I gave a (2nd) talk at #linuxsecuritysummit on a new configuration format, #Landlock Config, to define sandboxing security policies. The provided library (Rust and C for now) can also compose configurations to ease sharing and maintenance. This is especially useful to sandbox programs without modifying them, and to easily manage and audit Landlock policies. It could also be part of other configuration formats such as the OCI runtime specification.
https://lsseu2025.sched.com/event/25GET







