Skip to content

Comment on Landlock-Ing Linuxparent

Comments

You need to be root to set those up. These are typically admin-driven policies, not dev-driven. Landlock is unprivileged, meaning that a program can set its own policy up without root.

This is massive since most ways of dropping privileges on Linux require already having significant permissions (ie: root).

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.