<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Landlock on Nalar</title>
    <link>https://nalar.dev/tags/landlock/</link>
    <description>Recent content in Landlock on Nalar</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 17 Sep 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://nalar.dev/tags/landlock/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Landlock Rulesets Restrict Future Path Access, Not Open File Authority</title>
      <link>https://nalar.dev/landlock-rulesets-restrict-future-path-access-not-open-file-authority/</link>
      <pubDate>Thu, 17 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://nalar.dev/landlock-rulesets-restrict-future-path-access-not-open-file-authority/</guid>
      <description>&lt;h1 id=&#34;landlock-rulesets-restrict-future-path-access-not-open-file-authority&#34;&gt;Landlock Rulesets Restrict Future Path Access, Not Open File Authority&lt;/h1&gt;&#xA;&lt;p&gt;A process opens a writable configuration file, installs a restrictive Landlock ruleset, and then continues running code that should have access only to a small working directory. The later policy can block a fresh attempt to open that configuration path, yet the descriptor obtained before confinement remains usable. The filesystem view has narrowed, but authority already materialized as an open file has not vanished.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
