Robuta

https://dev.to/piyushjajoo/apparmor-and-seccomp-in-kubernetes-what-the-docs-dont-tell-you-4856 AppArmor and Seccomp in Kubernetes: What the Docs Don't Tell You - DEV Community You've read the Kubernetes security docs. You know to set appArmorProfile: RuntimeDefault and... Tagged with kernel, linux, kubernetes, infrastructure. https://android-developers.googleblog.com/2017/07/seccomp-filter-in-android-o.html Android Developers Blog: Seccomp filter in Android O News and insights on the Android platform, developer tools, and events. android developers blogseccompfilter https://kubernetes.io/docs/reference/node/seccomp/ Seccomp and Kubernetes | Kubernetes Seccomp stands for secure computing mode and has been a feature of the Linux kernel since version 2.6.12. It can be used to sandbox the privileges of a... seccompkubernetes https://lkml.indiana.edu/hypermail/linux/kernel/2103.2/06879.html Linux-Kernel Archive: [PATCH] seccomp: fix the cond to report loaded filters linux kernel https://docs.redhat.com/en/documentation/openshift_container_platform/3.11/html/cluster_administration/admin-guide-seccomp Chapter 32. Restricting Application Capabilities Using Seccomp | Cluster Administration | OpenShift... Chapter 32. Restricting Application Capabilities Using Seccomp | Cluster Administration | OpenShift Container Platform | 3.11 | Red Hat Documentation cluster administrationchapterrestrictingapplicationcapabilities https://lkml.iu.edu/1204.1/01092.html Linux-Kernel Archive: Re: [PATCH v17 08/15] seccomp: add system call filtering using BPF https://pkg.go.dev/arhat.dev/nikaya/third_party/v1_20/k8s.io/kubernetes/pkg/security/podsecuritypolicy/seccomp seccomp package -... seccomppackage https://forum.cursor.com/t/critical-governance-issue-cursor-sandbox-and-seccomp-blocking-root-sudo-kill-signals-eacces/158161 Critical Governance Issue: cursor_sandbox and Seccomp blocking Root/Sudo kill signals (EACCES) -... Apr 16, 2026 - Where does the bug appear (feature/product)? Cursor CLI Describe the Bug Processes spawned within the cursor_sandbox (likely by AI Agent or integrated... https://kubernetes.io/blog/2023/05/24/oci-security-profiles/ Using OCI artifacts to distribute security profiles for seccomp, SELinux and AppArmor | Kubernetes Jan 3, 2026 - The Security Profiles Operator (SPO) makes managing seccomp, SELinux and AppArmor profiles within Kubernetes easier than ever. It allows cluster administrators... https://lkml.iu.edu/hypermail/linux/kernel/1902.2/06387.html Linux-Kernel Archive: Re: [bpf] 568f196756: BUG:assuming_atomic_context_at_kernel/seccomp.c https://lkml.indiana.edu/1605.3/02602.html Linux-Kernel Archive: Re: [PATCH] seccomp: plug syscall-dodging ptrace hole linux kernelarchivepatch https://advisories.gitlab.com/golang/github.com/kyverno/kyverno/CVE-2023-33191/ kyverno seccomp control can be circumvented | GitLab Advisory Database (GLAD) CVE-2023-33191 kyverno seccomp control can be circumvented: Impact Users of the podSecurity (validate.podSecurity) subrule in Kyverno 1.9. See the... can bekyvernoseccompcontrolcircumvented https://kubernetes.io/docs/tutorials/security/seccomp/?ref=sredevops.org Restrict a Container's Syscalls with seccomp | Kubernetes Jan 28, 2026 - FEATURE STATE: Kubernetes v1.19 [stable] Seccomp stands for secure computing mode and has been a feature of the Linux kernel since version 2.6.12. It can be... restrictcontainersyscallsseccompkubernetes https://pkg.go.dev/arhat.dev/nikaya/third_party/v1_16/k8s.io/kubernetes/pkg/security/podsecuritypolicy/seccomp seccomp package -... seccomppackage https://lkml.indiana.edu/1703.0/01389.html Linux-Kernel Archive: Re: [PATCH v5 06/10] seccomp,landlock: Handle Landlock events per