SECCOMP, short for SECure COMPuting, is a part of Linux kernel that allows restricting, logging or otherwise reacting to systemcalls or systemcall arguments a userspace process can invoke. The talk offers a brief introduction to SECCOMP API and its history. Further I will focus on how SECCOMP is currently used (sandboxing) and some of its current limitations. As a bonus, I will briefly talk about debugging SECCOMP enabled process with Valgrind.
Watch video Miroslav Franc: Linux's SECCOMP, its usecases and problems online without registration, duration hours minute second in high quality. This video was added by user SUSE Labs 10 June 2024, don't forget to share it with your friends and acquaintances, it has been viewed on our site 112 once and liked it 5 people.