Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Consider adding optional pre-configure seccomp filters

Open
#710 2 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
25/100
Issue type
Feature
Clarity
Needs clarification
Activity status
Stale
Tech stack
c, linux

Research direction

Start with SECURITY.md and compare the seccomp rules used by Flatpak and other consumers. Build the requested table of rules and when they are needed, then use it to assess possible optional pre-configured filter sets. The issue names no source files or tests, so the implementation and completion criteria remain open.

Written by the indexing model from the issue text.

Description

SECURITY.md clarifies that it is not the task of bwrap to enure that a real security barrier is created.

However, as I understand it, there is a list of seccomp rules that are fundamental to ensuring that bwrap can function as a sandbox at all. For example: unshare, setns, or mount.

I originally wasn't in favor of adding this to bwrap, and thought we could put it into a library that uses bwrap. But now I think if we can find a good set or good multiple sets, we should add them.

The issue currently is that there are too many consumers that have to create seccomp rules for this themselves, and this is very prone to errors.

First step would be to have a table which lists what seccomp rules are needed and when. Sadly, even Flatpak etc don't properly document their seccomp rules.

Dominant language
C
Stars
8.8k
Forks
387
Avg merge
1d 23h
Merged PRs (30d)
13

Getting set up

We have not checked this project's setup files yet. Start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from containers/bubblewrap

All issues in containers/bubblewrap

Similar issues

More C issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.