Skip to content

other

seccomp

Linux syscall filtering facility that, with namespaces, forms the two-layered sandbox around the Workers runtime.

Known aliases

  • seccomp-bpf
  • seccomp filter
  • seccomp filters
  • seccomp profile
  • secure computing mode

Relationships

No evidence-backed relationships are recorded.

Current stories

security1 publisher

A guest escape can reach Firecracker's blocked syscalls through io_uring

Amazon patched a symlink-following chown in Firecracker's jailer that only affected aarch64. Behind it sits a seccomp policy that permits io_uring, and researcher antitree shows how that hands back file-system calls the filter denies.

Publishers:antitree.com

Reality

Evidence58
Adoption30
Hype gap−15
Incentives32
Confidence50