pub fn seccomp_profile(target: &Target) -> StringExpand description
An OCI/Docker/Podman seccomp profile that allows only the syscalls
target provides, answers ENOSYS for every other syscall, and answers
EINVAL for madvise advice values target does not know.
The profile is an allowlist on purpose. Container runtimes resolve names
with their own libseccomp and silently drop names it does not know, so a
blocklist fails open for exactly the newest syscalls. With an allowlist an
unknown name stays blocked (and syscall-probe reports it), and syscalls
newer than this crate’s data are blocked too.
madvise gets one rule per advice value from 0 to the highest known
value, plus one for anything above it, so no two rules overlap and the
result never depends on how a runtime orders conflicting rules. Values are
compared on the low 32 bits because the kernel reads an int.