@jannic if you want to convince me, checkout https://gitlab.exherbo.org/sydbox/sydbox and try to compile syd-oci as static. You need to pass --features oci to cargo build. This does not work because #youki uses proc-macros unlike #sydbox core code which is free of proc-macros.
Sydbox / sydbox · GitLab

rock-solid application kernel

GitLab

Не runc’ом единым: интересные среды запуска контейнеров

Существует множество сред для запуска контейнеров; среди распространенных можно выделить runc и kata. Мы в

https://habr.com/ru/companies/beeline_cloud/articles/979010/

#beeline_cloud #контейнеризация #youki #urunc #ocre #quark #kuasar #incus

Не runc’ом единым: интересные среды запуска контейнеров

Существует множество сред для запуска контейнеров; среди распространенных можно выделить runc и kata. Мы в Beeline Cloud решили поговорить не только о широко известных, но и о набирающих свою...

Хабр
All three breakouts feature procfs writes. #sydbox has hardened procfs and devfs, https://man.exherbo.org/syd.7.html#Hardened_procfs_and_devfs
which prevents such breaks. However wrt. syd-oci, the vulnerable code is within the container init done by #youki.
SYD(7)

Symlinks strike again! This time with 3 #container breakouts in #runc. Other runtimes including #youki and #crun are also affected. #sydbox' syd-oci is also affected which is based on #youki. Expect updates soon: https://www.openwall.com/lists/oss-security/2025/11/05/3 #exherbo #linux #security #podman
oss-security - runc container breakouts via procfs writes: CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881

Announcing #sydbox 3.20.0 which includes Crypt Sandboxing for transparent #AES-CTR file #encryption and Ghost Mode for enhanced confinement like #Seccomp Level 1. Fixes include proper read-write open sandboxing and #youki updates which fix #podman exec for syd-oci. New utilities: syd-key for AES-CTR keygen, syd-cp for efficient file copying, and syd-aes for {en,de}cryption. #sydbox is a rock-solid user-space #kernel to #sandbox apps on #Linux >=5.19 written in #rustlang: https://is.gd/2tczYu
With version 3.18.0 released today, #sydbox joins the family of #OCI container runtimes! The new syd-oci utility is largely based on #youki and provides a thin layer between the Syd #sandbox and #containers. It supports all the common commands and is compatible with both #Docker and #Podman. #sydbox is a rock-solid user-space #kernel to #sandbox apps on #Linux >=5.19 written in #rustlang. Read more about syd-oci here: https://man.exherbolinux.org/syd-oci.1.html
SYD-OCI(1)

Il était où, hein? #youki #rage
Rigolitch - Rage Against The Youki (RATM vs Richard Gotainer) - YouTube https://www.youtube.com/watch?v=Y5P0IxNIXpQ
Rigolitch - Rage Against The Youki (RATM vs Richard Gotainer)

YouTube