New Sandboxing Linux Security Module Coming

Discussion in 'all things UNIX' started by AutoCascade, Oct 31, 2019.

  1. AutoCascade

    AutoCascade Registered Member

    Joined:
    Feb 16, 2014
    Posts:
    741
    Location:
    United States
    https://www.phoronix.com/scan.php?page=news_item&px=Landlock-11-Linux-LSM



     
  2. summerheat

    summerheat Registered Member

    Joined:
    May 16, 2015
    Posts:
    2,225
    Yes, I had read that earlier. Sounds promising.
     
  3. AutoCascade

    AutoCascade Registered Member

    Joined:
    Feb 16, 2014
    Posts:
    741
    Location:
    United States
    This would be something Firejail could make use of as well as browsers correct?
     
  4. summerheat

    summerheat Registered Member

    Joined:
    May 16, 2015
    Posts:
    2,225
    I guess that would be possible.
     
  5. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,911
    Location:
    Outer space
    Anyone using this? It was integrated in mainline kernel last June (5.13).
     
  6. summerheat

    summerheat Registered Member

    Joined:
    May 16, 2015
    Posts:
    2,225
    FWIW, there is a pull request to add Landlock support to Firejail. We'll see what comes out of this.
     
  7. summerheat

    summerheat Registered Member

    Joined:
    May 16, 2015
    Posts:
    2,225
    Landlock has been added to Firejail. The README says, that Landlock support is "experimental" and disabled by default. It will be probably officially added in v. 0.9.74 early next year.
     
  8. EASTER

    EASTER Registered Member

    Joined:
    Jul 28, 2007
    Posts:
    11,482
    Location:
    U.S.A. (South)
    Exciting to learn of this and i/m looking forward to its official addition.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.