Comments

  • higgsboson@piefed.social
    link
    fedilink
    English
    arrow-up
    4
    ·
    5 days ago

    Landlock is a Linux API that lets applications explicitly declare which resources they are allowed to access. Its philosophy is similar to OpenBSD’s unveil() and (less so) pledge(): programs can make a contract with the kernel stating, “I only need these files or resources — deny me everything else if I’m compromised.”