<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:webfeeds="http://webfeeds.org/rss/1.0" xmlns:media="http://search.yahoo.com/mrss/">
  <channel>
    <title>alip</title>
    <description>Public posts from @alip@mastodon.online</description>
    <link>https://mastodon.online/@alip/tagged/exherbo</link>
    <image>
      <url>https://files.mastodon.online/accounts/avatars/000/194/530/original/0757c39f505e1e33.jpg</url>
      <title>alip</title>
      <link>https://mastodon.online/@alip/tagged/exherbo</link>
    </image>
    <lastBuildDate>Mon, 08 Jun 2026 06:33:06 +0000</lastBuildDate>
    <webfeeds:icon>https://files.mastodon.online/accounts/avatars/000/194/530/original/0757c39f505e1e33.jpg</webfeeds:icon>
    <generator>Mastodon v4.6.0-nightly.2026-06-12</generator>
    <item>
      <guid isPermaLink="true">https://mastodon.online/@alip/116713087757014189</guid>
      <link>https://mastodon.online/@alip/116713087757014189</link>
      <pubDate>Mon, 08 Jun 2026 06:33:06 +0000</pubDate>
      <description>&lt;p&gt;&lt;a href="https://mastodon.online/tags/Sydbox" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;Sydbox&lt;/span&gt;&lt;/a&gt; 3.55.0 is released! Introduces Domain Transitions to change sandbox policy manually or based on a set of events. IPC thread is hardened to set a limit on max connections and disconnect idle connections. Includes some minor security fixes for sandbox capabilities as well. Full story: &lt;a href="https://gitlab.exherbo.org/sydbox/sydbox/-/blob/main/ChangeLog.md" target="_blank" rel="nofollow noopener" translate="no"&gt;&lt;span class="invisible"&gt;https://&lt;/span&gt;&lt;span class="ellipsis"&gt;gitlab.exherbo.org/sydbox/sydb&lt;/span&gt;&lt;span class="invisible"&gt;ox/-/blob/main/ChangeLog.md&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/exherbo" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;exherbo&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/linux" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;linux&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/security" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;security&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;</description>
      <category>sydbox</category>
      <category>exherbo</category>
      <category>linux</category>
      <category>security</category>
    </item>
    <item>
      <guid isPermaLink="true">https://mastodon.online/@alip/116709717570321801</guid>
      <link>https://mastodon.online/@alip/116709717570321801</link>
      <pubDate>Sun, 07 Jun 2026 16:16:01 +0000</pubDate>
      <description>&lt;p&gt;&lt;a href="https://mastodon.online/tags/Sydbox" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;Sydbox&lt;/span&gt;&lt;/a&gt; now passes Linux Testing Project tests on &lt;a href="https://mastodon.online/tags/x32" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;x32&lt;/span&gt;&lt;/a&gt; architecture. Portability matters, even if x32 is very little in use, it has similarities to architectures such as &lt;a href="https://mastodon.online/tags/mips64n32" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;mips64n32&lt;/span&gt;&lt;/a&gt; which we cannot easily test. &lt;a href="https://mastodon.online/tags/exherbo" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;exherbo&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/linux" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;linux&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/security" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;security&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;</description>
      <category>sydbox</category>
      <category>x32</category>
      <category>mips64n32</category>
      <category>exherbo</category>
      <category>linux</category>
      <category>security</category>
    </item>
    <item>
      <guid isPermaLink="true">https://mastodon.online/@alip/116708767923188752</guid>
      <link>https://mastodon.online/@alip/116708767923188752</link>
      <pubDate>Sun, 07 Jun 2026 12:14:31 +0000</pubDate>
      <description>&lt;p&gt;News from &lt;a href="https://mastodon.online/tags/Sydbox" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;Sydbox&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/git" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;git&lt;/span&gt;&lt;/a&gt;: As of version 3.55.0, bind mounts are secure by default. Regardless of whether the source is an absolute path or a filesystem type, every bind is mounted with nodev, noexec, nosuid, and nosymfollow options applied. User must therefore explicitly opt back into the relaxed behaviour upfront using the options dev, exec, suid and symfollow: &lt;a href="https://man.exherbo.org/syd.2.html#bind" target="_blank" rel="nofollow noopener" translate="no"&gt;&lt;span class="invisible"&gt;https://&lt;/span&gt;&lt;span class=""&gt;man.exherbo.org/syd.2.html#bind&lt;/span&gt;&lt;span class="invisible"&gt;&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/exherbo" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;exherbo&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/linux" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;linux&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/security" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;security&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;</description>
