Landlock is a simple, unprivileged, deny-by-default sandboxing mechanism for Linux. It’s easy to understand, easy to integrate, and has tremendous potential for improving desktop and application security. Because Landlock requires no privileges to use, adding it to most programs is straightforward. Bindings exist for languages such as Rust, Go, and Haskell, and several projects provide user-friendly unveil-style wrappers.

blog.prizrak.me/post/landlock/

0

If you have a fediverse account, you can quote this note from your own instance. Search https://mastodon.social/users/nixCraft/statuses/115638595998025176 on your instance and quote it. (Note that quoting is not supported in Mastodon.)