MDRSS · MARKDOWN SNAPSHOT
0.0/10

Sandlock

Confines untrusted code using Landlock (filesystem + network + IPC), seccomp-bpf (syscall filtering), and seccomp user notification (resource limits, IP enforcement, /proc virtualization). Sandlock targets the gap: strict confinement without image builds or root privileges.

#ai-agents / card #1566★ 0◌ 0snapshot 2026-08-04