      <category>sydbox</category>
      <category>git</category>
      <category>exherbo</category>
      <category>linux</category>
      <category>security</category>
    </item>
    <item>
      <guid isPermaLink="true">https://mastodon.online/@alip/116698010293795813</guid>
      <link>https://mastodon.online/@alip/116698010293795813</link>
      <pubDate>Fri, 05 Jun 2026 14:38:43 +0000</pubDate>
      <description>&lt;p&gt;News from &lt;a href="https://mastodon.online/tags/Sydbox" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;Sydbox&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/git" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;git&lt;/span&gt;&lt;/a&gt; for &lt;a href="https://mastodon.online/tags/Emacs" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;Emacs&lt;/span&gt;&lt;/a&gt; users: Self-contained syd.el which has full support for the syd(2) API now supports syntax hilighting for syd-3 profiles exactly like Syd&amp;#39;s &lt;a href="https://mastodon.online/tags/vim" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;vim&lt;/span&gt;&lt;/a&gt; syntax hilighting. &lt;br /&gt;&lt;a href="https://mastodon.online/tags/exherbo" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;exherbo&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/linux" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;linux&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/security" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;security&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;</description>
      <category>sydbox</category>
      <category>git</category>
      <category>emacs</category>
      <category>vim</category>
      <category>exherbo</category>
      <category>linux</category>
      <category>security</category>
    </item>
    <item>
      <guid isPermaLink="true">https://mastodon.online/@alip/116696707026040189</guid>
      <link>https://mastodon.online/@alip/116696707026040189</link>
      <pubDate>Fri, 05 Jun 2026 09:07:16 +0000</pubDate>
      <description>&lt;p&gt;News from &lt;a href="https://mastodon.online/tags/sydbox" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;sydbox&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/git" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;git&lt;/span&gt;&lt;/a&gt;: We have &lt;a href="https://mastodon.online/tags/Caitsith" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;Caitsith&lt;/span&gt;&lt;/a&gt; like Domain Transitions now which allows you to change sandbox policy atomically either manually or upon certain events such as exec, chdir, mmap, bind, connect, accept. One example would be restricten the confinement of a web server upon first bind another example is per-directory sandbox policies. There&amp;#39;re many other nice uses, see examples: &lt;a href="https://man.exherbo.org/syd.7.html#Domain_Transitions" target="_blank" rel="nofollow noopener" translate="no"&gt;&lt;span class="invisible"&gt;https://&lt;/span&gt;&lt;span class="ellipsis"&gt;man.exherbo.org/syd.7.html#Dom&lt;/span&gt;&lt;span class="invisible"&gt;ain_Transitions&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/exherbo" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;exherbo&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/linux" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;linux&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/security" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;security&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;</description>
      <category>sydbox</category>
      <category>git</category>
      <category>caitsith</category>
      <category>exherbo</category>
      <category>linux</category>
      <category>security</category>
    </item>
    <item>
      <guid isPermaLink="true">https://mastodon.online/@alip/116663609177075489</guid>
      <link>https://mastodon.online/@alip/116663609177075489</link>
      <pubDate>Sat, 30 May 2026 12:50:03 +0000</pubDate>
