Painless Linux sandboxing API
ファイルへ移動
Albert S 265a19d351 Assign syscalls into groups. Add whitelist mode (default).
Classify syscalls into groups, for x86_64 only for now.
Up to date for 5.15, generate some #ifndef for syscalls
introduced since 5.10. Only support x86_64 therefore at this point.

Switch from blacklisting to a default whitelist.
2021-11-08 22:59:07 +01:00
gengroup.py Assign syscalls into groups. Add whitelist mode (default). 2021-11-08 22:59:07 +01:00
grouping_x86-64.txt Assign syscalls into groups. Add whitelist mode (default). 2021-11-08 22:59:07 +01:00
Makefile Start implementing tests 2021-06-05 20:11:07 +02:00
qssb.h Assign syscalls into groups. Add whitelist mode (default). 2021-11-08 22:59:07 +01:00
README.md README.md: Update 2021-09-05 17:12:25 +02:00
test.c Assign syscalls into groups. Add whitelist mode (default). 2021-11-08 22:59:07 +01:00
test.sh test: Refactor: Put seccomp tests into child processes ; Simplfy .sh 2021-09-05 17:12:25 +02:00

qssb.h (quite simple sandbox)

qssb.h is a simple header-only library that provides an interface to sandbox processes on Linux. Using Seccomp and Linux Namespaces for that purpose requires some knowledge of annoying details which this library aims to abstract away as much as possible, when reasonable. Hence, the goal is to provide a convenient way for processes to restrict themselves in order to mitigate the effect of exploits. Currently, it utilizes technologies like Seccomp, Namespaces and Landlock to this end.

Status

No release yet, expiremental, API is unstable, builds will break on updates of this library.

Currently, it's mainly evolving according to the needs of my other projects.

Features

  • Systemcall filtering (using seccomp-bpf)
  • restricting file system access (using Landlock and/or Namespaces)
  • dropping privileges
  • isolating the application from the network, etc.

Requirements

Kernel >=3.17

sys/capabilities.h header. Depending on your distribution, libcap might be needed for this.

While mostly transparent to users of this API, kernel >= 5.13 is required to take advantage of Landlock.

FAQ

Does the process need to be priviliged to utilize the library?

No.

It doesn't work on Debian!

You can thank a Debian-specific kernel patch for that. In the future, the library may check against that. Execute echo 1 > /proc/sys/kernel/unprivileged_userns_clone to disable that patch for now.

Examples

Contributing

Contributions are very welcome. Options:

  1. Pull-Request on github
  2. Mail to qssb at quitesimple.org with instructions on where to pull the changes from.
  3. Mailing a classic patch/diff to the same address.

License

ISC