cloudflare / cloudflare/sandbox
Apply sandbox to specific users and/or system wide?
Open
- Dominant language
- C
- Stars
- 533
- Forks
- 32
- PR merge metrics
- No merged PRs in 30d
Description
Is it possible to apply sandbox to all programs that are run by a specific user or group? Is it possible to apply it system wide?
Perhaps combine it with apparmor style profiles/config files for each binary.
Contributor guide
Research direction
The issue names no files, tests, or entry points. Start by reviewing the sandbox's current Linux seccomp behavior and how programs are selected for sandboxing. Done would require a maintainer-confirmed design or implementation for per-user, per-group, and system-wide application, including whether AppArmor-style profiles are in scope.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- c, linux
- Domain
- operating-systems, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100