Hacker News new | ask | show | jobs
by jiveturkey 785 days ago
isn't that exactly what the parent was asking for? limiting syscalls.

EDIT: oh. but not limited to the caller from a specific system library.