Landrun: sandboxing Linux processes without root
Summary
Landrun makes Landlock rules usable as an unprivileged command line sandbox for any Linux process. Landlock file system protection has existed since Linux 5.13. TCP restrictions require at least Linux 6.7 and ABI 4.
Ideas
- Processes can permanently restrict their own rights and those of their children.
- Landlock complements existing Unix permissions as a stackable Linux Security Module.
- File rules distinguish reading, writing, executing and directory operations.
- Newer ABIs restrict TCP ports, signals and Unix sockets.
- Strict mode prevents unnoticed loss of protection on older kernels.
Insights
- Self-restriction reduces potential damage without a privileged sandbox daemon.
- Compatibility modes trade availability for verifiable security guarantees.
- Resources that are already open limit isolation that is set up afterwards.
Facts
- Files opened before the sandbox are not subsequently subject to all rules.
Recommendations
- In security-relevant use, choose strict mode rather than silent downgrading.
- Only allow documented paths, libraries and network destinations.
References
Links to the original source and the Web Archive open in a new tab.