rules for device control groups; • employ the ptrace (2) PTRACE_SECCOMP_GET_FILTER operation ... dump tracee's seccomp filters; • employ the ptrace (2) PTRACE_SETOPTIONS operation …these symbolic links is governed by a ptrace access mode PTRACE_MODE_READ_FSCREDS check ... ptrace (2). The /proc/sys/user directory The files in the /proc/sys/user directory (whic…according to their run-time parent policies. Ptrace restrictions A sandboxed process has less privileges ... another process. To be allowed to use ptrace (2) and related syscalls o…ALSO newgidmap (1), newuidmap (1), clone (2), ptrace (2), setns (2), unshare (2), proccall, for example: kill (2), ptrace (2), setpriority (2), setpgid (2), setsid (2), sigqueueNICE systemd-nspawn (1) CAP_SYS_PTRACE systemd-nspawn (1), systemd.exec (5) CAP_SYS_RAWIO