The bpf syscall can load code into the kernel which may persist beyond container lifecycle. Requires CAP_SYS_ADMIN already. Signed-off-by: Justin Cormack <justin.cormack@unikernel.com> Upstream-commit: 33568405f34f363de49b1146119cc53bcb9e5f16 Component: engine