Block kcmp, procees_vm_readv, process_vm_writev. All these require CAP_PTRACE, and are only used for ptrace related actions, so are not useful as we block ptrace. Signed-off-by: Justin Cormack <justin.cormack@unikernel.com> Upstream-commit: a0a8ca0ae0bc9dc7faa0b8bacf4ca376c7257348 Component: engine