From: Justin Suess <utilityemal77@gmail.com>
To: Jarkko Sakkinen <jarkko@kernel.org>
Cc: landlock@lists.linux.dev
Subject: Re: Landstrip
Date: Fri, 5 Jun 2026 15:19:09 -0400 [thread overview]
Message-ID: <aiMegwnNp515dmWB@zenbox> (raw)
In-Reply-To: <ah41G3F850HLeiBQ@kernel.org>
On Tue, Jun 02, 2026 at 04:42:51AM +0300, Jarkko Sakkinen wrote:
> I played with an idea could Landlock LSM be used to do conceptually a
> better fit sandbox for programs such as Anthropic Sandbox Runtime [1].
>
> After some missteps at first I got it pulled together quite well:
>
> https://crates.io/crates/landstrip
>
> To see it in action I also have a fork of pi-hashline-readmap plugin,
> which was a cherry-picked test case I wanted to try out given it already
> hooks the bash tool command for compressed output.
>
> I just thought that this might interest some as Landlock is not really
> over-used kernel feature in "application sense".
>
> This is a more lower barrier and more failure tolerant to deploy than
> Bubblewrap based container for this use and purpose in my opinion
> at least.
>
Very cool! Landlock is great for this usecase of application driven
sandboxing.
(just a quick note, the linux-security-module/linux-integrity
mailing lists mostly for kernel development patches, the
landlock.lists.linux.dev list is more for
userspace Landlock topics like this. so I removed the cc for
linux-security-module/linux-integrity and added that list)
I notice there is a seccomp policy for unix sockets in this application.
Although it might not be in your kernel yet, support for sandboxing
named unix sockets with Landlock was recently merged. :)
https://lore.kernel.org/linux-security-module/20260327164838.38231-1-gnoack3000@gmail.com/
Justin
> [1] https://github.com/anthropic-experimental/sandbox-runtime/issues/291
> [2] https://github.com/jarkkojs/pi-hashline-readmap
>
> BR, Jarkko
>
prev parent reply other threads:[~2026-06-05 19:19 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-02 1:42 Landstrip Jarkko Sakkinen
2026-06-05 19:19 ` Justin Suess [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aiMegwnNp515dmWB@zenbox \
--to=utilityemal77@gmail.com \
--cc=jarkko@kernel.org \
--cc=landlock@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.