Software sandboxing: The basics (2025)
A technical write-up presents composable seccomp-BPF syscall allowlist policies for sandboxing unprivileged Linux applications, inspired by Docker, systemd, and OpenBSD pledge.
The article explains the basics of software sandboxing on Linux through syscall allowlists implemented as seccomp BPF programs, organized into composable categories such as BasicIo, CRuntime, Debug, Filesystem, and Credentials. The design draws on Docker's default profile, systemd's seccomp filter sets, and OpenBSD's pledge promises, while avoiding root-only and fingerprinting-friendly syscalls to reduce overhead. It also discusses compat quirks for x86, Wine, and 32-bit emulation, and points to Landlock for granular filesystem restrictions akin to pledge's rpath/wpath split.