3 ms·
Interesting no mentioned about OpenBSD pledge(2), unveil(2). By far the easiest sandboxing out there. An example: #ifdef OpenBSD if(pledge("stdio r
by jmclnx 12d ago
Interesting no mentioned about OpenBSD pledge(2), unveil(2). By far the easiest sandboxing out there. An example:
#ifdef OpenBSD
if(pledge("stdio rpath wpath cpath",NULL) == -1)
err(1,"pledge\n");
#endif
Very easy, all the other examples seem rather complex to me. unveil(2) is just as easy.
- mitxela 12d agoWorks because OpenBSD has totalitarian control of the ecosystem, just like Windows. Wouldn't work on Linux because what do those flags even mean to the kernel?
- shiomiru 12d agoThis is often repeated in these kinds of threads, but I don't think it's true. You just have to implement it in glibc, which can map the flags to the actual syscalls used on the current architecture and restrict the process to those with a seccomp BPF filter. (Indeed, cosmo libc does exactly that, so it's definitely possible.)