Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Mickaël Salaün

@l0kod@mastodon.social
mastodon 4.8.0-nightly.2026-10-06
  • Open on mastodon.social

Creator and maintainer of #Landlock: https://landlock.io
Security and open source enthusiast

0 Followers
0 Following
16 Posts
Joined November 15, 2022
Personal website:
https://digikod.net
Landlock:
https://landlock.io
Bluesky:
https://bsky.app/profile/l0kod.bsky.social
Twitter:
https://twitter.com/l0kod
Open post
Mickaël Salaün @l0kod@mastodon.social
· 3mo ago
Here is the #Landlock threat model (up-to-date patch): https://lore.kernel.org/all/20260707210336.2060040-1-mic@digikod.net/ This is a follow-up of the recent Linux kernel thread model doc, which should help Landlock users and security researchers, especially with the rise of AI-assisted security reports. 🔒🤖
lore.kernel.org
2
0
3
0
Open post
Mickaël Salaün @l0kod@mastodon.social
· 8mo ago

I gave a talk at #FOSDEM about Island: Sandboxing tool powered by #Landlock
https://fosdem.org/2026/schedule/event/EW8M3R-island/

mastodon.social

Mastodon

7
6
7
0
Open post
Mickaël Salaün @l0kod@mastodon.social
· 12mo ago
Replying to
Talking about sandboxing services, I'll give a talk at #AllSystemsGo in a few hours about using #Landlock with systemd: https://cfp.all-systems-go.io/all-systems-go-2025/talk/FXWDCF/
cfp.all-systems-go.io

Sandboxing services with Landlock All Systems Go! 2025

Landlock is an unprivileged kernel feature that enables all Linux users to sandbox their processes. Complementary to seccomp, developers can leverage Landlock to restrict their programs in a fine-grained way. While Landlock can be used by end users through sandboxer tools, there is currently no well-integrated solution to define security policies tailored to system services. Although AppArmor and seccomp security policies can already be tied to a system unit, we aim to provide a more dynamic, st

7
2
3
0
Open post
Mickaël Salaün @l0kod@mastodon.social
· 13mo ago

Script integrity: I gave a talk at #linuxsecuritysummit in Amsterdam on the latest news about Linux's AT_EXECVE_CHECK, useful to check the full file executability (including LSMs' policies), and the two new secbits to incrementally enforce restrictions and really control executable code.
Feel free to let me know if you want to contribute by enlightening your favorite interpreter!
https://lsseu2025.sched.com/event/25GEQ

mastodon.social
5
0
2
0
Open post
Mickaël Salaün @l0kod@mastodon.social
· 12mo ago
Replying to
The recording is already online! https://youtu.be/tZuezmpfwy8

Sandboxing services with Landlock

4
1
1
0
Open post
Mickaël Salaün @l0kod@mastodon.social
· 10mo ago
Replying to
@trou@infosec.exchange You can restrict TCP connect and bind, see [[net_port]]: https://github.com/landlock-lsm/landlockconfig/blob/main/examples/mini-write-tmp.toml
GitHub

landlockconfig/examples/mini-write-tmp.toml at main · landlock-lsm/landlockconfig

Landlock configuration library. Contribute to landlock-lsm/landlockconfig development by creating an account on GitHub.

1
1
0
0
Open post
Mickaël Salaün @l0kod@mastodon.social
· 10mo ago
Replying to
news.ycombinator.com
1
0
0
0
Open post
Mickaël Salaün @l0kod@mastodon.social
· 10mo ago
Replying to
@trou@infosec.exchange Only TCP is supported for now, but UDP support is WIP: https://github.com/landlock-lsm/linux/issues/10 and the socket creation restriction is almost ready: https://github.com/landlock-lsm/linux/issues/6 More reviewers would help 😉
GitHub

UDP socket control · Issue #10 · landlock-lsm/linux

We can now control TCP actions (bind(2) and connect(2)), and it would be useful to have a similar semantic for UDP. It's a bit tricky because of the datagram nature of UDP though. However, it shoul...

1
3
0
0
Open post
Mickaël Salaün @l0kod@mastodon.social
· 10mo ago
Replying to
@tris@chaos.social there are a lot of sandboxing tools and I tried to highlight the main differences in the readme. Anyway, I encourage you to test it and see for yourself 😉
1
0
0
0
Open post
Mickaël Salaün @l0kod@mastodon.social
· 13mo ago

I gave a (2nd) talk at #linuxsecuritysummit on a new configuration format, #Landlock Config, to define sandboxing security policies. The provided library (Rust and C for now) can also compose configurations to ease sharing and maintenance. This is especially useful to sandbox programs without modifying them, and to easily manage and audit Landlock policies. It could also be part of other configuration formats such as the OCI runtime specification.
https://lsseu2025.sched.com/event/25GET

https://github.com/landlock-lsm/landlockconfig

mastodon.social
1
0
1
0
Open post
Mickaël Salaün @l0kod@mastodon.social
· 10mo ago
Replying to
@trou@infosec.exchange there is definitely room for doc improvement, but I wanted to release it sooner than later. Contributions are welcome too!
0
0
0
0
Open post
Mickaël Salaün @l0kod@mastodon.social
· 8mo ago
Replying to
@Regit the default config for a new profile should just work (wrt the install path)
0
0
0
0
Open post
Mickaël Salaün @l0kod@mastodon.social
· 8mo ago
Replying to
@tcheneau@linuxrocks.online thanks for the heads-up. Which talk is it?
0
3
0
0
Open post
Mickaël Salaün @l0kod@mastodon.social
· 8mo ago
Replying to
@tcheneau@linuxrocks.online Indeed: https://fosdem.org/2026/schedule/event/37NC8K-gomodjail/ The Q/A about Landlock in the slide is a bit cryptic though 🤔
fosdem.org
0
1
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 11:27:20 UTC