write(2), _exit(2) (but not exi
by 6yyyyyy 4y ago
This is more or less what seccomp is on Linux:
>The only system calls that the calling thread is permitted to make are read(2), write(2), _exit(2) (but not exit_group(2)), and sigreturn(2). Other system calls result in the termination of the calling thread, or termination of the entire process with the SIGKILL signal when there is only one thread. Strict secure computing mode is useful for number-crunching applications that may need to execute untrusted byte code, perhaps obtained by reading from a pipe or socket.