4 ms·
I wonder if blink could be used as a lightweight sandbox. Looking at PR46[0], it seems sandboxing is not one of the current features, but it would be cool to ha
by polyrand 4y ago
I wonder if blink could be used as a lightweight sandbox. Looking at PR46[0], it seems sandboxing is not one of the current features, but it would be cool to have a way to run arbitrary code (e.g: Python) in a sandboxed environment. Even cooler if you could limit the amount of memory/CPU used.
[0]: https://github.com/jart/blink/pull/46#pullrequestreview-1264664859 https://github.com/jart/blink/pull/46#pullrequestreview-1264...
- jart 4y agoAuthor of Blink here. I wrote another command called pledge.com which does sandboxing: https://justine.lol/pledge/ https://justine.lol/pledge/ Let's say for example you want to be able to run the `ls` command under Blink in a way that (1) restricts which parts of the file system it's allowed to use and (2) prevents it from talking to the Internet. You could say: ~/blink$ pledge.com -v/lib -v/bin/ls -v. -p 'stdio rpath tty prot_exec' o//blink/blink /bin/ls HTAGS LICENSE Makefile README.md TAGS blink build o test third_party tool You can now be certain that your `ls` command isn't spying on you or uploading your bitcoin wallet to the cloud. The blink command itself is currently unsecured. However that shouldn't matter, since we can compose blink with pledge.com to bolt on all the security we need separately!
- polyrand 4y agoAwesome! I was just reading about pledge. I think I need to find some time to play around with it. Right now, there's a lot of interest in using WASM as a sandbox for untrusted code, but pledge looks easier to use and more versatile (you don't need any kind of WASM compatibility, just a binary to run).
- jart 4y agoOffline WASM runtimes like Wasmtime are pretty cool, however I'd call SECCOMP BPF with Landlock LSM a shining beacon of light. The problem is that (1) coding BPF assembly has always been terrifying to the uninitiated and (2) Landlock LSM only came out in the past year. I believe pledge.com is the first tool that makes using both these Linux security tools together universally accessible for everyone. Be sure to run a bleeding edge Linux kernel if you use the `-v PATH` flag. If you're running an older kernel, then the pledge.com command will treat unveiling as a no-op in the interest of compatibility. I use Landlock LSM on my desktop, which runs Alpine Linux 5.15.74-0-lts. I also use Landlock in production on GCE, but I needed to `apt install linux-image-5.18.0-0.deb11.4-cloud-amd64` in order for it to work.