$ cd ~ # Chaitanya Rahalkar
  • Home
  • About
  • Blog
  • Publications
  • Talks
  • Resume↗
  • Home
  • About
  • Blog
  • Publications
  • Talks
  • Resume↗

$ cd ~/tags/sandboxing

sandboxing

2026-02-23

Seccomp-BPF: Confining Linux Processes at the Syscall Boundary

A deep dive into Linux seccomp-BPF — building syscall sandboxes from raw BPF filters to production-grade policies, with practical C examples and analysis of how Chrome, Docker, and systemd use…

23 min read
containers linux kernel security Seccomp BPF Sandboxing Syscalls Hardening
GitHub Twitter Email RSS

$ echo "© 2026 Chaitanya Rahalkar"

Powered by Astro & MultiTerm