You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
seccomp-bpf allows you to filter which syscalls an application is allowed to use.
Firejail and bubblewrap (#62) both have seccomp support. Firejail also has a seccomp guide.
Orjail shouldn't use a very restrictive filter as that'd break many applications running inside it but it can use a simple blacklist that blocks certain dangerous syscalls.
Firejail has a default seccomp blacklist that can be enabled via the --seccomp flag. See the --seccomp part at the man page.
The text was updated successfully, but these errors were encountered:
seccomp-bpf allows you to filter which syscalls an application is allowed to use.
Firejail and bubblewrap (#62) both have seccomp support. Firejail also has a seccomp guide.
Orjail shouldn't use a very restrictive filter as that'd break many applications running inside it but it can use a simple blacklist that blocks certain dangerous syscalls.
Firejail has a default seccomp blacklist that can be enabled via the
--seccomp
flag. See the--seccomp
part at the man page.The text was updated successfully, but these errors were encountered: