Bartłomiej Piotrowski commented:
Also copy-pasting possible workaround for posterity:
what may work is
you can probably borrow https://github.com/containers/common/blob/main/pkg/seccomp/seccomp.json , stick it into buildah image, and tell buildah bud to use it with --seccomp
sufficiently new crun (does buildah use it by default?) does the right thing about unknown syscalls
I will see how feasible is it tomorrow unless @alatiera beats me to it.