[ Watching this with popcorn from the sidelines, but I'll chime in anyway ] On Tue, 21 Jan 2025 15:38:48 +0100 Jiri Olsa <olsajiri@xxxxxxxxx> wrote: > I'm still trying to come up with some other solution but wanted > to exhaust all the options I could think of I think this may have been mentioned, but is there a way that the kernel could know that this system call is being monitored by seccomp, and if so, just stick with the interrupt version? If not, enable the system call? -- Steve