Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Straight forward thanks to all privileged operations being done early enough during startup. Basically forbid all groups of syscalls except for networking, so no fileystem access, signals, process management, etc.
- Loading branch information