From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from atuin.qyliss.net (localhost [IPv6:::1]) by atuin.qyliss.net (Postfix) with ESMTP id 93721137AA; Thu, 04 Dec 2025 02:22:09 +0000 (UTC) Received: by atuin.qyliss.net (Postfix, from userid 993) id 82E00136DD; Thu, 04 Dec 2025 02:21:57 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 4.0.1 (2024-03-26) on atuin.qyliss.net X-Spam-Level: X-Spam-Status: No, score=-0.1 required=3.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,DMARC_PASS,FREEMAIL_FROM,RCVD_IN_DNSWL_NONE, SPF_HELO_NONE autolearn=unavailable autolearn_force=no version=4.0.1 Received: from mail-yx1-xb12c.google.com (mail-yx1-xb12c.google.com [IPv6:2607:f8b0:4864:20::b12c]) by atuin.qyliss.net (Postfix) with ESMTPS id 24AC9136BF for ; Thu, 04 Dec 2025 02:21:55 +0000 (UTC) Received: by mail-yx1-xb12c.google.com with SMTP id 956f58d0204a3-6443b62daf6so346815d50.0 for ; Wed, 03 Dec 2025 18:21:53 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1764814913; x=1765419713; darn=spectrum-os.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to; bh=iA+Fw/lwVCf10L6eWxdfJ22D/2QMByvV02Vg9Kahb9g=; b=nM1Z0QGI2PhsPUmP48sCMMs4Pj7sYMf3TBscxWLNSntQ14fFEqwnCsWvtTFEim+/fx XogYcm7eqVS8hYUpsXv/wjO46X175hB1EsJek4Plb+s7mLjco5mBqbX9EY89GMo32or8 fPA+e4+vx9+u/bouTn8MjH5VqAbESjuydEZxCCj6JKI/35MRkAiy5eFZZ3B0qjmegbjs DkG2Q7oKKKt4+K/8BgND+p1GRnV3ilMTka7cgeGm+0ZpV8fcUOBJQfpKY2J+wasZPlud rwNp4y/zq4URD/WrJRkZcBTTEbYmMgSzeQqwU/uCCKbY8WJeIo+eDYfwWDY1YWLga2Z5 YgoA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1764814913; x=1765419713; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to; bh=iA+Fw/lwVCf10L6eWxdfJ22D/2QMByvV02Vg9Kahb9g=; b=TCHlnxRUw5I7fai37TXCG3mZEzFBUrzdxjAhjxFfekfy6zt+zpTwD9+ALc4XIzQ0MG /K7AeF/pyaS1HzCRRLRjdcTOGemT9oQOu9htiguVEp5OnesUcgZucwxMtPxHy7ewUEYM JzVEXtNQ/oeINSGyGf77macup6KAXKk9E0wjRTEBrRaiZb4y+2jS4dpVmLgxevr6brGt 1dzbHX7URqhdRfOMu4q/YJiyIQUkYmWqGUyfX1fi8nnEKY+UB/GdIyyAOYmE+qckfzQe YcKyllyU6+vtVIbj8BmVYFP668L2WSNlYqgjK5zdQx7a/eOIKNbdlnYA338z0X9svPUc Zs0Q== X-Gm-Message-State: AOJu0Yz0dZLLbZAPzuhfPL8e9ErllnUC4MpA35F27e3yMM4G7PztbOCK wDUtHUQzrNd6Y+C9+4Hzlf6EClTeal99QCw3Jbw+6OcMwcZtbUv0iyY9K/9ZrQ== X-Gm-Gg: ASbGncvugrCq/uLKG7k5+dXZaQdT1McBV5ktlpKx/srpOjxZaV4NE9syZ+rB1bgCCJV taaztg4QY7YYohQuN/RZjy2NAPMdi7vt9OLNen/v9dPVQIUOFEoUNPlFB+iZ97Q25BdrFQ8AELV jw4NabBrCbFX7tRw6qbUKlo6zJylXrHsIPuVYYKx1HnUNlrrLNP9R87Wdark3BydO0QVF6GMFKy RCcX0WQGwNJtlmgpLJXxGjAwtfOFOCkZeYOWYwn4Ve+AAyMY9YTqHuq8cH1Frv2NGmgGTYbQcrF ANMje2XKXCB8D15jrSpdhCsjreKJ5dcCKk71XsDtx4Ki9FOcH4ffaSlRRhbBHcEULDMj7d30h9+ y+YyJoHMA8RTuL/FAnHO2C8evdEjvvb2XHqcwRCKbNTPBQC4CbMLTDaBF5r8OfRqZKt//5lUkqo fB7FpKDlRCermUIQn2KD4e5wuGwtxNNyGPT7iGXxUAPeLRqI+DUmXd9XiehqzIZyidkEHKRYg+x 9Ejv/30F6VjvVzTbtJD1s5QQmMv4YUHQkTLax11p/0q3g== X-Google-Smtp-Source: