4 ms·
Here is an example for sandboxing zlib: https://github.com/google/sandboxed-api/blob/main/sandboxed_api/examples/zlib/main_zlib.cc https://github.com/google/sa
by steerablesafe 5y ago
Here is an example for sandboxing zlib:
https://github.com/google/sandboxed-api/blob/main/sandboxed_api/examples/zlib/main_zlib.cc https://github.com/google/sandboxed-api/blob/main/sandboxed_...
So it adds extra state, that needs to be initialized, adds extra failure points than needed to be handled in the code (sandbox initialization can fail, the RPC layer can fail itself), need to wrap some data structures so they can be passed through (you can't just pass pointers as-is).
I wonder how callbacks can be passed, but maybe that's actually less problematic than data pointers.
- nly 5y agoTo be honest it seems like writing a capnproto rpc around the functionality you want to sandbox, and running it as a low privilege microservice, would be better than SAPI. capnproto supports passing callacks/interfaces back via its capabilities mechanism.
- ithkuil 5y agobut you'd have to manually define such an rpc wrapper IDL, right? IIUC the interesting trick behind SAPI is that it generates the wrapper for you based on parsing the library public API. Perhaps I misunderstood something.