≥ 4.17 for cgroup-bpf socket address hooks and /sys/power/resume_offset
≥ 4.20 for PSI (used by systemd-oomd)
≥ 5.2 for cgroup freezer
- ≥ 5.3 for bounded loops in BPF program
+ ≥ 5.3 for bounded loops in BPF program and keyring namespacing
≥ 5.4 for pidfd, new mount API, and signed Verity images
⛔ Kernel versions below 5.4 ("minimum baseline") are not supported at all,
{ 0, "@file-system" },
{ 0, "@io-event" },
{ 0, "@ipc" },
+ { 0, "@keyring" },
{ 0, "@mount" },
{ 0, "@network-io" },
{ 0, "@process" },
* The following syscalls and groups are knowingly excluded:
*
* @cpu-emulation
- * @keyring (NB: keyring is not namespaced!)
* @obsolete
* @pkey
* @swap