build1 publisher
An unprivileged process can confine itself to a directory list without root
Landlock has been in mainline since kernel 5.13 and needs no policy file and no administrator to confine a process to named paths. The dev.to walkthrough explaining it leaves the enforcing syscall inside a comment.
Publishers:dev.to
Reality
- Evidence30
- Adoption35
- Hype gap+45
- Incentives30
- Confidence45