ENVIRONMENT_COMMANDS: uname -r; id -u; grep -E 'NoNewPrivs|Seccomp:' /proc/self/status ENVIRONMENT_OUTPUT: 5.10.134-013.16.kangaroo.al8.x86_64; 1001; before parent shell NoNewPrivs: 0, Seccomp: 0 (00/env-raw.txt) COMMAND: cc -std=c11 -Wall -Wextra -Werror source/_posts/2026-10-01-容器08-权限边界/seccomp_probe.c -o /tmp/containers-seccomp-probe CC_EXIT_CODE=0 UTC_BEGIN: 2026-10-01T13:44:55Z COMMAND: /tmp/containers-seccomp-probe before_getpid=2589849 no_new_privs=1 after_getpid=-1 errno=1 allowed_getppid=2589836 RUN_EXIT_CODE=0 UTC_END: 2026-10-01T13:44:55Z COMMAND: rg 'NoNewPrivs|Seccomp:' /proc/self/status NoNewPrivs: 0 Seccomp: 0 EXPECTED: trusted child only sets no_new_privs, denies its own getpid with EPERM, allows getppid; parent remains unchanged. ACTUAL: all three branches matched expectation; no container runtime, capability drop or LSM denial tested. CLEANUP_COMMAND: python3 -c 'from pathlib import Path; target=Path("/tmp/containers-seccomp-probe"); target.unlink(); print("CLEANUP:", str(target), "exists=", target.exists())' CLEANUP: /tmp/containers-seccomp-probe exists= False; child already exited, parent NoNewPrivs=0 Seccomp=0.