-
Notifications
You must be signed in to change notification settings - Fork 3
Open
Labels
enhancementNew feature or requestNew feature or request
Description
Description:
Currently, restrict applies syscall filters globally. It would be useful to support per-thread filtering, so plugins/workers can have different restrictions (e.g., a thread handling file I/O vs. one executing untrusted code).
Use Case:
Prevent a background thread from execve while allowing it in the main thread.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or request