Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

alip

@alip@mastodon.online
mastodon 4.8.0-nightly.2026-10-06
  • Open on mastodon.online

Homo Ludens. I push wood, set traps, write code and poetry. #sydbox is my problem child. I live in #Berlin. I am an #Exherbo #Linux developer. I love #chess, #freesoftware, #poetry, #perl, #c, #rustlang, and #haskell. #Antifa, #Atheist, #fckafd, and #fckakp. Don't come to me with guns, come to me with roses. #Revolution will not be broadcasted on TV. #direngezi!
https://chesswob.org
https://git.sr.ht/~alip/jja
https://sydbox.exherbolinux.org

125 Followers
522 Following
36 Posts
Joined February 26, 2021
E-Mail:
alip@chesswob.org
PGP Key:
5DF763560390A149AC6C14C7D076A377FB27DE70
Keybase:
https://keybase.io/alip
TwTxt:
https://alip.srht.site/twtxt.txt
Open post
alip @alip@mastodon.online
· 6mo ago
News from #sydbox git: Starting next release, we're going to be signing binary releases with #OpenBSD signify rather than #GnuPG. To enable practical signing in #Exherbo #Gitlab CI, I wrote an #ISC licensed, pure portable #POSIX shell implementation of #OpenBSD signify. signify.sh has no external dependencies and runs with PATH=. It has unit tests embedded which may be run with --test option: https://gitlab.exherbo.org/sydbox/sydbox/-/raw/next/dev/signify.sh #exherbo #linux #security
gitlab.exherbo.org
9
5
8
0
Open post
alip @alip@mastodon.online
· 6mo ago

#Sydbox is NOT hosted on #Github and this is an ethical decision. Main repository is the #Exherbo #Gitlab, we have mirrors on #Sourcehut and #Codeberg. Having said that, the code is GPL-3 and I can't legally prevent anyone from mirroring it on Github. I can just kindly ask not to...: https://github.com/tamaroning/sydbox/issues/1 #exherbo #linux #security

mastodon.online

Mastodon

6
6
4
0
Open post
alip @alip@mastodon.online
· 6mo ago

#gVisor recently got its own #ASLR implementation. OTOH, #Sydbox uses ASLR provided by the #Linux #kernel and enforces PIE executables. #HardenedBSD has a sysctl to enforce PIE as well: https://man.exherbo.org/syd.7.html#Enforcing_Position-Independent_Executables_(PIE) #exherbo #linux #security

mastodon.online
5
0
1
0
Open post
alip @alip@mastodon.online
· 2mo ago

New #Linux #LPE: #RefluXFS which is a direct attack against #XFS filesystem using the reflink feature giving #root access to unprivileged users by overwriting inaccessible data on #XFS filesystems. #Syd containers are not vulnerable because FICLONE{,RANGE} ioctls are denied by default with errno EOPNOTSUPP allowing cp --reflink to seamlessly fallback: https://cdn2.qualys.com/advisory/2026/07/22/RefluXFS.txt #exherbo #linux #security

mastodon.online

Mastodon

1
0
1
0
Open post
alip @alip@mastodon.online
· 2mo ago

Oh my #TOCTOU! Multiple vulnerabilities fixed in #snap, #Ubuntu users to the update mobile! https://discourse.ubuntu.com/t/snapd-multiple-vulnerabilities-fixed/85433 #linux #security

mastodon.online
1
0
0
0
Open post
alip @alip@mastodon.online
· 6mo ago

Here is #rustlang bindings for Redis' #radix tree: https://crates.io/crates/redix New #sydbox uses this for path canonicalization which sufficiently reduces its userspace overhead. Let me know if sydbox-3.51.1 is too fast for you and I'll add some random sleeps around the code ;) #exherbo #linux #security

mastodon.online

Mastodon

4
0
0
0
Open post
alip @alip@mastodon.online
· 6mo ago

Code does not become better out of thin air just because you rewrite it in #rustlang. TOCTOUs are typically language agnostic. Here's one for tar: https://blog.rust-lang.org/2026/03/21/cve-2026-33056/ #security

mastodon.online

Mastodon

4
0
6
0
Open post
alip @alip@mastodon.online
· 6mo ago
Replying to
@xgqt@functional.cafe indeed. Sourcehut CI's main advantage for me is the ability to be able to SSH into the VM after a build failure and having the chance to install whatever debugging utilities you need. This typically saves me hours if not days of work trying to reproduce bugs locally, especially with races and such.
2
0
0
0
Open post
alip @alip@mastodon.online
· 6mo ago

