samples/landlock: Add a sandbox manager example
Add a basic sandbox tool to launch a command which can only access a list of file hierarchies in a read-only or read-write way. Cc: James Morris <jmorris@namei.org> Cc: Serge E. Hallyn <serge@hallyn.com> Signed-off-by:Mickaël Salaün <mic@linux.microsoft.com> Reviewed-by:
Jann Horn <jannh@google.com> Reviewed-by:
Kees Cook <keescook@chromium.org> Link: https://lore.kernel.org/r/20210422154123.13086-12-mic@digikod.net Signed-off-by:
James Morris <jamorris@linux.microsoft.com>
Showing
- MAINTAINERS 1 addition, 0 deletionsMAINTAINERS
- samples/Kconfig 7 additions, 0 deletionssamples/Kconfig
- samples/Makefile 1 addition, 0 deletionssamples/Makefile
- samples/landlock/.gitignore 1 addition, 0 deletionssamples/landlock/.gitignore
- samples/landlock/Makefile 13 additions, 0 deletionssamples/landlock/Makefile
- samples/landlock/sandboxer.c 238 additions, 0 deletionssamples/landlock/sandboxer.c
Loading
Please register or sign in to comment