Skip to main content

Module local

Module local 

Source
Expand description

Runs a program on the host under a seccomp filter that simulates a kernel.

No container runtime and no root are needed: the child sets no_new_privs, installs the filter from crate::filter, and executes the program. Only the kernel is simulated; the program still uses the host’s libc and userland. Inside the filtered process tree, setuid programs (such as sudo) cannot gain privileges.

Functions§

run
Runs program with args under the filter for target and returns its exit status (128 if it was killed by a signal). The current directory and environment are inherited. Suitable for a Cargo runner.