#Sydbox has a new #tutorial: https://man.exherbo.org/sydtutorial.7.html #exherbo #linux #security

mastodon.online

Mastodon

2
0
2
0
Open post
alip @alip@mastodon.online
· 6mo ago

#Sydbox 3.51.0 is out: #Security update fixing multiple Crypt Sandboxing race conditions, an ioctl(2) truncation bypass, and a MIPS ptrace(2) bug. Force Sandboxing now uses the Kernel Crypto API (AF_ALG) for zero-copy hashing. #Landlock sandboxing is on by default. wordexp(3) confinement hardened. pandora 0.20.0 generates #Landlock rules. Sydbox is a rock solid application #kernel to sandbox applications on #Linux: https://gitlab.exherbo.org/sydbox/sydbox/-/blob/main/ChangeLog.md?ref_type=heads#3510 #exherbo

mastodon.online

Mastodon

2
0
1
0
Open post
alip @alip@mastodon.online
· 6mo ago

Is it a red flag that #sydbox is developed mainly by a single person in their free time rather than bigcorp? #exherbo #linux #security

mastodon.online
2
1
0
0
Open post
alip @alip@mastodon.online
· 6mo ago

#apparmor local root: who's going to watch the watchers episode 202603! #ubuntu people should bump their #kernel and consider switching to unprivileged alternatives such as #sydbox ;): https://www.openwall.com/lists/oss-security/2026/03/12/7 #linux #security

mastodon.online
2
0
2
0
Open post
alip @alip@mastodon.online
· 5mo ago

unwrap is the new unsafe! #rustlang

mastodon.online

Mastodon

1
18
1
0
Open post
alip @alip@mastodon.online
· 6mo ago
Replying to
@mei@donotsta.re yes, that's correct. signify.sh includes 65 NIST CAVP SHA-256, 129 NIST CAVP SHA-512, 1024 DJB Ed25519 sign/verify, and 150 Wycheproof Ed25519 vectors.
1
1
0
0
Open post
alip @alip@mastodon.online
· 6mo ago

Reading this made me reconsider switching #Sydbox from GPL-3 to AGPL-3: https://www.onlyoffice.com/blog/2026/03/onlyoffice-flags-license-violations-in-euro-office-project-by-nextcloud-and-ionos WDYT? #exherbo #linux #security #poll

mastodon.online

Mastodon

1
0
2
0
Open post
alip @alip@mastodon.online
· 6mo ago
Replying to
@lattera@bsd.network for sure! I've been following #HardenedBSD's attempts to migrate with interest. I have never got around to learning it myself to the point I can mirror #Sydbox. Pointers welcome.
1
0
0
0
Open post
alip @alip@mastodon.online
· 6mo ago

Oh my snap! https://www.openwall.com/lists/oss-security/2026/03/17/8 A case of fortune favors the patient: "an unprivileged local attacker who wants to exploit this LPE must wait for 10 days (in Ubuntu > 24.04) or 30 days (in Ubuntu 24.04) to obtain a fully privileged root shell." This is why it matters to use unprivileged sandboxes such as #sydbox: Who's going to watch the watchers? #ubuntu #linux #security

openwall.com
1
0
0
0
Open post
alip @alip@mastodon.online
· 6mo ago

News from #sydbox git: Force sandboxing (binary verification) now uses #Linux #kernel cryptography. You may use any hash algorithm your kernel supports and checksumming process happens with zero-copy without copying data into Syd's process space. This ensures performance and privacy. Syd is hash-algorithm agnostic and makes no choice of a default. Pandora learned to autoselect best avaliable algorithm. Refer to the manual page for more information: https://man.exherbo.org/syd.7.html#Force_Sandboxing #exherbo #security

mastodon.online
1
0
1
0
Open post
alip @alip@mastodon.online
· 7mo ago

#Sydbox 3.50.0 is out: New lock mode "drop" when sandbox policy may only be edited to reduce privileges a la #OpenBSD pledge(2), KCOV/syzkaller support, support for memfd_secret(2) and SCM_PIDFD control message, glob support for ioctl(2) names in sandbox rules (e.g. allow/ioctl+KVM_*), fix for a trusted symlink bypass, new trusted feature to gate unsafe options which can circumvent the sandbox. Sydbox is a rock solid application kernel to sandbox applications on #Linux: https://gitlab.exherbo.org/sydbox/sydbox/-/blob/main/ChangeLog.md?ref_type=heads#3500

mastodon.online

Mastodon

1
0
0
0
Open post
alip @alip@mastodon.online
· 6mo ago
Replying to
@mei@donotsta.re Thank you very much for the feedback, I have removed the fallback.
0
1
0
0
Open post
alip @alip@mastodon.online
· 5mo ago

