1 files changed, 7 insertions(+), 1 deletions(-)
M README.md => README.md +7 -1
@@ 1,6 1,12 @@
Filter what syscalls programs are allowed to call.
Filter what syscalls programs are allowed to call without needing root.
The main motivation for this tool was running a program without internet
access. It could've been done with unshare in theory, but using `unshare -nr`
messed up the program's perception of what the home path was.
Warning: this should not be used as a security tool!