pub const BLOCKED_SYSCALLS: &[&str];Expand description
Syscalls that should be blocked in seccomp-bpf profiles.
Following the field guide: “A tight seccomp profile blocks syscalls that expand kernel attack surface or enable escalation.”
This is a blocklist (deny-list), not a whitelist. Per the sandboxing-basics
analysis (Emilua 2025), blocklists are inherently fragile: new kernel syscalls,
multiarch numberings, and the x32 ABI (__X32_SYSCALL_BIT) can bypass naive
filters. linux_seccomp::primary_rules therefore installs both the native
number and its x32-aliased variant on x86_64, and the launcher kills
mismatched architectures outright (SECCOMP_RET_KILL_PROCESS via
seccompiler arch validation). Prefer Landlock for filesystem policy and keep
this list focused on escalation/escape primitives.
Group labels mirror the Kafel-inspired families from that analysis
(Debug, FilesystemHandle, IoUring, ProcessVm, …) so future
whitelist work can promote one family at a time.