Here is a #landlock oddity I noticed and reported today: https://github.com/landlock-lsm/linux/issues/58 #exherbo #linux #security

mastodon.online
0
0
0
0
Open post
alip @alip@mastodon.online
· 6mo ago

Am I a TOCTOU dreaming of a butterfly, or am I a butterfly dreaming of a TOCTOU?: https://git.kernel.org/pub/scm/libs/libcap/libcap.git/commit/?id=286ace1259992bd0c5d9016715833f2e148ac596 #exherbo #linux #security

git.kernel.org
0
0
0
0
Open post
alip @alip@mastodon.online
· 5mo ago
Replying to
@cobratbq@mastodon.social in my experience stack unwinding is typically killed due to direct proc(5) accesses which may be done for various reasons to resolve function names, symbols, current working directory and so on. Under Syd we have a direct fd to proc(5) at all times and /proc may not be proc(5) so this can never work.
0
3
0
0
Open post
alip @alip@mastodon.online
· 7mo ago

New hardening in #Sydbox 3.50.0: "Immutable Sticky Bit" where Syd enforces the immutability of the sticky bit at chmod(2) boundary for directories. Sticky bit on dirs such as /tmp is a critical security primitive that restricts file deletion/renaming to file/directory owner or root. This also helps raise the bar for trusted symlink bypasses. On by default, disable with trace/allow_unsafe_sticky:1. Refer to the manual page for more information: https://man.exherbo.org/syd.7.html#Immutable_Sticky_Bit #exherbo #linux #security

mastodon.online

Mastodon

0
0
0
0
Open post
alip @alip@mastodon.online
· 5mo ago
Replying to
@cobratbq@mastodon.social there're cases when it's recoverable, e.g. if a Syd emulator thread panics, the system call in progress is denied by a RAII guard which checks whether the current thread has panicked. You can't recover from panics of the main thread though, you're correct there.
0
13
0
0
Open post
alip @alip@mastodon.online
· 5mo ago
Replying to
@cobratbq@mastodon.social stack unwinding involves file i/o and other random syscalls on Linux, such as getcwd which are outright denied by syd threads, so typically stack unwind gets killed before it can even print a single thing.
0
2
0
0
Open post
alip @alip@mastodon.online
· 5mo ago
Replying to
@cobratbq@mastodon.social I am not exactly sure if these are part of stack unwinding itself or other machinery that happens as part of the panic handler though.
0
0
0
0
Open post
alip @alip@mastodon.online
· 5mo ago
Replying to
@cobratbq@mastodon.social I am not sure, problem with the main thread is you can't respawn it like any other thread. You need to re-exec which beats the whole purpose sometimes.
0
11
0
0
Open post
alip @alip@mastodon.online
· 5mo ago
Replying to
@cobratbq@mastodon.social This helps thanks, I'll do a bit of experimenting with it. All you have to know wrt. Syd about main thread panicking is it's functionally equivalent to turning your computer off immediately with the power-off switch. No sandbox process will have any chance whatsoever to clean up for anything. It's the most unkind thing Syd can ever do. This is why I have gradually eliminated more code from the main thread, making it handle only wait/ptrace events which is a design limitation on Linux.
0
5
0
0
Open post
alip @alip@mastodon.online
· 5mo ago
Replying to
@cobratbq@mastodon.social panicing is not necessarily deterministic in every context.
0
16
0
0
Open post
alip @alip@mastodon.online
· 22mo ago

"Seek #freedom and become captive of your desires, seek discipline and find your liberty." — Frank Herbert, Dune

mastodon.online
0
0
0
0
Open post
alip @alip@mastodon.online
· 6mo ago

Symbolic links bite again! This time it's #NixOS did you know #sydbox has trace/force_no_symlinks and trace/force_no_magiclinks options to disable following symlinks/magiclinks? You can even change them at runtime to achieve #pledge like confinement: https://discourse.nixos.org/t/nix-security-advisory-privilege-escalation-via-symlink-following-during-fod-output-registration/76900 #nix #linux #security

mastodon.online
0
0
0
0
Open post
alip @alip@mastodon.online
· 5mo ago
Replying to
@cobratbq@mastodon.social another problem with this is, syd is a userspace kernel, there really must not be any unrecoverable errors, all errors are sandbox process' to handle. We try really really hard to avoid all panics and be very conservative with deps not to introduce panicing code accidentally.
0
7
0
0
Open post
alip @alip@mastodon.online
· 6mo ago
Replying to
@xgqt@functional.cafe yes, having backups is useful. We also use the sourcehut ci for testing. One of the main reasons sydbox is very well tested is the awesome CI services of Exherbo Gitlab and Sourcehut for which I am eternally thankful :-)
0
2
0
0
Open post
alip @alip@mastodon.online
· 20mo ago
Replying to
@Lapsus run your $BROWSER under #sydbox. Thank me later.
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 20:49:40 UTC