On Mon, Sep 12, 2022 at 09:05:03PM +0200, Mickaël Salaün wrote: > On 08/09/2022 21:58, Günther Noack wrote: > > Update the sandboxer sample to restrict truncate actions. This is > > automatically enabled by default if the running kernel supports > > LANDLOCK_ACCESS_FS_TRUNCATE, expect for the paths listed in the > > except for Fixed, good catch! -Günther --