One of the most intelligent and practical systems for security is once again ditched by Linu(s|x). SELinux is not used by anyone outside preconfigured policies. System wide policies are HARD to write and maintain, a dynamic seccomp would enable every application developer to reduce the attack surface (which is huge) to the bare minimum.