|
From: Jeff D. <jd...@ad...> - 2016-05-26 13:12:29
|
On Thu, May 26, 2016 at 12:49:13AM -0700, Dan Kaminsky wrote: > So I'm curious. There is another option -- seccomp-bpf can trap on > arbitrary syscalls. Is there a reason anyone sees why UML couldn't be > routed through it? You need to be able to annull system calls. Dunno if seccomp can do that, but if it can, as well as read them out which I assume it can, you're golden. Jeff -- Jeff Dike AddToIt 978-254-0789 (o) 978-394-8986 (c) |