Comment by awirth
9 years ago
Ditto for the seccomp syscall (and args) blacklist, although I wouldn't describe it as "worrying" considering the disclaimer at the top. Jess Frazelle's contained.af uses a seccomp whitelist[1], which doesn't need to be that long to allow reasonable programs to execute.
This is a very good piece of writing with extensive references and I'll definitely find this useful to share in the future. She documents a ton of tradeoffs she made and resources she chose not to constrain (including the aforementioned syscalls and capabilities), which is important in this type of design and something that I wish I saw more of.
[1]: https://github.com/jessfraz/contained.af/blob/master/seccomp...
No comments yet
Contribute on Hacker News ↗