On Tue, Mar 16, 2021 at 09:42:51PM +0100, Mickaël Salaün wrote: > From: Mickaël Salaün <mic@xxxxxxxxxxxxxxxxxxx> > > Add a basic sandbox tool to launch a command which can only access a > list of file hierarchies in a read-only or read-write way. > > Cc: James Morris <jmorris@xxxxxxxxx> > Cc: Kees Cook <keescook@xxxxxxxxxxxx> > Cc: Serge E. Hallyn <serge@xxxxxxxxxx> > Signed-off-by: Mickaël Salaün <mic@xxxxxxxxxxxxxxxxxxx> I'm very happy to see any example! Reviewed-by: Kees Cook <keescook@xxxxxxxxxxxx> -- Kees Cook