pro: improved security in daemons (often network)
con: some packages might pull in libseccomp (~250KB)

there shouldn't be measurable runtime overhead here as the filtering is done by 
a JIT in the kernel itself.  if the kernel lacks support for seccomp, daemons 
generally should fallback at runtime.  if they don't, people should file bugs 
to 
get them fixed.
-mike

Attachment: signature.asc
Description: Digital signature

Reply via email to