Filesystem sandboxing with eBPF
Filesystem sandboxing with eBPF
Posted Nov 7, 2019 5:29 UTC (Thu) by gutschke (subscriber, #27910)Parent article: Filesystem sandboxing with eBPF
I don't see any mention of suid-binaries, but given the very obvious potential for abuse, this filesystem hopefully prevents all new privileges, as soon as it has been mounted for a process hierarchy.