cloudflare / cloudflare/sandbox

ld_audit vs ld_preload for sandbox

Open
#13 4 comments 0 reactions 0 assignees View on GitHub
Dominant language
C
Stars
533
Forks
32
PR merge metrics
No merged PRs in 30d

Description

This [article](https://labs.sentinelone.com/leveraging-ld_audit-to-beat-the-traditional-linux-library-preloading-technique/) mentions that LD_AUDIT is an alternative for LD_PRELOAD. Does ld_audit offer any benefits over ld_preload for sandbox?

Contributor guide

Open the contributing guide

Research direction

Start by reading the linked SentinelOne article and the sandbox repository description to understand how LD_AUDIT and LD_PRELOAD relate to seccomp-based sandboxing. Compare the potential benefits of LD_AUDIT for this sandbox, then document a clear conclusion or proposal for whether it should be supported.

Written by the indexing model from the issue text.

Assessment

Tech stack
c, linux
Domain
operating-systems, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.