seccomp load() fails with EBUSY on repeated calls, preventing multi-stage sandboxing
seccomp load() fails with EBUSY on repeated calls, preventing multi-stage sandboxing: a task in LegoFlow-SWE (Harbor dataset). The kernel returns EBUSY because libseccomp unconditionally requests the SECCOMP FILTER FLAG NEW LISTENER flag during every seccomp load() . The kernel only permits one…
The task
The kernel returns `EBUSY` because libseccomp unconditionally requests the `SECCOMP_FILTER_FLAG_NEW_LISTENER` flag during every `seccomp_load()`. The kernel only permits **one** `NEW_LISTENER` request per process. Consequently, any second `seccomp_load()` call is rejected, regardless of whether the filter contains…
Part of Lego-X/LegoFlow-SWE.