nitter
Justin Cormack
@justincormack
13 May 2015
Note how the FreeBSD sandbox "cap_enter()" fits in a tweet compared to complexity of Linux, OpenBSD
github.com/brynet/file/blob/โฆ
3
3
Daniel Silverstone ๐๐๐๐ยฒ ๐ณ๏ธโ๐๐ฌ๐ง
@dsilverstone
13 May 2015
Replying to
@justincormack
@justincormack
@fanf
Looks somewhat less flexible though.
May 13, 2015 ยท 12:38 PM UTC
2
Justin Cormack
@justincormack
13 May 2015
Replying to
@dsilverstone
@dsilverstone
@fanf
it can be tweaked with cap_rights but default sane. But yes technically less flexible...
Justin Cormack
@justincormack
13 May 2015
Replying to
@dsilverstone
@dsilverstone
@fanf
but the flexibility vastly increases complexity. Eg the comments about not sandboxing ioctl in the OpenBSD code
1
more replies