      <description>&lt;p&gt;&lt;a href="https://mastodon.online/tags/Sydbox" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;Sydbox&lt;/span&gt;&lt;/a&gt; 3.54.1 released! Security release with fcntl(2) hardening against SIGIO bypass of &lt;a href="https://mastodon.online/tags/landlock" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;landlock&lt;/span&gt;&lt;/a&gt; signal scoping. Adds log rate limiting with log/rlimit_interval and log/rlimit_burst options. New deleted file access mediation denies unlinked files through open fds. chown(2) confined to caller&amp;#39;s credentials by default, force_umask default now 7000 for setuid/setgid/sticky stripping like &lt;a href="https://mastodon.online/tags/OpenBSD" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;OpenBSD&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/pledge" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;pledge&lt;/span&gt;&lt;/a&gt;. Ghost mode implies lock:on. Full story: &lt;a href="https://gitlab.exherbo.org/sydbox/sydbox/-/blob/main/ChangeLog.md" target="_blank" rel="nofollow noopener" translate="no"&gt;&lt;span class="invisible"&gt;https://&lt;/span&gt;&lt;span class="ellipsis"&gt;gitlab.exherbo.org/sydbox/sydb&lt;/span&gt;&lt;span class="invisible"&gt;ox/-/blob/main/ChangeLog.md&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/exherbo" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;exherbo&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/linux" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;linux&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/security" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;security&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;</description>
      <category>sydbox</category>
      <category>landlock</category>
      <category>openbsd</category>
      <category>pledge</category>
      <category>exherbo</category>
      <category>linux</category>
      <category>security</category>
    </item>
    <item>
      <guid isPermaLink="true">https://mastodon.online/@alip/116615286374185667</guid>
      <link>https://mastodon.online/@alip/116615286374185667</link>
      <pubDate>Fri, 22 May 2026 00:00:56 +0000</pubDate>
      <description>&lt;p&gt;New hardening in &lt;a href="https://mastodon.online/tags/sydbox" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;sydbox&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/git" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;git&lt;/span&gt;&lt;/a&gt;: Deleted File Access Mediation, inspired by &lt;a href="https://mastodon.online/tags/AppArmor" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;AppArmor&lt;/span&gt;&lt;/a&gt; flag PATH_MEDIATE_DELETED: &lt;a href="https://man.exherbo.org/syd.7.html#Deleted_File_Access_Mediation" target="_blank" rel="nofollow noopener" translate="no"&gt;&lt;span class="invisible"&gt;https://&lt;/span&gt;&lt;span class="ellipsis"&gt;man.exherbo.org/syd.7.html#Del&lt;/span&gt;&lt;span class="invisible"&gt;eted_File_Access_Mediation&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/exherbo" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;exherbo&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/linux" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;linux&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/security" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;security&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;</description>
      <category>sydbox</category>
      <category>git</category>
      <category>apparmor</category>
      <category>exherbo</category>
      <category>linux</category>
      <category>security</category>
    </item>
    <item>
      <guid isPermaLink="true">https://mastodon.online/@alip/116573158490545112</guid>
      <link>https://mastodon.online/@alip/116573158490545112</link>
      <pubDate>Thu, 14 May 2026 13:27:15 +0000</pubDate>
      <description>&lt;p&gt;&lt;a href="https://mastodon.online/tags/Sydbox" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;Sydbox&lt;/span&gt;&lt;/a&gt; containers are not affected by the new LPE &lt;a href="https://mastodon.online/tags/Fragnesia" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;Fragnesia&lt;/span&gt;&lt;/a&gt; because: 1. Unprivileged user/network namespaces are denied unless trace/allow_unsafe_namespace:user,net 2. Kernel algorithm (AF_ALG) sockets are denied unless trace/allow_unsafe_kcapi:true 3. Socket option TCP_ULP is denied unless trace/allow_unsafe_setsockopt:true. You may sleep in peace: &lt;a href="https://raw.githubusercontent.com/v12-security/pocs/d4043edc2acbd75d093e3f5795751b678c66b259/fragnesia/fragnesia.c" target="_blank" rel="nofollow noopener" translate="no"&gt;&lt;span class="invisible"&gt;https://&lt;/span&gt;&lt;span class="ellipsis"&gt;raw.githubusercontent.com/v12-&lt;/span&gt;&lt;span class="invisible"&gt;security/pocs/d4043edc2acbd75d093e3f5795751b678c66b259/fragnesia/fragnesia.c&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/exherbo" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;exherbo&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/linux" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;linux&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/security" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;security&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;</description>
