ä¸ã®ä¸ã«ã¯seccompã¨ãããã®ããããç¥ããã¦ãã¾ããçããã¯BPFã§ããã人ã¯ããã seccompã«ã¤ãã¦ã¯ä»¥åæ¸ãã¾ãããLinuxã®ã·ã¹ãã ã³ã¼ã«å¼ã³åºãããã£ã«ã¿ãªã³ã°ãã¦è¨±å¯ãããç¦æ¢ããããããã®ã§ãã udzura.hatenablog.jp ãã¦ä»åãæä½ mruby-seccomp 㧠SCMP_ACT_TRACE ã¢ã¯ã·ã§ã³ããµãã¼ããã¾ããããã®è¾ºã®è©±ããã¦ã¿ã¾ãã libseccompã®ã³ã³ãã¯ã¹ãã« SCMP_ACT_TRACE ã®ã¢ã¯ã·ã§ã³ã追å ãã¦ãã¼ãããã¨ãå½è©²ã·ã¹ãã ã³ã¼ã«ã®å¼ã³åºãã ptrace(2) ã§ãã¬ã¼ã¹ã§ãã¾ãã ptrace(2) ã¯æ®éãããããã·ã¹ãã ã³ã¼ã«ã SIGTRAP ã§æ¢ããã¿ãããªåãããã¾ãããç¹å®ã®ã·ã¹ãã ã³ã¼ã«ã®ã¿ãåæ¢ã§ããã¾ãã·ã°ãã«ã SIGTRAP ã§ã¯ãªãå¥ã®ãã®ã¨ãããã¨ãã§ãã¾ãã ptrace(
{{#tags}}- {{label}}
{{/tags}}