[$] Deep argument inspection for seccomp
In the Kernel Summittrack at the2019Linux Plumbers Conference, Christian Brauner and Kees Cook led adiscussion on finding a way to do deep argument inspection for seccompfiltering. Currently, seccomp filters can only look at the top-levelarguments to a system call, which means that there are use cases thatcannot be supported. There was a lively discussion in the session, but nodefinitive conclusion was reached; various ideas were considered, but noneseemed to quite fit the bill.