重新设计沙箱机制 #1
Loading…
Reference in New Issue
Block a user
No description provided.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
最早设计时
seccomp
采用白名单机制,只允许执行几个经过挑选的系统调用,对于Go
在内的语言不友好可能的方式:
open
有限制性的约束考虑使用黑名单机制to 重新设计沙箱机制open
有限制性的约束:ae91f2c3f5