process... https://groups.google.com/g/linux-kernel-proxy/c/vBFwsONPrmI [RFC,PATCH 2/2] Documentation: prctl/seccomp_filter rfcpatchdocumentationseccompfilter https://lwn.net/Articles/603321/ man-pages: seccomp.2: document syscall [LWN.net] man pagesseccompdocumentsyscalllwn https://lkml.iu.edu/hypermail/linux/kernel/1601.0/03090.html Linux-Kernel Archive: Re: [PATCH v3 0/4] um: Add seccomp support linux kernel https://lists.debian.org/deity/2017/11/msg00049.html Bug#881519: marked as done (apt: do not attempt seccomp in qemu-user) https://lkml.iu.edu/hypermail/linux/kernel/1406.3/00825.html Linux-Kernel Archive: [PATCH v8 1/9] seccomp: create internal mode-setting function https://lkml.indiana.edu/2203.3/04752.html Linux-Kernel Archive: [PATCH] selftests/seccomp: Add SKIP for failed unshare() linux kernelarchivepatch https://lkml.indiana.edu/1703.0/00770.html Linux-Kernel Archive: Re: [PATCH v5 06/10] seccomp,landlock: Handle Landlock events per process... https://aventer-ug.github.io/marathon/docs/seccomp.html Marathon: seccomp marathonseccomp https://lkml.indiana.edu/2010.3/07341.html Linux-Kernel Archive: Re: [seccomp] Request for a "enable on execve" mode for Seccomp filters https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/ARRGCCDSTOWCP46R634AHW3NEA7Q3XMU/ Fedora 34 Update: oci-seccomp-bpf-hook-1.2.3-1.fc34 - package-announce - Fedora mailing-lists https://tracker.debian.org/pkg/golang-github-seccomp-libseccomp-golang golang-github-seccomp-libseccomp-golang - Debian Package Tracker debian packagegolanggithubseccomptracker https://lkml.iu.edu/1810.1/03461.html Linux-Kernel Archive: Re: [PATCH v7 3/6] seccomp: add a way to get a listener fd from ptrace https://www.elastic.co/docs/reference/beats/heartbeat/linux-seccomp Use Linux Secure Computing Mode (seccomp) | Beats On Linux 3.17 and later, Heartbeat can take advantage of secure computing mode, also known as seccomp. Seccomp restricts the system calls that a process... secure computinguselinuxmodeseccomp https://manpages.ubuntu.com/manpages/questing/man2/seccomp.2.html Ubuntu Manpage: seccomp - operate on Secure Computing state of the process operate on Secure Computing state of the process secure computingstate ofubuntumanpageseccomp https://lkml.indiana.edu/2010.3/07775.html Linux-Kernel Archive: [seccomp] Request for a "enable on execve" mode for Seccomp filters linux kernelrequest for https://manpages.ubuntu.com/manpages/questing/man2/seccomp_unotify.2.html Ubuntu Manpage: seccomp_unotify - Seccomp user-space notification mechanism Seccomp user-space notification mechanism user spaceubuntumanpageseccompnotification https://wiki.mozilla.org/index.php?title=B2G/Architecture/System_Security/Seccomp&action=edit View source for B2G/Architecture/System Security/Seccomp - MozillaWiki view sourcesystem securityarchitectureseccomp https://lkml.iu.edu/hypermail/linux/kernel/1811.2/05727.html Linux-Kernel Archive: Re: [Patch v7 14/18] x86/speculation: Add 'seccomp' Spectre v2 app to app... https://lwn.net/Articles/756331/ Deferring seccomp decisions to user space [LWN.net] user spaceseccompdecisionslwn https://www.elastic.co/blog/seccomp-in-the-elastic-stack Seccomp in the Elastic Stack | Elastic Blog Apr 19, 2024 - Learn how the Elastic Stack uses seccomp to prevent the execution of certain system calls, and how you can monitor seccomp violations using the Elastic... in theelastic stackseccompblog https://lkml.iu.edu/1810.1/02433.html Linux-Kernel Archive: Re: [PATCH v7 1/6] seccomp: add a return code to trap to userspace https://lists.debian.org/deity/2017/11/msg00044.html Processed: cloning 880582, reassign -1 to apt, retitle -1 to apt: do not attempt seccomp in... https://lkml.indiana.edu/2211.0/06334.html Linux-Kernel Archive: Re: [PATCH