3 ms·
This is one of the main problems with "whole program sandboxes". Many times a program only needs permissions right at the start and then never again. From the o
by staticassertion 5y ago
This is one of the main problems with "whole program sandboxes". Many times a program only needs permissions right at the start and then never again. From the outside though there's no way to signal "OK, I'm done, lock me down" for most sandboxing systems.
One approach that may work with systemd is to have two processes. One would be a broker, running as root. It would grab a port, for example. The other process would be spawned by the broker as a limited service and inherit that port from the parent, with no permissions of its own to open it, only to inherit.
IDK how to express that in systemd-land though. At that point you might be better off just writing the code to sandbox things yourself.