3 ms·
Are (abstract) unix sockets supported? I'm trying to run a self-contained webserver executable without any external dependency. It starts but daemon <-> worker
by trikko 2y ago
Are (abstract) unix sockets supported?
I'm trying to run a self-contained webserver executable without any external dependency. It starts but daemon <-> workers communication doesn't seem working (it is done via unix socket)
It works fine with bubblewrap or inside a scratch docker container.
- deleted 2y ago[deleted]
- dsp_person 2y agoaren't abstract sockets un-jailable unless using network namespaces? or in the other direction, to truly prevent e.g. xorg socket from being accessed by a bubblejailed application, it should exclude --share-net, regardless if you bind the actual path to the socket (since abstract permeates beyond that)
- trikko 2y agoWell, so should it work? You're telling me there's another reason, then... Can't guess which one. Hmmm...
- Zoup 2y agothey can be jailed by landlock, we don't have support in go-landlock tho afaik, @Gnoack
- gnoack 2y agoIt's tracked in https://github.com/landlock-lsm/go-landlock/issues/35 https://github.com/landlock-lsm/go-landlock/issues/35 - signals and abstract Unix sockets do unfortunately not interact well with the inherently multithreaded Go runtime. We are working on a fix in https://github.com/landlock-lsm/go-landlock/issues/36 https://github.com/landlock-lsm/go-landlock/issues/36 but this needs to be on the kernel side and this is delaying this feature in Go, unfortunately. It is usable from (single threaded) C programs though.
- Zoup 2y agoThanks!