All three breakouts feature procfs writes. #sydbox has hardened procfs and devfs, https://man.exherbo.org/syd.7.html#Hardened_procfs_and_devfs
which prevents such breaks. However wrt. syd-oci, the vulnerable code is within the container init done by #youki.