@jschauma Shouldn't further seccomp(2) calls be more restrictive though?
At least that's how I read this paragraph in seccomp(2):
If prctl(2) or seccomp() is allowed by the attached filter,
further filters may be added. This will increase evaluation
time, but allows for further reduction of the attack surface
during execution of a thread.