Apply sandboxing #29

Closed
opened 2026-01-07 08:18:25 +01:00 by oysteikt · 1 comment
Owner

finger in particular requires access to a bunch of different files in /home/<user>. We should figure out what we need, and sandbox the service not to be able to access anything else.

Systemd does not seem to be able to sandbox with globs atm, so maybe landlock at the start of the service is the way to go. look into unveil for the bsds

finger in particular requires access to a bunch of different files in `/home/<user>`. We should figure out what we need, and sandbox the service not to be able to access anything else. Systemd does not seem to be able to sandbox with globs atm, so maybe landlock at the start of the service is the way to go. look into `unveil` for the bsds
oysteikt added the security label 2026-01-07 08:18:25 +01:00
oysteikt added this to the Initial release milestone 2026-01-16 08:18:37 +01:00
Author
Owner

I'll pick up the landlock stuff when it becomes relevant, rwhod doesn't need it at this point

I'll pick up the landlock stuff when it becomes relevant, rwhod doesn't need it at this point
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: Projects/roowho2#29