feat: Add support for Landlock based Sandbox for Linux (#238)

* feat: Initial implementation of landlock based sandbox driver

* fix: Handle seccom probe failure

* fix: Remove unnecessary seccomp probe

* fix: Use file based policy load

* fix: Keep bpf filter in memory

* fix: Use TSYNC for seccom filter

* fix: Use TSYNC for seccom filter

* fix: Update landlock translator

* fix: Landlock sandbox implementation

* fix: Landlock + seccomp based sandboxing on Linux

* fix: Misc fixes

* fix: Cleanup sandbox files

* fix: Handle mandatory deny API change post merge

* fix: Landlock write access translation

* chore: Fix linter issues

* ci: Use /tmp for npm cache for landlock
This commit is contained in:
Abhisek Datta
2026-05-07 12:42:28 +05:30
committed by GitHub
parent 5122a1594c
commit 4c42ceca0e
27 changed files with 4356 additions and 122 deletions
+1 -1
View File
@@ -80,7 +80,7 @@ func TestLoadCustomProfile(t *testing.T) {
tempFile, err := os.CreateTemp(t.TempDir(), "sandbox-policy-*.yml")
assert.NoError(t, err)
defer tempFile.Close()
defer func() { _ = tempFile.Close() }()
err = yaml.NewEncoder(tempFile).Encode(c.policy)
assert.NoError(t, err)