      <category>sydbox</category>
      <category>fragnesia</category>
      <category>exherbo</category>
      <category>linux</category>
      <category>security</category>
    </item>
    <item>
      <guid isPermaLink="true">https://mastodon.online/@alip/116563014289657375</guid>
      <link>https://mastodon.online/@alip/116563014289657375</link>
      <pubDate>Tue, 12 May 2026 18:27:27 +0000</pubDate>
      <description>&lt;p&gt;I made an &lt;a href="https://mastodon.online/tags/asciicast" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;asciicast&lt;/span&gt;&lt;/a&gt; showcasing Ghost Mode of &lt;a href="https://mastodon.online/tags/sydbox" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;sydbox&lt;/span&gt;&lt;/a&gt;: &lt;a href="https://asciinema.org/a/1039185" target="_blank" rel="nofollow noopener" translate="no"&gt;&lt;span class="invisible"&gt;https://&lt;/span&gt;&lt;span class=""&gt;asciinema.org/a/1039185&lt;/span&gt;&lt;span class="invisible"&gt;&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/exherbo" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;exherbo&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/linux" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;linux&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/security" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;security&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;</description>
      <category>asciicast</category>
      <category>sydbox</category>
      <category>exherbo</category>
      <category>linux</category>
      <category>security</category>
    </item>
    <item>
      <guid isPermaLink="true">https://mastodon.online/@alip/116562513741722372</guid>
      <link>https://mastodon.online/@alip/116562513741722372</link>
      <pubDate>Tue, 12 May 2026 16:20:09 +0000</pubDate>
      <description>&lt;p&gt;&lt;a href="https://mastodon.online/tags/Sydbox" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;Sydbox&lt;/span&gt;&lt;/a&gt; 3.53.0 is released! This is a feature release improving sandbox categories walk, stat, and adding the new category list for directory listing which allows easy use of walk+list categories for path hiding. readlink is also split from stat category which is by far the most common syscall so this helps with overhead of other categories. We also have bunch of security fixes. Full story, as always, is in the ChangeLog, thanks for flying Syd: &lt;a href="https://gitlab.exherbo.org/sydbox/sydbox/-/blob/main/ChangeLog.md?ref_type=heads#3530" target="_blank" rel="nofollow noopener" translate="no"&gt;&lt;span class="invisible"&gt;https://&lt;/span&gt;&lt;span class="ellipsis"&gt;gitlab.exherbo.org/sydbox/sydb&lt;/span&gt;&lt;span class="invisible"&gt;ox/-/blob/main/ChangeLog.md?ref_type=heads#3530&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/exherbo" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;exherbo&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/linux" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;linux&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/security" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;security&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;</description>
      <category>sydbox</category>
      <category>exherbo</category>
      <category>linux</category>
      <category>security</category>
    </item>
    <item>
      <guid isPermaLink="true">https://mastodon.online/@alip/116541238581584369</guid>
      <link>https://mastodon.online/@alip/116541238581584369</link>
      <pubDate>Fri, 08 May 2026 22:09:36 +0000</pubDate>
      <description>&lt;p&gt;Fun exercise for &lt;a href="https://mastodon.online/tags/Syd" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;Syd&lt;/span&gt;&lt;/a&gt; users: Run &amp;quot;PATH= /path/to/syd&amp;quot; and try to break out of the default restricted &lt;a href="https://mastodon.online/tags/bash" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;bash&lt;/span&gt;&lt;/a&gt; shell session. You&amp;#39;re in a directory that does not exist and you have no access to external commands. It&amp;#39;s not easy or where&amp;#39;s the fun? &lt;a href="https://mastodon.online/tags/exherbo" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;exherbo&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/linux" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;linux&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/security" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;security&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;</description>
