3 ms·
Doesn't OpenBSD have an API that has this kind of functionality too, albeit in a slightly simpler form?
by Varriount 3y ago
Doesn't OpenBSD have an API that has this kind of functionality too, albeit in a slightly simpler form?
- skywal_l 3y agopledge and unveil.
- masklinn 3y agopledge(2)? That’s generally about blacklisting syscalls though a few options allow carveouts (mostly around file system access). Sealing memory mappings is a lot lower level, and more fine-grained.
- tristan957 3y agohttps://man.openbsd.org/pledge.2 https://man.openbsd.org/pledge.2
- akaij 3y agoLinux port by @jart: https://github.com/jart/pledge https://github.com/jart/pledge
- brynet 3y agoNot pledge. This is an overdesigned, overcomplicated clone of mimmutable. https://man.openbsd.org/mimmutable https://man.openbsd.org/mimmutable The OpenBSD kernel does automatic immutable for certain regions (e.g: stack, program text, bss), as well as from ld.so. Ironically, mimmutable(2) is already used in the OpenBSD chromium port for v8. https://marc.info/?l=openbsd-ports-cvs&m=168854379207826&w=2 https://marc.info/?l=openbsd-ports-cvs&m=168854379207826&w=2 There is absolutely no excuse for Google to propose something different for no reason.