Firejail – Simple Linux sandbox with seccomp
l3net.wordpress.com
l3net.wordpress.com
> Also: https://github.com/arachsys/containers https://github.com/ghedo/pflask https://github.com/vincentbernat/jchroot https://github.com/vi/dive
> But seccomp in Firejail is a distinctive feature.
Looks like mbox doesnt use file system namespaces to isolate a process from fs, but instead combines seccomp and ptrace.
Hm, Ill try to use this to record a programs interactions with the network, tcpdump listens to _all_ the traffic and I havent found a good way yet to filter only on a certain process.
But its not yet there, mbox is closest - as it can intercept any socket syscalls from a process, and then choose to deny based on the socket syscall arguments. Firejail could do the same, as it also has seccomp filters.
Firejail is pre-compiled with syscall filter table, but could be extended/fixed to provide those in a config file.
Hm, actually Im thinking firejail extended like this - firejailed process could be run in its own network namespace, catch any socket syscalls with a seccomp-filter, show what the process attempted to do to the user (through syslog or another daemon listening to present question to user with choice of UI), then if he denies/accepts it - run iptables -A OUTPUT -j REJECT/DROP/ACCEPT in the namespace of the process. Then save the "profile" for the process somewhere for next time it is invoked with firejail! Yes, yes, this would be quite nice!
And all of this, even the invocation of programs using firejail with their respective profiles could be automated/integrated seamlessly, with say KDE! This would be BEAUTIFUL.
Firejail adds easy seccomp - right now only about 4-5 syscalls are blacklisted, but it would be gravy to specify a whitelist of syscalls and arguments on the command line to firejail.
Other security improvments to do is to run with grsecurity, or just use alpine linux - it has all binaries compiled with stack-protection position independent code.