Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Linux 5.13 was the first kernel release with Landlock incorporated, but the Landlock project is from 2016 also.

I found the announcement email for Landlock posted to the lkml[1] where the author compares the project to Pledge. There's also his talk[2] from 2016 if you're interested. I was certain landlock predated pledge, as I thought the website or earliest talk was from late 2015, but I am less certain now, indeed I seem to have been wrong in my claim.

As for either being the first, at the very least Seatbelt from Apple has a paper dated 2011[3] and was released with macOS 10.5.

[1] https://lwn.net/Articles/700607/

[2] https://archives.kernel-recipes.org/document/landlock-lsm-un...

[3] https://www.ise.io/wp-content/uploads/2017/07/apple-sandbox....



OpenBSD's pledge(2) was first talked about publicly as tame(2), and was presented in at FSec 2015, it was renamed pledge(2) as mentioned on the OpenBSD 5.9 page.

https://www.openbsd.org/papers/tame-fsec2015/

https://man.openbsd.org/OpenBSD-5.8/tame

https://www.openbsd.org/59.html


I thought I had remembered something from Landlock from 2015 also, but can't find anything supporting that. The first version referenced is v7 or v0.7, so it's possible there was a talk for v0.1 or something that isn't online anywhere.

I'll concede that's less likely and I'm probably just wrong and misremembering though.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: