MDRSS · MARKDOWN SNAPSHOT
0.0/10
Sandlock
Confines untrusted code using Landlock (filesystem + network + IPC), seccomp-bpf (syscall filtering), and seccomp user notification (resource limits, IP enforcement, /proc virtualization). Sandlock targets the gap: strict confinement without image builds or root privileges.