HeadlinesBriefing favicon HeadlinesBriefing.com

Software Sandboxing: The Basics

Hacker News •
×

The article outlines seccomp-based sandboxing policies shaped by Docker's default profile, designed mainly for unprivileged users rather than root containers. Policies are split into categories inspired by systemd's seccomp filter sets and OpenBSD's pledge promises, minimizing syscalls to reduce BPF program size and overhead.

Key policy groups include Aio, Basic Io, Clock, Compat X86, Compat DB32, Compat Systemd, Compat Wine, Credentials, Credentials Extra, Credentials Mutation, and CRuntime. Each defines a specific set of allowed syscalls, such as I/O operations, clock functions, credential queries, and memory or thread management.

The Compat X86 policy addresses old ABI emulation and arch_prctl, while Compat Wine allows modify_ldt. Credentials Mutation covers capability and identity changes, and CRuntime ensures C runtime functions like brk, mmap, mprotect, futex, and getrandom remain available for standard program execution.