Comment by als0

Comment by als0 3 days ago

2 replies

If the application in the container wants to add more restrictive rules then it should be allowed to. But it should not be able to mess with the existing rules imposed by the container manager. This would be the ideal outcome.

arianvanp 3 days ago

There is nothing to do here. Landlock already a guarantees that you can't undo rules that were already applied. Your application can further restrict itself but it can't unrestrict itself.

  • als0 3 days ago

    Just need the container manager to not block the landlock system call