> But that would require modifying the application
Technically it can be done using LD_PRELOAD on fopen() and such.
Technically it can be done using LD_PRELOAD on fopen() and such.
If my application invokes syscalls directly, that wouldn't hit anything interposed using LD_PRELOAD.
There are other solutions such as seccomp (as siblings of your post have pointed out) that solve this securely, but LD_PRELOAD won't.