      <category>syd</category>
      <category>exherbo</category>
      <category>linux</category>
      <category>security</category>
      <category>bash</category>
    </item>
    <item>
      <guid isPermaLink="true">https://mastodon.online/@alip/116527744051900625</guid>
      <link>https://mastodon.online/@alip/116527744051900625</link>
      <pubDate>Wed, 06 May 2026 12:57:46 +0000</pubDate>
      <description>&lt;p&gt;AF_ALG is marked deprecated as response to copy.fail. Somewhat sad to see a useful API die: &lt;a href="https://lore.kernel.org/linux-crypto/20260430011544.31823-1-ebiggers@kernel.org/" target="_blank" rel="nofollow noopener" translate="no"&gt;&lt;span class="invisible"&gt;https://&lt;/span&gt;&lt;span class="ellipsis"&gt;lore.kernel.org/linux-crypto/2&lt;/span&gt;&lt;span class="invisible"&gt;0260430011544.31823-1-ebiggers@kernel.org/&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/exherbo" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;exherbo&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/linux" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;linux&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/security" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;security&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;</description>
      <category>exherbo</category>
      <category>linux</category>
      <category>security</category>
    </item>
    <item>
      <guid isPermaLink="true">https://mastodon.online/@alip/116505499797317848</guid>
      <link>https://mastodon.online/@alip/116505499797317848</link>
      <pubDate>Sat, 02 May 2026 14:40:46 +0000</pubDate>
      <description>&lt;p&gt;News from &lt;a href="https://mastodon.online/tags/Sydbox" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;Sydbox&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/git" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;git&lt;/span&gt;&lt;/a&gt;: New option trace/force_wx_open: Specify whether creating/writing open(2) family system calls for executables should be denied regardless of path. This option is restricted to creat, open, openat, and openat2 syscalls and may be combined with trace/force_umask option to confine filesystem as Write XOR Execute. New profile &amp;quot;wx&amp;quot; combines the new option with trace/force_umask:7177 to confine filesystem as W^X. User profile includes wx profile. &lt;a href="https://mastodon.online/tags/exherbo" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;exherbo&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/linux" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;linux&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/security" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;security&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;</description>
      <category>sydbox</category>
      <category>git</category>
      <category>exherbo</category>
      <category>linux</category>
      <category>security</category>
    </item>
    <item>
      <guid isPermaLink="true">https://mastodon.online/@alip/116501206209790130</guid>
      <link>https://mastodon.online/@alip/116501206209790130</link>
      <pubDate>Fri, 01 May 2026 20:28:51 +0000</pubDate>
      <description>&lt;p&gt;&lt;a href="https://mastodon.online/tags/Sydbox" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;Sydbox&lt;/span&gt;&lt;/a&gt; 3.52.0 is released! I&amp;#39;ve just merged 428 commits from next to main to make this release. It includes no new features, only bug fixes. Some of these bug fixes are security critical and you&amp;#39;re recommended to upgrade as soon as possible. Full story, as always, is in the ChangeLog, thanks for flying Syd: &lt;a href="https://gitlab.exherbo.org/sydbox/sydbox/-/blob/main/ChangeLog.md" target="_blank" rel="nofollow noopener" translate="no"&gt;&lt;span class="invisible"&gt;https://&lt;/span&gt;&lt;span class="ellipsis"&gt;gitlab.exherbo.org/sydbox/sydb&lt;/span&gt;&lt;span class="invisible"&gt;ox/-/blob/main/ChangeLog.md&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/exherbo" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;exherbo&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/linux" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;linux&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/security" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;security&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;</description>