AGHT+IEwUHZrt2G9zL4fqFsjL8BRk8NNc1Cofde6GqUD9jShj94CaFuPDvtPf4wyjaPCAhG6cquXHg== X-Received: by 2002:a05:690e:128b:b0:640:db91:33b7 with SMTP id 956f58d0204a3-64436fc5c5amr3513693d50.19.1764814912483; Wed, 03 Dec 2025 18:21:52 -0800 (PST) Received: from localhost.localdomain (h96-60-249-169.cncrtn.broadband.dynamic.tds.net. [96.60.249.169]) by smtp.gmail.com with UTF8SMTPSA id 956f58d0204a3-6443f5a3e81sm148264d50.16.2025.12.03.18.21.51 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 03 Dec 2025 18:21:52 -0800 (PST) From: Demi Marie Obenour Date: Wed, 03 Dec 2025 21:20:43 -0500 Subject: [PATCH v4 6/6] host/rootfs: "Sandbox" Weston MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Message-Id: <20251203-sandbox-v4-6-71542a7dcf5c@gmail.com> References: <20251203-sandbox-v4-0-71542a7dcf5c@gmail.com> In-Reply-To: <20251203-sandbox-v4-0-71542a7dcf5c@gmail.com> To: Spectrum OS Development X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=ed25519-sha256; t=1764814837; l=835; i=demiobenour@gmail.com; s=20250729; h=from:subject:message-id; bh=F6lIguRdspGvt0qRIqs57mPEsNXAu/L3bDqQn7IOvHw=; b=iuDWmAuIfTrovX4eVoHFRrsMeB/vJDBG40QdR9tlvZBf0uEYUFbeVMMnGFoH0Srt3EX1cs2op VSpGc8GzwQXBuKKy8Q2iaqtKkj+A0X0X3uPRFgw+QLOj6Sb44R1zDA2 X-Developer-Key: i=demiobenour@gmail.com; a=ed25519; pk=X57Q4/YQDj9t4SBeKaDwvXYKB6quZJVx/DE2Ly2out0= Message-ID-Hash: N3FVYG5JR2G562ZI4SYQPOYIDB3AYPN3 X-Message-ID-Hash: N3FVYG5JR2G562ZI4SYQPOYIDB3AYPN3 X-MailFrom: demiobenour@gmail.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-devel.spectrum-os.org-0; header-match-devel.spectrum-os.org-1; header-match-devel.spectrum-os.org-2; header-match-devel.spectrum-os.org-3; header-match-devel.spectrum-os.org-4; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: Demi Marie Obenour , Alyssa Ross X-Mailman-Version: 3.3.9 Precedence: list List-Id: Patches and low-level development discussion Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: This is not a true sandbox, but it does protect Weston from other code that tries to connect to an abstract namespace socket or System V IPC object. Cgroup, IPC, network, and UTS namespaces are unshared. Signed-off-by: Demi Marie Obenour --- host/rootfs/image/etc/s6-rc/weston/run | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/host/rootfs/image/etc/s6-rc/weston/run b/host/rootfs/image/etc/s6-rc/weston/run index c1bce8505944b68c75c1b87d1ae736ff655e0f07..12e5d702b976c165249ac9f8078ce6434fbb43b1 100644 --- a/host/rootfs/image/etc/s6-rc/weston/run +++ b/host/rootfs/image/etc/s6-rc/weston/run @@ -18,4 +18,9 @@ redirfd -r 0 /dev/tty1 importas -i home HOME cd $home if { udevadm wait /dev/dri/card0 } +unshare + --cgroup + --ipc + --net + --uts weston -- 2.52.0