Comment by simcop2387
9 years ago
Seccomp with ptrace is the way I'd do this. You can setup the rules to signal the ptracing process to intercept the syscall. I've not done it before but it should be possible. Id also look at doing it in a mount namespace with overlayfs on top of everything the process can see, so that you can manipulate anything you want or need filewise without destroying the original system. Then you can copy out any changed files later if you want to preserve them.
You should check out DockerSlim [0] then :-) It'll generate a seccomp profile for you and it uses ptrace too.
[0] http://dockersl.im