4 ms·
> my effects system compiles to a seccomp + apparmor profile so that your rust program is sandboxed at runtime based on info at compile time. is this open or p
by fire 4y ago
> my effects system compiles to a seccomp + apparmor profile so that your rust program is sandboxed at runtime based on info at compile time.
is this open or proprietary? I'd love a link to a repo
- insanitybit 4y agoI'll see if I can open source it this weekend. I'm not trying to be the "like and subscribe for updates" but if you want to see it when it's open source I'd suggest following me on Twitter (or Github? Does Github have a follow thing?) cause I won't remember to reply on HN. Here's a little snippet: #[effect::declare( args=(inner_tmp as I) returns=("/tmp/" + I) )] fn tmp_dir(inner_tmp: Path) -> Path { Path::from("tmp/").join(inner_tmp) } So it can reason about that Path's constraints. When that Path gets used by, say, "File::create(path)", it gets turned into a rule and added to an apparmor policy. Apparmor doesn't support a "hey I'm a process, please sandbox me" so I have to write a privileged daemon that manages that bit. I also have a way to apply effects to functions you don't own, mutating functions, functions that branch, etc. None of that is implemented yet, just designed.
- fire 4y agowhat's your twitter/gh? Could you add them to your hn profile?
- littlestymaar 4y agoCan't be certain, but given the content I'm pretty sure that it's these ones: - Github : https://github.com/insanitybit https://github.com/insanitybit - Twitter: https://twitter.com/InsanityBit https://twitter.com/InsanityBit
- insanitybit 4y agoThanks, yes. I'll add those to my profile.
- fire 4y agoNice, followed you on both