Expand description
Runs a program on the host under a seccomp filter that simulates a kernel.
No container runtime and no root are needed: the child sets
no_new_privs, installs the filter from crate::filter, and executes
the program. Only the kernel is simulated; the program still uses the
host’s libc and userland. Inside the filtered process tree, setuid
programs (such as sudo) cannot gain privileges.
Functions§
- run
- Runs
programwithargsunder the filter fortargetand returns its exit status (128 if it was killed by a signal). The current directory and environment are inherited. Suitable for a Cargo runner.