refactor(fspy): replace seccomp unotify with filtered ptrace - #575
Draft
wan9chi wants to merge 1 commit into
Draft
refactor(fspy): replace seccomp unotify with filtered ptrace#575wan9chi wants to merge 1 commit into
wan9chi wants to merge 1 commit into
Conversation
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
fspy benchmarklinuxmacoswindows |
wan9chi
force-pushed
the
agent/seccomp-filtered-ptrace
branch
3 times, most recently
from
July 28, 2026 10:50
597c364 to
db34073
Compare
Co-authored-by: GPT-5.6 Codex <codex@openai.com>
wan9chi
force-pushed
the
agent/seccomp-filtered-ptrace
branch
from
July 28, 2026 11:07
db34073 to
06f8432
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Motivation
Static Linux binaries and musl builds currently use seccomp user notification for direct-syscall tracking. That path requires a notification file descriptor, descriptor handoff, and a userspace request/continue round trip for every selected syscall. Seccomp-filtered
ptracekeeps the filter selective while replacing the notification-fd handoff with a process-tree tracer.Changes
fspy_seccomp_unotifycrate withfspy_seccomp_ptraceSECCOMP_RET_TRACEfilter and follow fork, clone, exec, signal, and exit events withptraceseccompilerrelease instead of the user-notification fork