Earlier quoted context omitted.
Whether or not people who likely have no actual experience in this space dislike what I’m saying about the pointlessness of using wasm for this use case has no bearing on my correctness. Most of them demonstrated they didn’t know the difference between seccomp and seccomp-bpf and there have been no rational counter arguments that hold their weight. Usually downvotes without rational rebuttals are a sign of the OP’s c…
I mention the downvotes because when you find yourself thinking you're right and everyone is wrong usually it's you that's mistaken. In this case anyone with experience in computer security can tell you multiple layers of defense are always better than one. Seccomp is great, and I think you actually have a point about it, but it's hard to get right without locking out all system calls entirely - and that's hard to do…
Seccomp locks out every system call except for read, write, exit, and sigreturn. That’s why the extra defense afforded by wasm is superfluous here.