      <category>sydbox</category>
      <category>exherbo</category>
      <category>linux</category>
      <category>security</category>
    </item>
    <item>
      <guid isPermaLink="true">https://mastodon.online/@alip/116495249968505898</guid>
      <link>https://mastodon.online/@alip/116495249968505898</link>
      <pubDate>Thu, 30 Apr 2026 19:14:06 +0000</pubDate>
      <description>&lt;p&gt;Mitigation against copy.fail in upcoming &lt;a href="https://mastodon.online/tags/Sydbox" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;Sydbox&lt;/span&gt;&lt;/a&gt;: Syd will reject to open SUID files regardless of mode unless the option trace/allow_unsafe_open_suid:1 is set. This does not prevent exploitation altogether as the attacker can write to files such as /etc/passwd, however it raises the bar with very little added cost. &lt;a href="https://mastodon.online/tags/exherbo" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;exherbo&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/linux" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;linux&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/security" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;security&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;</description>
      <category>sydbox</category>
      <category>exherbo</category>
      <category>linux</category>
      <category>security</category>
    </item>
    <item>
      <guid isPermaLink="true">https://mastodon.online/@alip/116494911107379764</guid>
      <link>https://mastodon.online/@alip/116494911107379764</link>
      <pubDate>Thu, 30 Apr 2026 17:47:55 +0000</pubDate>
      <description>&lt;p&gt;&lt;a href="https://mastodon.online/tags/GVisor" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;GVisor&lt;/span&gt;&lt;/a&gt; supports only x86_64, arm64 yet they claim they run everywhere. &lt;a href="https://mastodon.online/tags/Sydbox" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;Sydbox&lt;/span&gt;&lt;/a&gt; passes tests on x86_64, i686, x32, arm64, armv7, ppc64, ppc64le, ppc, s390x, loongarch64, mips64el, and mipsel but I won&amp;#39;t claim we are portable until we have mips64, mips, m68k and sparc! Huge thanks to Compile Farm people for enabling us to test Syd on various different architectures! &lt;a href="https://mastodon.online/tags/exherbo" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;exherbo&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/linux" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;linux&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/security" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;security&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;</description>
      <category>gvisor</category>
      <category>sydbox</category>
      <category>exherbo</category>
      <category>linux</category>
      <category>security</category>
    </item>
    <item>
      <guid isPermaLink="true">https://mastodon.online/@alip/116494519914608215</guid>
      <link>https://mastodon.online/@alip/116494519914608215</link>
      <pubDate>Thu, 30 Apr 2026 16:08:26 +0000</pubDate>
      <description>&lt;p&gt;Correction: I was wrong about copy.fail and &lt;a href="https://mastodon.online/tags/sydbox" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;sydbox&lt;/span&gt;&lt;/a&gt; earlier: Force sandboxing and Crypt sandboxing _imply_ the option trace/allow_safe_kcapi:1 so when these two are in use the sandbox process can abuse the AEAD issue in the &lt;a href="https://mastodon.online/tags/Linux" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;Linux&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/kernel" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;kernel&lt;/span&gt;&lt;/a&gt;. With &lt;a href="https://mastodon.online/tags/sydbox" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;sydbox&lt;/span&gt;&lt;/a&gt; 3.52.0 to be released very soon, we rename the trace/allow_safe_kcapi option to trace/allow_unsafe_kcapi and Force/Crypt sandboxing are no longer going to imply this option, rather allow only Syd&amp;#39;s use of AF_ALG sockets. &lt;a href="https://mastodon.online/tags/exherbo" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;exherbo&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/linux" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;linux&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/security" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;security&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;</description>
