> my effects system compiles to a seccomp + apparmor profile so that your rust program is sandboxed at runtime based on info at compile time.
is this open or proprietary? I'd love a link to a repo
is this open or proprietary? I'd love a link to a repo
Here's a little snippet:
#[effect::declare(
args=(inner_tmp as I)
returns=("/tmp/" + I)
)]
fn tmp_dir(inner_tmp: Path) -> Path {
Path::from("tmp/").join(inner_tmp)
}
So it can reason about that Path's constraints. When that Path gets used by, say, "File::create(path)", it gets turned into a rule and added to an apparmor policy.Apparmor doesn't support a "hey I'm a process, please sandbox me" so I have to write a privileged daemon that manages that bit.
I also have a way to apply effects to functions you don't own, mutating functions, functions that branch, etc. None of that is implemented yet, just designed.
- Github : https://github.com/insanitybit
- Twitter: https://twitter.com/InsanityBit