3 ms·
Non-root can use seccomp-bpf. Chrome already does.
by boustrophedon 3y ago
Non-root can use seccomp-bpf. Chrome already does.
- londons_explore 3y agoSo theres nothing preventing OP implementing what they want entirely in userspace with no kernel changes already?
- jagrsw 3y agomalloc can use mmap (aside from s/brk) - it's impossible these days to sandbox any more complex program and not allow mmap (arguments can be limited though to only a subset of flags).
- londons_explore 3y agoBut that would be the same for both this proposed mseal() and my proposed seccomp solution.