      <category>sydbox</category>
      <category>linux</category>
      <category>kernel</category>
      <category>exherbo</category>
      <category>security</category>
    </item>
    <item>
      <guid isPermaLink="true">https://mastodon.online/@alip/116492667669657030</guid>
      <link>https://mastodon.online/@alip/116492667669657030</link>
      <pubDate>Thu, 30 Apr 2026 08:17:23 +0000</pubDate>
      <description>&lt;p&gt;New &lt;a href="https://mastodon.online/tags/container" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;container&lt;/span&gt;&lt;/a&gt; breakout: &lt;a href="https://copy.fail/" target="_blank" rel="nofollow noopener" translate="no"&gt;&lt;span class="invisible"&gt;https://&lt;/span&gt;&lt;span class=""&gt;copy.fail/&lt;/span&gt;&lt;span class="invisible"&gt;&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/sydbox" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;sydbox&lt;/span&gt;&lt;/a&gt; containers aren&amp;#39;t affected because Syd denies access to Kernel Cryptography API (KCAPI, AF_ALG sockets) by default unless trace/allow_safe_kcapi:1 is specified at startup. Crypt Sandboxing is also not affected because we don&amp;#39;t use AEAD but CTR(AES). &lt;a href="https://mastodon.online/tags/exherbo" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;exherbo&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/linux" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;linux&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/security" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;security&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;</description>
      <category>container</category>
      <category>sydbox</category>
      <category>exherbo</category>
      <category>linux</category>
      <category>security</category>
    </item>
    <item>
      <guid isPermaLink="true">https://mastodon.online/@alip/116477617687048919</guid>
      <link>https://mastodon.online/@alip/116477617687048919</link>
      <pubDate>Mon, 27 Apr 2026 16:29:58 +0000</pubDate>
      <description>&lt;p&gt;&lt;a href="https://mastodon.online/tags/Sydbox" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;Sydbox&lt;/span&gt;&lt;/a&gt; is on &lt;a href="https://mastodon.online/tags/Radicle" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;Radicle&lt;/span&gt;&lt;/a&gt; with ID rad:z38HCnbmcDegA2BMxuPaPRPMdp6wF seed it and share the love! Huge thanks to &lt;a href="https://mastodon.online/tags/HardenedBSD" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;HardenedBSD&lt;/span&gt;&lt;/a&gt; folks for seeding! &lt;a href="https://mastodon.online/tags/exherbo" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;exherbo&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/linux" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;linux&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/security" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;security&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/git" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;git&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;</description>
      <category>sydbox</category>
      <category>radicle</category>
      <category>hardenedbsd</category>
      <category>exherbo</category>
      <category>linux</category>
      <category>security</category>
      <category>git</category>
    </item>
    <item>
      <guid isPermaLink="true">https://mastodon.online/@alip/116387678720077248</guid>
      <link>https://mastodon.online/@alip/116387678720077248</link>
      <pubDate>Sat, 11 Apr 2026 19:17:19 +0000</pubDate>
      <description>&lt;p&gt;Here is a &lt;a href="https://mastodon.online/tags/landlock" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;landlock&lt;/span&gt;&lt;/a&gt; oddity I noticed and reported today: &lt;a href="https://github.com/landlock-lsm/linux/issues/58" target="_blank" rel="nofollow noopener" translate="no"&gt;&lt;span class="invisible"&gt;https://&lt;/span&gt;&lt;span class="ellipsis"&gt;github.com/landlock-lsm/linux/&lt;/span&gt;&lt;span class="invisible"&gt;issues/58&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/exherbo" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;exherbo&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/linux" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;linux&lt;/span&gt;&lt;/a&gt; &lt;a href="https://mastodon.online/tags/security" class="mention hashtag" rel="tag"&gt;#&lt;span&gt;security&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;</description>
      <category>landlock</category>
      <category>exherbo</category>
      <category>linux</category>
      <category>security</category>
    </item>
  </channel>
</rss>
