Skip to main content

BLOCKED_SYSCALLS

Constant BLOCKED_SYSCALLS 

Source
pub const BLOCKED_SYSCALLS: &[&str];
Expand description

Syscalls that should be blocked in seccomp-bpf profiles.

Following the field guide: “A tight seccomp profile blocks syscalls that expand kernel attack surface or enable escalation.”

This is a blocklist (deny-list), not a whitelist. Per the sandboxing-basics analysis (Emilua 2025), blocklists are inherently fragile: new kernel syscalls, multiarch numberings, and the x32 ABI (__X32_SYSCALL_BIT) can bypass naive filters. linux_seccomp::primary_rules therefore installs both the native number and its x32-aliased variant on x86_64, and the launcher kills mismatched architectures outright (SECCOMP_RET_KILL_PROCESS via seccompiler arch validation). Prefer Landlock for filesystem policy and keep this list focused on escalation/escape primitives.

Group labels mirror the Kafel-inspired families from that analysis (Debug, FilesystemHandle, IoUring, ProcessVm, …) so future whitelist work can promote one family at a time.