rvstaveren, Dutch
@rvstaveren@mastodon.online avatar

Just a thought… Wouldn’t it be nice if capsicum in #FreeBSD could be used in such way that you didn’t need to alter binaries, but from e.g. daemon(8) which would jail your binaries with the restricted capabilities

mpts,
@mpts@mastodon.social avatar

@rvstaveren There you go:

https://papers.freebsd.org/2020/bsdcan/stone-oblivious_sandboxing_capsicum_ebpf/

It is called oblivious sandboxing AFAIK.

Ryan Stone has worked on it at one point. I don't remember the details though.

feld,
@feld@bikeshed.party avatar

@mpts @rvstaveren if you just want to use jails for all services you can modify rc.subr to add a new jailing feature where it just shares the same root filesystem but all the services you specify are in a jail with some lowered capabilities and it behaves like a cgroup in that fashion

I wish some people took this seriously and pushed it as a core feature because it would rule

rvstaveren,
@rvstaveren@mastodon.online avatar

@feld @mpts yes definitely! The reason I mentioned capsicum was that the jailing could even go deeper than that and keep processes unprivileged right from the start

  • All
  • Subscribed
  • Moderated
  • Favorites
  • FreeBSD
  • DreamBathrooms
  • everett
  • InstantRegret
  • magazineikmin
  • thenastyranch
  • rosin
  • Durango
  • ethstaker
  • Youngstown
  • slotface
  • khanakhh
  • kavyap
  • ngwrru68w68
  • osvaldo12
  • JUstTest
  • tacticalgear
  • cubers
  • cisconetworking
  • anitta
  • provamag3
  • modclub
  • mdbf
  • GTA5RPClips
  • tester
  • megavids
  • normalnudes
  • Leos
  • lostlight
  • All magazines