Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Ain’t eBPF hooks there so you can limit what a cgroup/process can do, not matter what API it’s calling. Like disallowing opening files or connecting sockets altogether.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: