MDRSS ยท MARKDOWN SNAPSHOT
0.0/10

Sandlock

Confines untrusted code using Landlock (filesystem + network + IPC), seccomp-bpf (syscall filtering), and seccomp user notification (resource limits, IP enforcement, /proc virtualization). Sandlock targets the gap: strict confinement without image builds or root privileges.

#ai-agents / card #1566โ˜… 0โ—Œ 0snapshot 2026-08-04