Now that #20487 is merged, it would be nice if syscall sandboxing was extended to the other Linux platforms that have release binaries as well:
x86_64-linux-gnuarm-linux-gnueabihfaarch64-linux-gnuriscv64-linux-gnupowerpc64-linux-gnupowerpc64le-linux-gnu