alip

dev.exherbo.org

No description provided.

Recent twts from alip

Bïr çïçeğïm hⒶlk ☮rmⒶnındⒶ, Fışkırdım, bⒶşkⒶldırıy☮rum! Ben bïr bıçⒶk ucuyum, KⒶvgⒶ vermïş hⒶlkınⒶ, BⒶşkⒶldırıy☮rum ïşte, VⒶrın benïm fⒶrkımⒶ ! #sydb☮x

⤋ Read More

sydb☮x-1.2.1 released with the new –dry-run mode to run programs with no restriction but inspection and the new option -d fd[0-9]|tmp option to dump system call arguments including dereferenced pointers for strings and socket addresses in JSON lines. Pand☮ra is a the new Rust tool which is a helper for sydb☮x to make sandboxing practical.https://crates.io/crates/pandora_box . See https://sydbox.exherbo.org https.//pinktrace.exherbo.org and https://pandora.exherbo.org

⤋ Read More

sydb☮x-1.2.0 is released with seccomp allowing readonly open{,at} w/o trace-stop, stricter defaults for all default sandbox modes but read, seccomp & ptrace seize usage defaulting to on & the shared memory writable restriction defaulting to on. Finally, this version implements an improved & simpler dump interface which the helper Pand☮ra can read to generate profiles for practical, daily applications such as mail client, browser etc. A sample profile for Firefox is added too! #exherbo #sydb☮x

⤋ Read More

sydb☮x-scm improves seccomp for read only open calls which is a noticable optimization considering the overall count of trace stops, see details here: https://commits.exherbo.org/sydbox-1:8bc285f which shows remarkable improvements of reduction in open{,at} calls and build times. Apart from the commit message there’s the benchmark https://git.exherbo.org/sydbox-1.git/tree/bench/2021.05.30-paludis-seccomp-open.txt on my build host which has the timing to build the current paludis-3.0.0 (scm). Help test sydb☮x-scm, report back and enjoy! #exherbo #sydb☮x

⤋ Read More