A Highly Portable Sandbox Facility For OpenBSD
An Anonymous Coward writes: "A new facility called 'systrace' has been developed by one of the OpenBSD developers. It allows enforcement of system call policies on untrusted binaries. For now it is only available OpenBSD-current, but the author claims it is highly portable and can easily be integrated into GNU/Linux systems. Eventually binary-only software is going to become more and more common in Linux, so this could be a another 'Good Thing(TM)' from the paranoids that brought us OpenSSH."
What sort of performance hit does this impose? For instance, is it low enough to run nearly everything in the sandbox as a matter of course?
Protoplasm. Quiet Protoplasm. I like quiet protoplasm.