v3] docs/zh_CN: Add userspace-api/seccomp_filter Chinese... https://lkml.iu.edu/hypermail/linux/kernel/1811.2/06907.html Linux-Kernel Archive: Re: [patch 24/24] x86/speculation: Add seccomp Spectre v2 app to app... https://groups.google.com/g/libseccomp/c/2wo4ocDflOw [seccomp/libseccomp] 861e2d: tests: fix 54-live-binary_tree to use binary tree binary treeseccomptestsfix https://lwn.net/Articles/764818/ Deferring seccomp decisions to user space [LWN.net] user spaceseccompdecisionslwn https://docs.redhat.com/zh-cn/documentation/openshift_container_platform/4.18/html/security_and_compliance/seccomp-profiles Chapter 14. Configuring seccomp profiles | Security and compliance | OpenShift Container Platform |... Chapter 14. Configuring seccomp profiles | Security and compliance | OpenShift Container Platform | 4.18 | Red Hat Documentation security and compliancechapterconfiguringseccompprofiles https://pkg.go.dev/github.com/carmark/cadvisor/Godeps/_workspace/src/github.com/docker/libcontainer/seccomp seccomp package -... Package seccomp provides native seccomp ( https://www.kernel.org/doc/Documentation/prctl/seccomp_filter.txt ) support for go. seccomppackage https://dev.to/hexshift/seccomp-in-docker-reducing-kernel-attack-surface-with-system-call-filtering-2654 Seccomp in Docker: Reducing Kernel Attack Surface with System Call Filtering - DEV Community Containers offer process-level isolation but still rely on the shared kernel of the host system. This... Tagged with docker, security, cybersecurity, json. https://lkml.iu.edu/2210.2/06269.html Linux-Kernel Archive: [PATCH 0/5 v2] seccomp: add the synchronous mode for seccomp_unotify https://manpages.ubuntu.com/manpages/resolute/man2/seccomp.2.html Ubuntu Manpage: seccomp - operate on Secure Computing state of the process operate on Secure Computing state of the process secure computingstate ofubuntumanpageseccomp https://lkml.iu.edu/1708.1/04076.html Linux-Kernel Archive: Re: [PATCH v3 2/4] seccomp: Add SECCOMP_FILTER_FLAG_KILL_PROCESS https://lkml.iu.edu/hypermail/linux/kernel/1506.1/05537.html Linux-Kernel Archive: Re: [PATCH v5] seccomp: add ptrace options for suspend/resume https://lwn.net/Articles/893697/ Handle seccomp notification preemption [LWN.net] handleseccompnotificationpreemptionlwn https://lwn.net/Articles/756341/ Deferring seccomp decisions to user space [LWN.net] user spaceseccompdecisionslwn https://qa.debian.org/cgi-bin/vcswatch?package=golang-github-seccomp-libseccomp-golang golang-github-seccomp-libseccomp-golang vcswatch -- Debian Quality Assurance golanggithubseccompdebianquality https://lkml.indiana.edu/2302.0/01282.html Linux-Kernel Archive: [PATCH 5/6] selftest/seccomp: add a new test for the sync mode of... https://lwn.net/Articles/753152/ Better integrate seccomp logging and auditing [LWN.net] betterintegrateseccomploggingauditing https://lwn.net/Articles/756323/ Deferring seccomp decisions to user space [LWN.net] user spaceseccompdecisionslwn https://lkml.iu.edu/hypermail/linux/kernel/1506.1/05517.html Linux-Kernel Archive: Re: [PATCH v5] seccomp: add ptrace options for suspend/resume https://koschei.fedoraproject.org/package/oci-seccomp-bpf-hook?collection=f42 Koschei - oci-seccomp-bpf-hook ociseccompbpfhook https://lkml.iu.edu/hypermail/linux/kernel/1406.3/03144.html Linux-Kernel Archive: [PATCH v9 06/11] MIPS: add seccomp syscall linux kernelarchivepatch https://aur.archlinux.org/cgit/aur.git/tree/chromium-145-fix-SYS_SECCOMP.patch?h=chromium-no-extras chromium-145-fix-SYS_SECCOMP.patch - aur.git - AUR Package Repositories chromiumfixsysseccomppatch https://lkml.indiana.edu/1703.0/01733.html Linux-Kernel Archive: Re: [kernel-hardening] [PATCH v5 06/10] seccomp,landlock: Handle Landlock... linux kernel