seccomp: add spawn argument to command line
This patch adds [,spawn=deny] argument to `-sandbox on' option. It
blacklists fork and execve system calls, avoiding Qemu to spawn new
threads or processes.
Signed-off-by: NEduardo Otubo <otubo@redhat.com>
Showing
想要评论请 注册 或 登录