I don't think TIF_NOTIFY_RESUME is apropos here. That only triggers on returning to user mode, i.e. after syscall exit. But regardless of the exact implementation details, I don't think it will be prohibitive to add some means by which the fast-path can back off before actual syscall entry and go to the slow path for ptrace reporting. Since there is no strong reason to think it can't be reorganized that way later, I don't see any good rationale for constraining the seccomp-filter feature definition based on a plan to optimize the implementation in the future. Thanks, Roland -- To unsubscribe from this list: send the line "unsubscribe linux-doc" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html