|
|
|
|
|
by codedokode
3 days ago
|
|
I also wanted to limit access to files/directories inside /proc/PID, or provide fake data. The /proc/PID also contains too many data. Also, I might want to provide some fake data, for example, if app relies on reading /proc/cmdline or /proc/cpuinfo. So the app should be able to read the files, but not the real data. > And most sandboxes disallow unprivileged CLONE_NEWUSER with seccomp I ma worried that some applications (like Chrome, Electron-based apps) might not work without user namespaces. GTK uses "glycin" library, it launches subprocesses for handling images in a bwrap-based sandbox, and it broke inside my sandbox, so I had to do quick fixes for it. No, sandboxing in Linux is not easy. Just look at "man capabilities" or "man user_namespaces" and see how many rules and exceptions from rules are there. You need to understand it if you write a sandbox, but it is so complicated. And obviously AI cannot be trusted with such a responsible task. |
|