3 ms·
it'd be interesting to see a comparison of these -- the building blocks are (mostly) the same, but the interfaces differ in interesting ways: - nsjail - firej
by 5- 2y ago
it'd be interesting to see a comparison of these -- the building blocks are (mostly) the same, but the interfaces differ in interesting ways:
- nsjail
- firejail
- bubblewrap
- runc
etc.
- sushidev 2y agoAnd jailer from firecracker and systemd itself which has some similar capabilities
- anonzzzies 2y agoMe too, for me the ease of use is rather important. NSJail is very easy to use, I am not sure which ones I tried when looking for these tools but some of them were an absolute pain to get going. Edit: funnily, chatgpt 03-mini tells me nsjail is the second hardest to use (first = systemd) of these...
- a-french-anon 2y agoAs a bubblewrap user, beware https://github.com/containers/bubblewrap/pull/586 https://github.com/containers/bubblewrap/pull/586 still missing. The usual ^C doesn't work with your sandboxed stuff, very annoying. A cursory look at NSjail tells me its filesystem stuff is less granular than bwrap's bind mounting. Firejail can't handle : in some paths (at all, no escaping provided) which made me dump it.
- selendym 2y ago> Firejail can't handle : in some paths (at all, no escaping provided) which made me dump it. This doesn't match my experience. For example, the following works just fine in a profile file: blacklist /sys/devices/pci0000:00/* Can you give an example of what you had problems with?
- a-french-anon 2y agoLooks like this specific character got fixed. But still a lot of forbidden ones. cf https://github.com/netblue30/firejail/issues/4614 https://github.com/netblue30/firejail/issues/4614, https://github.com/netblue30/firejail/blob/master/src/firejail/macros.c#L268 https://github.com/netblue30/firejail/blob/master/src/fireja... and https://github.com/netblue30/firejail/blob/master/src/lib/common.c#L487 https://github.com/netblue30/firejail/blob/master/src/lib/co...
- yamrzou 2y agoAnd pledge(): https://justine.lol/pledge/ https://justine.lol/pledge/
- kennysoona 2y agopledge is the openbsd version of landlock, a pretty different category from the other namespace based solutions listed.
- bjackman 2y agoIt's still a reasonable comparison though. The seccomp-bpf is part of nsjail is achieving the same thing, one way to look at it is that Landlock/pledge are just a better implementation for the same approximate feature.
- kennysoona 2y agoI don't really find it reasonable, landlock type functionality is a tiny subset of what namespace based sandboxing offers. It's like comparing a scanner to authenticate ID cards against a fortified house.
- bjackman 2y agoOh yeah I was just talking specifically about the seccomp-bpf bit. It's not comparable to nsjail as a whole.
- l0kod 2y agoNamespace are very useful to build virtual environments, but I think it's important to keep in mind that they are not designed for sandboxing and don't provide security guarantees (e.g. mount point propagation), nor fine-grained access rights, nor security events (e.g. logs)... which might be OK according to use cases. Also, namespaces increase the attack surface of the kernel (e.g. vulnerabilities that can be reached through user namespaces). That being said, even if Landlock can control the most important filesystem access rights, not all of them are supported yet. New kernel releases bring new Landlock features (e.g. IPC, network control). It takes some time to build a new and safe access control system but we'll get there!
- beardedwizard 2y agoOne is not like the others - firejail is aimed at more of desktop type applications you interact with, where the others can do so but are more suited for arbitrary workloads. A parent comment mentions ebpf syscall interception, many end up combining gvisor and nsjail and seccomp.
- pveierland 2y agoAnother interesting and modern alternative is Syd written in Rust. https://gitlab.exherbo.org/sydbox/sydbox https://gitlab.exherbo.org/sydbox/sydbox