<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
  xmlns:xhtml="http://www.w3.org/1999/xhtml">
  <url>
    <loc>https://www.scrivano.org/posts/2026-06-05-sealing-with-composefs/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/composefs/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/erofs/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/fs-verity/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/posts/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/categories/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/categories/development/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/development/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/git/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/posts/2025-04-30-git-chronicler/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/openai/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/cgroups/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/cgroups-v2/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/podman/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/rootless/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/posts/2024-1-26-why-do-i-have-two-cgroup/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/cve/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/posts/2022-12-21-hide-self-exe/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/kernel/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/prctl/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/security/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/crun/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/oci/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/performance/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/seccomp/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/posts/2022-10-21-the-journey-to-speed-up-oci-containers/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/posts/2022-09-05-seccomp-listener/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/posts/2021-10-26-compose-fs/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/containers/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/storage/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/easyseccomp/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/posts/2021-01-30-easyseccomp/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/posts/2020-08-14-oom-group/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/oom/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/conmon/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/posts/2020-08-10-seccomp-notifications/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/2019/12/27/avoid-a-memory-page-allocation-on-mount/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/mount/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/fuse-overlayfs/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/2019/10/24/run-containers-without-pulling-images/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/stargz/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/categories/uncategorized/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/2019/08/12/crun-moved-to-github-com-containers/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/2019/05/12/rootless-resources-management-with-podman-on-fedora-30/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/2019/02/26/resources-management-with-rootless-containers/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/systemd/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/namespaces/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/2019/02/24/rootless-containers-devconf-cz/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/slirp4netns/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/2019/01/10/suid-binaries-from-a-user-namespace/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/user-namespace/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/2019/01/09/disposable-rootless-sessions/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/overlayfs/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/2018/12/18/an-emacs-mode-for-rust/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/emacs/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/rust/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/2018/10/12/rootless-podman-from-upstream-on-centos-7/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/2018/08/05/network-namespaces-for-unprivileged-users/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/2018/07/19/become-root-in-an-user-namespace/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/2018/07/13/fuse-overlayfs-moved-to-github-com-containers/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/buildah/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/2018/02/25/current-status-problems-running-buildah-non-root/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/copr/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/2017/11/15/new-copr-repository-crun/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/2017/10/23/c-still-makes-sense-low-level-tools-oci-runtime/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/runc/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/atomic/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/openshift/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/2017/02/23/openshift-system-containers/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/system-containers/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/2017/01/30/system-containers-presentation/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/2016/12/27/facebook-detox/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/bubblewrap/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/2016/10/22/use-bubblewrap-unprivileged-user-run-systemd-images/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/2016/05/11/brainfucd-brainfk/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/brainfuck/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/gcc/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/2016/04/22/rename-symbol-across-several-git-patches/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/2016/03/24/system-containers-for-atomic/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/docker/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/ostree/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/2015/09/30/ostree-docker-builder/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/rpm-ostree/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/gsoc2015/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/posts/2015-04-30-summer-of-code-2015-wget/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/wget/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/posts/2015-04-20-create-a-qcow2-image-for-fedora-22-atomic/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/qcow2/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/tags/docker-compose/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/posts/2015-04-19-wordpress-in-a-docker-container/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/about/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url><url>
    <loc>https://www.scrivano.org/archives/</loc>
    <lastmod>2026-06-06T10:03:54+00:00</lastmod>
  </url>
</urlset>
